Content
65%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body delivers a well-sequenced, fully executable privesc playbook with concrete payloads for every major vector. Its weaknesses are efficiency and structure: it re-lists basic enumeration commands Claude already knows, duplicates material in a quick-reference section, keeps everything in one long file instead of splitting references, and lacks validation checkpoints around its destructive steps.
Suggestions
Add explicit validation checkpoints between phases of the destructive steps (e.g., verify a kernel exploit on a test snapshot before running it, confirm a writable cron script's permissions and cron daemon status before injecting a payload) so the workflow doesn't rely on the post-hoc Troubleshooting table.
Cut Phase 1's basic-command listings down to the handful of privesc-relevant commands (sudo -l, SUID find, getcap, crontab, exports) and drop the Quick Reference table that duplicates them, or move both into a reference file.
Split the monolithic body: move the kernel-exploit table, reverse-shell one-liners, worked examples, and troubleshooting table into one-level-deep reference files (e.g., references/kernel-exploits.md, references/payloads.md) and keep SKILL.md as the phased overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body avoids concept explanations, but Phase 1 spends ~80 lines listing trivial commands Claude already knows (hostname, whoami, id, env, ps aux, ifconfig, cat /etc/issue), and the Quick Reference table plus reverse-shell one-liners repeat or extend material already covered. Mostly efficient with clear trim opportunities, matching anchor 3 rather than anchor 4's 'minor instances'. | 3 / 5 |
Actionability | Every phase is copy-paste executable: complete enumeration commands, an LD_PRELOAD C source with its exact gcc invocation, concrete GTFOBins-style sudo/SUID payloads, a writable-cron hijack, PATH hijack, and an NFS SUID-shell recipe. This matches anchor 5 — executable, specific examples covering the common cases. | 5 / 5 |
Workflow Clarity | The nine phases are clearly sequenced, but destructive operations (kernel exploits that 'may crash the system', overwriting cron scripts, writing to /etc/shadow) have no inline validation checkpoints — only a post-hoc Troubleshooting table and a guardrail sentence. The rubric's cap for destructive workflows without validation applies, holding this at anchor 3 rather than 4. | 3 / 5 |
Progressive Disclosure | Section headers and a quick-reference summary give real structure, but ~500 lines are inlined in one monolithic SKILL.md with no bundle files — the kernel-exploit table, reverse-shell one-liners, worked examples, and troubleshooting table are prime candidates for one-level-deep reference files. This fits anchor 3 ('content that should be separate is inline') better than anchor 2, since navigation via headers is present and clear. | 3 / 5 |
Total | 14 / 20 Passed |