Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body delivers concrete, well-sequenced incident-response guidance with specific commands and time-boxed priorities, and a genuine verification section. Its main weaknesses are undiscoverable bundle files (the reference guide and automation script are never mentioned), some explanatory padding of widely known security concepts, and missing feedback loops in verification.
Suggestions
Add a short "Resources" section pointing to references/api-reference.md (CISA URLs, NIST mapping, reporting channels) and scripts/agent.py (playbook generation and compliance checking), so the bundled materials are discoverable from SKILL.md.
Trim the Key Concepts and Tools & Systems tables to only non-obvious entries (e.g., RTO/RPO in this context) and drop definitions of widely known concepts like Double Extortion, MITRE ATT&CK, and NIST CSF.
Turn the Verification section into a feedback loop: after the tabletop exercise or checklist validation, explicitly instruct to record gaps, revise the playbook, and re-validate until no critical gaps remain.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The core body is dense, high-value material — checklists, detection indicators, and a recovery priority matrix with time windows — with specific commands like "Reset ALL passwords including service accounts, krbtgt (twice, 12h apart)". However, the Key Concepts table defines terms Claude already knows ("Double Extortion", "Patient Zero", "Tabletop Exercise") and Tools & Systems re-describes NIST CSF and MITRE ATT&CK, so it is efficient with minor over-explanation rather than fully lean (5). | 4 / 5 |
Actionability | Guidance is concrete and specific — "Disable or restrict RDP; require VPN for remote access", "Sysmon Event ID 11 (file creation) spikes", "Rebuild affected systems from known-clean images (do NOT decrypt in place)" — with a time-boxed containment and recovery matrix. It falls short of 5 because there is no example of the playbook deliverable itself and no invocation of the bundled automation despite the "Python 3.8+ for playbook generation and compliance checking automation" prerequisite. | 4 / 5 |
Workflow Clarity | A clear five-step sequence (Preparation → Detection → Containment → Eradication/Recovery → Post-Incident) is followed by a Verification section ("Validate playbook completeness against CISA StopRansomware checklist items", "Conduct tabletop exercise"). Not 5 because verification steps are listed without explicit feedback loops (e.g., "if gaps are found, revise the playbook and re-run the tabletop"), keeping checkpoints implicit rather than error-recovering. | 4 / 5 |
Progressive Disclosure | The body is well-sectioned with clear headers, but the bundle files references/api-reference.md and scripts/agent.py exist and are never referenced or signaled anywhere in SKILL.md, making them undiscoverable; the inlined CISA checklist detail also duplicates content that belongs in the reference file. This matches the 3 anchor ("references present but not clearly signaled; content that should be separate is inline") rather than 4, where references would be mostly clear. | 3 / 5 |
Total | 15 / 20 Passed |