CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attacks

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, highly actionable command reference with a proper one-level reference split and real validation steps for risky operations. It consistently stops just short of top marks due to duplicated summary tables, placeholder values without acquisition guidance, and an incomplete final example step.

Suggestions

Remove or merge the "Quick Reference" table (and its overlap with the "Essential Tools" table) — the commands duplicate content already shown in their own sections.

Complete Example 2's final step with the actual RBCD commands (e.g., setting delegation on the target machine with the created machine account) instead of ending on a bare comment.

Move the full CVE exploit walkthroughs (ZeroLogon, PrintNightmare, samAccountName spoofing) into a reference file, keeping a one-line summary and link inline to shorten the SKILL.md overview.

DimensionReasoningScore

Conciseness

Mostly lean, command-dense content with no explanation of concepts Claude already knows, but the "Essential Tools" table and "Quick Reference" table largely duplicate commands already shown in their sections and could be trimmed.

4 / 5

Actionability

Mostly copy-paste ready commands with correct real-world syntax (hashcat -m 13100/18200, full Impacket/Rubeus flags) covering common cases, but some placeholders (HASH, CA-NAME, S-1-5-21-xxx) go unexplained and Example 2 ends on a comment with no command for the final RBCD step.

4 / 5

Workflow Clarity

A clear Core Workflow sequence (clock sync → BloodHound recon → PowerView enumeration) with validation present (SMB signing check, CVE vulnerability pre-checks, the critical ZeroLogon password-restore step, and a troubleshooting table), though individual attack sections lack explicit post-exploitation verification checkpoints.

4 / 5

Progressive Disclosure

A well-sectioned body with a clearly signaled, one-level-deep reference to references/advanced-attacks.md (which exists and matches the described topics), but the ~385-line body inlines full CVE walkthroughs and AD CS attacks that could partly move to reference files.

4 / 5

Total

16

/

20

Passed

Description

86%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with excellent, comprehensive trigger-term coverage and a clear niche. Its main weakness is that the "what" — what the skill actually does or provides — is only implied via "needs guidance on", while the attack names serve as triggers rather than capability statements.

DimensionReasoningScore

Specificity

Names many concrete techniques ("Kerberoasting", "DCSync", "pass-the-hash", "Golden Ticket", "AS-REP roasting") with comprehensive coverage, but they are framed as trigger phrases rather than explicitly stating the skill's actions or capabilities.

4 / 5

Completeness

Has an explicit and specific "when" clause ("This skill should be used when the user asks to...") with concrete triggers, but the "what" is only implied by "needs guidance on Windows domain penetration testing" — the skill's actual capabilities are never stated.

4 / 5

Trigger Term Quality

Comprehensive coverage of natural terms users would say, including synonyms and variations: "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "NTLM relay", and "Windows domain penetration testing".

5 / 5

Distinctiveness Conflict Risk

A clear niche (Active Directory attack techniques) with distinct named triggers like DCSync and Kerberoasting; minimal risk of triggering for the wrong skill.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.