Content
76%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, command-dense skill body that assumes Claude's competence and avoids concept explanations, but its workflows lack explicit validation checkpoints for destructive operations and carry some redundant boilerplate that could be trimmed or moved to the reference file.
Suggestions
Insert explicit validation checkpoints between risky stages (e.g., 'verify credentials with a read-only command before exploitation', 'confirm DCSync succeeded by dumping krbtgt before forging a Golden Ticket', 'verify password restore after ZeroLogon') to lift workflow clarity.
Consolidate the three separate authorization/warning blocks into one gate and remove the filler 'When to Use' sentence and the duplicated 'Purpose' paragraph to tighten conciseness.
Consider moving the Critical CVEs and AD CS sections into references/advanced-attacks.md so SKILL.md reads as a tighter overview with a cleaner split across files.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is a lean command reference with no basic-concept padding ('Essential Tools' table, terse code blocks, quick-reference and troubleshooting tables), but has minor trimmable redundancy: three overlapping authorization banners, a 'Purpose' section duplicating the frontmatter description verbatim, and the filler line 'This skill is applicable to execute the workflow or actions described in the overview.' | 4 / 5 |
Actionability | Nearly every section gives copy-paste-ready, tool-specific commands with correct details (e.g., 'hashcat -m 13100' / '-m 18200' modes, 'GetUserSPNs.py ... -request -outputfile', 'certipy req ... -template VulnTemplate -upn'), and worked examples cover common cases end-to-end. | 5 / 5 |
Workflow Clarity | The 'Core Workflow' steps are sequenced and Example 1/2 give numbered chains, but there are no explicit validation checkpoints between risky stages (e.g., verify cracked credentials or confirm DC sync before forging tickets); per the rubric, destructive/batch operations without validation cap workflow clarity at 3, so it cannot score 4 despite the clear ordering. | 3 / 5 |
Progressive Disclosure | A single one-level-deep reference (references/advanced-attacks.md, verified to exist with nine clearly-titled sections) is well signaled under 'Additional Resources' with an accurate content summary, but the main body is fairly monolithic — CVE exploits, AD CS attacks, and the quick-reference table are inlined rather than split out — so it sits at 'good structure with minor organization gaps' rather than the cleanly split top anchor. | 4 / 5 |
Total | 16 / 20 Passed |