CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-windows-shellbag-artifacts

Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsing activity and prove user interaction with directories, including removable media and network shares, even after the folders are deleted. Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/analyzing-windows-shellbag-artifacts/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is technically accurate and gives usable SBECmd commands, but it is padded with redundant example output and duplicated reference tables, and it fails to wire its own bundle (scripts, references, template) into the workflow. Tightening and cross-linking the bundle would lift all four dimensions.

Suggestions

Trim the large fabricated SBECmd output block and the inline registry-location/API tables; replace them with one-level-deep links to references/api-reference.md and references/standards.md so the body stays a lean overview.

Add an explicit numbered workflow (extract hives → parse with SBECmd → validate/confirm CSV → run scripts/process.py → correlate → document using assets/template.md), with a validation checkpoint, and reference references/workflows.md for the detail.

Wire the bundled scripts into the body — show concrete invocations of scripts/agent.py and scripts/process.py so the most executable artifacts are actually surfaced.

DimensionReasoningScore

Conciseness

Mostly efficient with genuine tool commands and shell-item internals, but the ~55-line fabricated SBECmd output block and registry-location tables duplicate content already in references/, and the Overview explains some basics, so not every token earns its place.

2 / 3

Actionability

Concrete executable SBECmd commands and documented output columns are present, but the bundled scripts/agent.py and scripts/process.py — the most actionable artifacts — are never invoked or referenced from the body, leaving a key executable path implicit.

2 / 3

Workflow Clarity

Sections are present (Prerequisites, Analysis, Scenarios, Limitations) but there is no explicit end-to-end sequenced workflow with validation checkpoints in the body, and forensic hive processing warrants a validate step; the existing references/workflows.md is not pointed to.

2 / 3

Progressive Disclosure

A real bundle exists (references/, scripts/, assets/) but the body never signals or links to any of it — registry/API tables are duplicated inline instead of referenced, and the bundle files are orphaned rather than navigated to from SKILL.md.

2 / 3

Total

8

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and complete, clearly stating both the capability and when to use it in third person. It is a strong, low-conflict skill description.

DimensionReasoningScore

Specificity

Names multiple concrete actions with specific tools — 'Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer', 'reconstruct folder browsing activity', 'prove user interaction with directories, including removable media and network shares' — matching the anchor for listing several specific concrete actions.

3 / 3

Completeness

Explicitly answers both what (analyze shellbag artifacts with SBECmd/Shellbags Explorer to reconstruct and prove folder access) and when via the explicit trigger 'Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work.'

3 / 3

Trigger Term Quality

Natural terms a DFIR user would actually say are well covered — 'shellbag', 'BagMRU', 'registry artifacts', 'folder browsing activity', 'folder access history', 'removable media', 'network shares', 'DFIR' — satisfying the good-coverage anchor.

3 / 3

Distinctiveness Conflict Risk

The Windows Shellbag/BagMRU forensics niche is highly specific with distinct triggers, making it unlikely to fire for an unrelated skill.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.