CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attacks

Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./plugins/agentic-awesome-skills-claude/skills/active-directory-attacks/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, command-dense skill body that assumes Claude's competence and avoids concept explanations, but its workflows lack explicit validation checkpoints for destructive operations and carry some redundant boilerplate that could be trimmed or moved to the reference file.

Suggestions

Insert explicit validation checkpoints between risky stages (e.g., 'verify credentials with a read-only command before exploitation', 'confirm DCSync succeeded by dumping krbtgt before forging a Golden Ticket', 'verify password restore after ZeroLogon') to lift workflow clarity.

Consolidate the three separate authorization/warning blocks into one gate and remove the filler 'When to Use' sentence and the duplicated 'Purpose' paragraph to tighten conciseness.

Consider moving the Critical CVEs and AD CS sections into references/advanced-attacks.md so SKILL.md reads as a tighter overview with a cleaner split across files.

DimensionReasoningScore

Conciseness

The body is a lean command reference with no basic-concept padding ('Essential Tools' table, terse code blocks, quick-reference and troubleshooting tables), but has minor trimmable redundancy: three overlapping authorization banners, a 'Purpose' section duplicating the frontmatter description verbatim, and the filler line 'This skill is applicable to execute the workflow or actions described in the overview.'

4 / 5

Actionability

Nearly every section gives copy-paste-ready, tool-specific commands with correct details (e.g., 'hashcat -m 13100' / '-m 18200' modes, 'GetUserSPNs.py ... -request -outputfile', 'certipy req ... -template VulnTemplate -upn'), and worked examples cover common cases end-to-end.

5 / 5

Workflow Clarity

The 'Core Workflow' steps are sequenced and Example 1/2 give numbered chains, but there are no explicit validation checkpoints between risky stages (e.g., verify cracked credentials or confirm DC sync before forging tickets); per the rubric, destructive/batch operations without validation cap workflow clarity at 3, so it cannot score 4 despite the clear ordering.

3 / 5

Progressive Disclosure

A single one-level-deep reference (references/advanced-attacks.md, verified to exist with nine clearly-titled sections) is well signaled under 'Additional Resources' with an accurate content summary, but the main body is fairly monolithic — CVE exploits, AD CS attacks, and the quick-reference table are inlined rather than split out — so it sits at 'good structure with minor organization gaps' rather than the cleanly split top anchor.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped offensive-security description with strong capability coverage and low conflict risk, but it lacks an explicit 'Use when...' trigger clause, capping completeness and leaving natural trigger synonyms unused.

Suggestions

Append an explicit trigger clause such as 'Use when the user mentions Active Directory, AD, domain controllers, Kerberos tickets, or red team / pentest engagements against a domain.'

Add natural synonyms and shorthand users actually say (e.g., 'AD', 'domain controller', 'post-exploitation') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

The description names six concrete attack categories — 'reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance' — giving comprehensive, specific coverage of the domain, matching the top anchor; there are no meaningful gaps that would justify a 4.

5 / 5

Completeness

The 'what' is clearly stated ('Provide comprehensive techniques for attacking Microsoft Active Directory environments'), but there is no 'Use when...' clause or equivalent explicit trigger guidance — the trailing 'for red team operations and penetration testing' only weakly implies when, which the rubric caps at 3.

3 / 5

Trigger Term Quality

It includes natural terms users would say such as 'Active Directory', 'red team', 'penetration testing', and 'Kerberos attacks', but misses common variations like 'AD', 'domain controller', or 'post-exploitation', so it falls just below the comprehensive-synonyms anchor of 5.

4 / 5

Distinctiveness Conflict Risk

'attacking Microsoft Active Directory environments' with Kerberos and domain-dominance terminology carves out a clear niche with distinct triggers and minimal overlap risk with other skills; it is not merely 4 since no closely related skill would plausibly collide on these triggers.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.