CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attacks

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.

60

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/active-directory-attacks/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with comprehensive, copy-paste-ready AD attack commands and a clearly signaled reference file, but it is verbose and monolithic with weak validation checkpoints for its destructive operations.

Suggestions

Move the per-technique command catalogs (Critical CVEs, Kerberos Ticket Attacks, AD CS) into reference files and keep SKILL.md a concise overview with the Core Workflow and Quick Reference, improving both conciseness and progressive disclosure.

Add explicit validation/checkpoint steps for destructive ops — e.g., confirm the ZeroLogon password reset took effect and verify restore afterward; check account-lockout thresholds before spraying — to raise workflow clarity above 2.

Remove the duplicated Quick Reference table or the Examples that restate commands already shown in the technique sections to cut redundancy.

DimensionReasoningScore

Conciseness

Sections are mostly lean command blocks rather than concept explanations, but the ~380-line body carries redundancy — the Quick Reference table and the Examples section restate commands already shown in Credential Attacks and Ticket Attacks — plus Purpose/Inputs/Outputs overhead that could be tightened.

2 / 3

Actionability

It provides dense, executable, copy-paste-ready commands across impacket, mimikatz, rubeus, certipy, hashcat, and crackmapexec with concrete flags and targets, matching the fully-executable anchor.

3 / 3

Workflow Clarity

A Core Workflow and numbered examples give a sequence, but destructive/batch operations such as the ZeroLogon DC password reset and password spraying lack explicit validate-then-proceed feedback loops, capping clarity at 2 per the destructive-operations rule.

2 / 3

Progressive Disclosure

There is one real, clearly signaled one-level reference (references/advanced-attacks.md), but SKILL.md itself is monolithic — CVE exploits, ticket attacks, ADCS, and relay sections are all inline rather than split into references — so content that should be separate stays inline.

2 / 3

Total

9

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has excellent trigger coverage and a clear, conflict-resistant AD niche, but it is phrased as a trigger list rather than an action-first capability statement, leaving the 'what does this do' portion implicit.

Suggestions

Lead with concrete action verbs before the trigger clause — e.g., 'Performs Active Directory attack techniques — Kerberoasting, DCSync, pass-the-hash, ticket forging, and NTLM relay. Use when ...' — so the capability is stated explicitly.

Replace the meta phrasing 'This skill should be used when the user asks to ...' with the standard 'Use when ...' form and keep the enumerated technique terms as the 'when' triggers to separate what-and-when.

DimensionReasoningScore

Specificity

It names the AD attack domain and technique labels (Kerberoasting, DCSync, pass-the-hash) but is trigger-first rather than action-first, and the only capability verb is the vague 'needs guidance on Windows domain penetration testing', so concrete actions are implied rather than stated.

2 / 3

Completeness

An explicit 'should be used when the user asks to ...' trigger clause answers 'when', but the 'what' is weak and merged with the triggers, leaning on 'guidance on Windows domain penetration testing' rather than stating concrete capabilities — not the clearly separated what-and-when of a level 3 example.

2 / 3

Trigger Term Quality

It lists a strong set of natural terms a user would actually say ('attack Active Directory', 'Kerberoasting', 'DCSync', 'pass-the-hash', 'Golden Ticket', 'NTLM relay'), giving good coverage of the domain's common phrasings.

3 / 3

Distinctiveness Conflict Risk

The niche is highly specific (Windows AD offensive techniques) with distinct, domain-only triggers, making it unlikely to fire for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.