Content
63%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body delivers a well-sequenced, mostly executable five-step workflow with real API/STIX/ATT&CK code and a validation checklist, but it is dragged down by boilerplate sections, a non-functional correlation function, an OTX endpoint inconsistent with its own bundle reference, and complete failure to link the bundled references/api-reference.md and scripts/agent.py.
Suggestions
Link the existing bundle files from the body (e.g., under References: "OTX/ATT&CK API details: see references/api-reference.md; full collector script: scripts/agent.py") and move the inline API/tactic tables and endpoint details there to resolve the OTX URL contradiction and shrink SKILL.md.
Fix or remove Step 4's correlate_infrastructure — it initializes ip_to_domains/domain_to_ips but never populates them, so shared_ips is always empty; either implement the correlation or drop the dead logic. Also add attackcti to Prerequisites.
Cut the generic "When to Use" boilerplate ("When deploying or configuring building threat actor profile from osint capabilities..."), the description-duplicating Overview, and the Known-concepts recitation in Key Concepts; replace the hardcoded APT29 prose with a short placeholder.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly efficient — the bulk is domain-specific executable code that earns its tokens — but several sections pad it: the Overview restates the frontmatter description, "When to Use" is auto-generated boilerplate ("When deploying or configuring building threat actor profile from osint capabilities in your environment"), "Key Concepts" recites frameworks Claude already knows (Diamond Model, ACH), and Step 2 embeds a large hardcoded APT29 prose description as sample data. Not 2 because the padding is a minority of the content and the code blocks themselves are not verbose; not 4 because the boilerplate and dead code (Step 4's never-populated sets) are clearly trimmable. | 3 / 5 |
Actionability | Four of the five workflow steps give concrete, largely executable code (real OTX/VirusTotal/Shodan requests, STIX 2.1 object construction, attackcti TTP extraction, dossier generation), which meets "mostly executable guidance with minor gaps". The gaps: Step 4's correlate_infrastructure initializes ip_to_domains/domain_to_ips but never adds members, so shared_ips is always empty (dead logic for the core correlation claim); the OTX URL ("/api/v1/search/pulses") conflicts with the bundled api-reference.md ("/api/v1/pulses/search"); and the attackcti dependency used in Step 3 is absent from Prerequisites. Not 3 because the majority of code is genuinely copy-paste runnable; not 5 because these are real defects a user would hit. | 4 / 5 |
Workflow Clarity | A clearly sequenced five-step pipeline (collect → structure in STIX → map TTPs → correlate infrastructure → generate dossier) with a terminal "Validation Criteria" checklist (6 explicit criteria). Not 5 because there are no per-step validation checkpoints or error-recovery loops — API calls silently return on non-200, no rate-limit/failure handling — so checkpoints are end-loaded rather than inline. Not 3 because the sequence is explicit, each step names its inputs/outputs, and a concrete validation checklist does exist (well above "checkpoints missing or implicit"). No destructive/batch cap applies. | 4 / 5 |
Progressive Disclosure | The bundle contains references/api-reference.md and scripts/agent.py, but the SKILL.md body never signals either — the "References" section lists only external URLs, so the bundle files are orphaned and the api-reference content (OTX endpoints, ATT&CK tactic IDs) is instead partially duplicated inline (with a conflicting OTX URL). Structure itself is decent (## sections, numbered steps), matching "some structure but references present but not clearly signaled; content that should be separate is inline". Not 2 because the body is well-sectioned, not an unstructured wall; not 4 because zero of the provided bundle files are navigable from the body. | 3 / 5 |
Total | 14 / 20 Passed |