Content
77%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An actionable, well-sequenced hunting skill with concrete commands and a strong validation gate, weakened mainly by redundancy (the ToolShell and download.aspx points recur across sections) and the absence of any progressive-disclosure file split for a long monolithic body.
Suggestions
Dedupe the ToolShell precondition chain and the 'download.aspx is NOT SSRF' discussion so each appears once (e.g. methodology step + one canonical reference), removing the restatements in Payload & Detection, Bypass Techniques, and Real Impact.
Split the CVE/build matrix and the per-endpoint payload patterns into a referenced bundle file (e.g. references/cve-matrix.md) to shorten the SKILL.md overview and add one-level-deep progressive disclosure.
Trim the 'Crown Jewel Targets' market commentary ('one of the richest enterprise attack surfaces in 2025-2026...') to a one-line framing so the body leads with operational content.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly high-signal operational detail Claude would not already know, but the ToolShell precondition chain and the 'download.aspx is NOT SSRF' point are restated across Methodology, Payload & Detection, Bypass Techniques, and Real Impact, and the 'Crown Jewel Targets' intro carries market commentary that could be trimmed. | 2 / 3 |
Actionability | Copy-paste-ready curl commands, exact SOAP payloads, concrete endpoints, expected response codes, and grep/jq extraction patterns throughout — fully executable guidance. | 3 / 3 |
Workflow Clarity | A sequenced 10-step methodology is reinforced by an explicit 'Gate 0 Validation' checklist (attacker-impact test, full-chain reproduction requirement, '<10 minutes from a clean shell' reproduce-list, and a retract-SSRF gate). | 3 / 3 |
Progressive Disclosure | No bundle files exist (references/, scripts/, assets/ absent) and the ~430-line body is monolithic; it is well-sectioned but the CVE matrix and detailed payload patterns are inline material that could be split into referenced files. | 2 / 3 |
Total | 10 / 12 Passed |