Content
65%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is an exceptionally actionable command reference with a coherent phase-based workflow, but it is a near-monolithic 500-line SKILL.md: duplicated quick-reference tables, no validation checkpoints in a workflow full of destructive operations, and only a single reference file. Splitting per-platform content out and adding verification steps would address the main gaps.
Suggestions
Split each platform's phases into reference files (e.g. references/azure.md, references/aws.md, references/gcp.md) with a short SKILL.md overview and workflow, turning the single end-of-file reference into well-signaled navigation — this also removes the need for the duplicate Quick Reference tables.
Add validation checkpoints after each destructive or batch step, e.g. confirm a backdoor key works with 'aws sts get-caller-identity' before moving on, and verify service-principal role grants with 'Get-AzRoleAssignment' before relying on persistence.
Delete or merge the Quick Reference tables (they restate commands already shown verbatim in the phases) and keep the tool list and troubleshooting table, which carry genuinely new information.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is command-dense with almost no explanatory padding, but the 'Quick Reference' tables (Azure/AWS/GCP Key Commands, Metadata Service URLs) largely restate commands already shown in the phases, adding roughly 60 lines of redundant tokens. Mostly efficient but with a clear tightenable duplication, matching anchor 3. | 3 / 5 |
Actionability | Nearly every section is copy-paste-ready CLI/PowerShell/bash with concrete flags, queries, and three fully worked examples (Azure password spray, S3 enumeration, GCP service-account pivot). Specific and executable throughout, matching the fully-executable anchor. | 5 / 5 |
Workflow Clarity | The 11 phases give a clear, coherent sequence from reconnaissance through persistence, but there are no validation checkpoints anywhere (e.g. verifying role assignments after privilege escalation, confirming key validity after backdoor creation). Per the rubric's explicit cap, a workflow involving destructive/batch operations (backdoor service principals, access-key creation, password spraying) without validation cannot score above 3. | 3 / 5 |
Progressive Disclosure | Section structure is clear and the single reference (references/advanced-cloud-scripts.md) is real, one level deep, and well-signaled — but it appears only at the very end, and ~490 lines are inlined where per-platform content (e.g. the per-cloud phases or quick-reference tables) clearly belongs in separate reference files. This matches anchor 3: structure present but content that should be separate is inline. | 3 / 5 |
Total | 14 / 20 Passed |