Content
75%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-organized, highly actionable command reference with a proper one-level reference split and real validation steps for risky operations. It consistently stops just short of top marks due to duplicated summary tables, placeholder values without acquisition guidance, and an incomplete final example step.
Suggestions
Remove or merge the "Quick Reference" table (and its overlap with the "Essential Tools" table) — the commands duplicate content already shown in their own sections.
Complete Example 2's final step with the actual RBCD commands (e.g., setting delegation on the target machine with the created machine account) instead of ending on a bare comment.
Move the full CVE exploit walkthroughs (ZeroLogon, PrintNightmare, samAccountName spoofing) into a reference file, keeping a one-line summary and link inline to shorten the SKILL.md overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly lean, command-dense content with no explanation of concepts Claude already knows, but the "Essential Tools" table and "Quick Reference" table largely duplicate commands already shown in their sections and could be trimmed. | 4 / 5 |
Actionability | Mostly copy-paste ready commands with correct real-world syntax (hashcat -m 13100/18200, full Impacket/Rubeus flags) covering common cases, but some placeholders (HASH, CA-NAME, S-1-5-21-xxx) go unexplained and Example 2 ends on a comment with no command for the final RBCD step. | 4 / 5 |
Workflow Clarity | A clear Core Workflow sequence (clock sync → BloodHound recon → PowerView enumeration) with validation present (SMB signing check, CVE vulnerability pre-checks, the critical ZeroLogon password-restore step, and a troubleshooting table), though individual attack sections lack explicit post-exploitation verification checkpoints. | 4 / 5 |
Progressive Disclosure | A well-sectioned body with a clearly signaled, one-level-deep reference to references/advanced-attacks.md (which exists and matches the described topics), but the ~385-line body inlines full CVE walkthroughs and AD CS attacks that could partly move to reference files. | 4 / 5 |
Total | 16 / 20 Passed |