Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The skill reads as a clean, well-organized overview with a sensible seven-step hunt workflow and a concrete output template, but it stays at the descriptive level: no example queries or commands in the body, no feedback loops for refuted hypotheses, and — most critically — none of the six bundle files (references, scripts, assets/template.md) are ever referenced, so the detailed content is undiscoverable. It is a solid skeleton that needs its flesh wired in via explicit pointers and a few concrete executable examples.
Suggestions
Add one or two concrete example queries (e.g., a Splunk SPL or Defender KQL hunting query) under 'Execute Queries', or link to references/workflows.md where the per-platform queries already live.
Reference the bundle files explicitly in the body — e.g., 'Detailed per-platform workflows: see [references/workflows.md](references/workflows.md)', 'Hypothesis builder: scripts/agent.py', 'Hunt report template: assets/template.md' — so the existing detail content is discoverable from SKILL.md.
Add feedback loops to the workflow: what to do when a hypothesis is refuted or queries return no data (refine the hypothesis, expand data sources/time window, re-run), and a checkpoint before documenting that findings were correlated across at least two data sources.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is table-driven and lean overall, but the 'Key Concepts' table ('TA0001 | Initial Access', 'TA0003 | Persistence') restates standard ATT&CK tactic mappings Claude already knows, and the 'When to Use' bullet 'indicators of building threat hunt hypothesis framework' is templated filler. These are minor trim candidates, matching 'efficient; minor instances of over-explanation'. | 4 / 5 |
Actionability | 'Execute Queries: Run detection queries against SIEM and EDR platforms' and 'Analyze Results: Examine query results for anomalies' are high-level directions with no actual SPL/KQL example, command, or script invocation anywhere in the body — the concrete queries live in references/workflows.md and scripts/ but are never surfaced. The Output Format template is the only concretely executable artifact, so guidance is present but incomplete ('some concrete guidance but incomplete; missing key details'), not the minimal-hints level of a 2. | 3 / 5 |
Workflow Clarity | The seven steps (Formulate → Identify Data Sources → Execute → Analyze → Validate → Correlate → Document) are clearly sequenced and 'Validate Findings: Distinguish true positives from false positives' is a named validation step. However, there are no feedback loops or checkpoints — no guidance on iterating when a hypothesis is refuted, queries return no data, or a data source is missing — so checkpoints are implicit rather than explicit, matching 'steps listed but validation gaps'. | 3 / 5 |
Progressive Disclosure | The body itself is well-sectioned (When to Use, Prerequisites, Workflow, Tools, Scenarios, Output Format), but it never mentions any of the provided bundle files — references/workflows.md (with the actual platform queries), references/api-reference.md, references/standards.md, scripts/agent.py, scripts/process.py, and assets/template.md are all invisible to a reader of SKILL.md. The structure is better than 'minimal' (not a 2), but the complete absence of links/pointers to existing detail files falls short of the clear signaled navigation of a 4 or 5. | 3 / 5 |
Total | 13 / 20 Passed |