CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-windows-shellbag-artifacts

Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsing activity and prove user interaction with directories, including removable media and network shares, even after the folders are deleted. Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/analyzing-windows-shellbag-artifacts/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is technically solid with concrete commands and useful forensic scenarios, but it over-relies on a large padded example output, omits any explicit end-to-end workflow, and fails to link to the bundle files it ships. Tightening the example and wiring up references would lift the weaker dimensions.

Suggestions

Trim or collapse the long fabricated 'Example Output' block to a representative excerpt, and replace the circular 'When to Use' bullets with concrete triggers.

Add an explicit numbered workflow (extract hives -> run SBECmd -> filter by USB/network -> correlate with MFT/LNK -> document) with validation checkpoints, or link to references/workflows.md.

Link the bundle files from the body — reference references/api-reference.md for field/type details, scripts/process.py for CSV analysis, and assets/template.md for reporting — so progressive disclosure is actually navigable.

DimensionReasoningScore

Conciseness

Mostly efficient in the analysis sections, but the ~50-line fabricated 'Example Output' block, circular 'When to Use' bullets ('When investigating security incidents that require analyzing windows shellbag artifacts'), and boilerplate 'Prerequisites' add padding that could be trimmed.

3 / 5

Actionability

Provides concrete, executable SBECmd commands with documented output columns and GUI steps; minor gap is that the bundled scripts/agent.py and scripts/process.py are never referenced or invoked from the body.

4 / 5

Workflow Clarity

Sections are present and the work is read-only (no destructive/batch cap), but there is no explicit numbered investigative sequence with validation checkpoints in the body; the actual workflow lives in the unreferenced references/workflows.md.

3 / 5

Progressive Disclosure

Good section structure and a bundle exists (references, scripts, assets), but the body inlines API-reference-style detail (registry paths, output fields, shell item types) that duplicates references/api-reference.md and never links to the bundle files, leaving them orphaned and un-signaled.

3 / 5

Total

13

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that states concrete capabilities, names the tools, and gives explicit 'Use when' trigger guidance tailored to DFIR practitioners. It is concise yet comprehensive with no noticeable fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'reconstruct folder browsing activity', 'prove user interaction with directories, including removable media and network shares, even after the folders are deleted' — using named tools (SBECmd, Shellbags Explorer), giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (analyze shellbag/BagMRU artifacts, reconstruct browsing, prove interaction) and when via a concrete 'Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work' clause.

5 / 5

Trigger Term Quality

Covers natural DFIR phrasing and synonyms a user would actually say — 'folder access history', 'proving access to a since-removed directory', 'removable media', 'network shares', 'DFIR work' — alongside the technical terms.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Windows Shellbag/BagMRU registry forensics with SBECmd/Shellbags Explorer) with distinct triggers and minimal overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.