Content
64%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a highly actionable skill with extensive, executable command examples covering a broad range of AD attack techniques. Its main weaknesses are the monolithic structure that could benefit from splitting into referenced sub-files, and the lack of integrated validation checkpoints within multi-step attack workflows. The content is mostly concise but has some redundancy and boilerplate that could be trimmed.
Suggestions
Integrate explicit validation checkpoints into multi-step workflows (e.g., 'Verify DCSync rights before attempting: crackmapexec ldap ... --check-replication-rights') rather than listing constraints separately at the end.
Split the content into referenced sub-files (e.g., kerberos-attacks.md, credential-attacks.md, relay-attacks.md, cve-exploits.md) and keep SKILL.md as a concise overview with the quick reference table and links.
Remove the redundant 'When to Use' boilerplate and consolidate the tool table with the quick reference table to reduce duplication.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The skill is mostly efficient with concrete commands rather than explanations, but includes some unnecessary sections like the 'Purpose' restating the description, the 'Inputs/Prerequisites' and 'Outputs/Deliverables' sections that are somewhat obvious, and the 'When to Use' boilerplate at the end. The tool table and quick reference table are somewhat redundant with each other. | 2 / 3 |
Actionability | Nearly every technique includes fully executable, copy-paste-ready commands with specific tool invocations, flags, and arguments. Multiple tool alternatives are provided for each attack type, and the examples section shows complete end-to-end attack chains with numbered steps. | 3 / 3 |
Workflow Clarity | The core workflow has numbered steps and the examples show sequenced attack chains, but validation checkpoints are largely missing. For destructive operations like ZeroLogon exploitation, the password restore step is mentioned but there's no explicit 'verify before proceeding' pattern. The constraints section lists some safety checks but they're separated from the workflow rather than integrated as validation gates. | 2 / 3 |
Progressive Disclosure | The content references 'references/advanced-attacks.md' for advanced techniques, which is good progressive disclosure, but no bundle files exist to support this reference. The main file itself is quite long (~300 lines) and could benefit from splitting credential attacks, Kerberos attacks, and CVE exploits into separate referenced files rather than inlining everything. | 2 / 3 |
Total | 9 / 12 Passed |