Content
77%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a strong, actionable skill with concrete UDM queries and clear MCP tool invocations for hunting credential access techniques. The workflow is well-sequenced with appropriate escalation paths and documentation requirements. Minor improvements could be made in conciseness and progressive disclosure by extracting the technique-specific query library into a separate reference file.
Suggestions
Consider extracting the technique-specific UDM queries into a separate reference file (e.g., CREDENTIAL_ACCESS_QUERIES.md) and keeping only one example query inline to reduce the main skill's length.
Remove the 'Understand: What the technique does / Common procedures/tools / Detection methods' bullet list in Step 1 as this is implicit in researching a technique.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The technique reference table and common techniques section add useful context, but some explanations are slightly verbose (e.g., 'Understand: What the technique does, Common procedures/tools, Detection methods' is somewhat obvious). The skill is reasonably efficient but could be tightened in places. | 2 / 3 |
Actionability | Provides concrete, executable UDM queries for each technique, specific MCP tool calls with parameters, and clear examples of what to search for. The queries are copy-paste ready and cover multiple credential access scenarios. | 3 / 3 |
Workflow Clarity | The 7-step workflow is clearly sequenced with logical progression from research through execution to documentation. It includes validation/enrichment steps (Steps 4-5), explicit escalation criteria with branching paths (Step 7), and guidance on handling both positive and negative findings. | 3 / 3 |
Progressive Disclosure | The content is well-structured with clear sections and tables, but it's a fairly long monolithic document. The inline UDM queries for multiple techniques could potentially be split into a reference file, and the cross-references to other skills (/respond-compromised-account, /document-in-case) are mentioned but not linked to files. | 2 / 3 |
Total | 10 / 12 Passed |