Content
72%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An excellent executable command catalog — every entry is copy-paste ready with realistic flags and targets. Weaknesses are structural: it masquerades as a workflow without any sequence or authorization/scope validation checkpoints (capped accordingly), and it is a monolithic single-file dump rather than an overview with per-tool reference files.
Suggestions
Add explicit validation checkpoints before risky operations: verify written authorization and target scope before any exploit or brute-force step, per the destructive-operations guideline.
Split the per-tool catalogs (nmap, metasploit, nikto, sqlmap, hydra, john, aircrack-ng, tshark) into references/ files and keep SKILL.md as a concise index with one-level-deep links.
Remove the duplicated nmap commands in 'Quick Reference' (or fold them into the Nmap section) and drop or merge the filler Prerequisites/Outputs lists.
Label the 'Password Hash Types' table correctly (the Mode numbers are hashcat modes, not john formats) or move it to a john/hashcat reference.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is almost entirely executable commands with one-line comments and no padding or explanations of concepts Claude already knows — efficient for a command reference. Not a 5 because the 'Quick Reference' section re-repeats nmap scans already covered above, and the generic 'Inputs/Prerequisites' and 'Outputs/Deliverables' sections add little actionable value. | 4 / 5 |
Actionability | Every entry is a complete, copy-paste-ready command with real flags and placeholder targets (e.g., "nmap --script smb-vuln-ms17-010 192.168.1.1", "hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.1"), covering the common cases per tool. This matches the fully-executable, common-cases-covered anchor. | 5 / 5 |
Workflow Clarity | Despite the 'Core Workflow' heading, there is no sequenced workflow — just a parallel tool catalog — and no validation checkpoints anywhere (no verify-authorization-before-running step, no confirm-target-scope check before exploitation or brute force). The rubric caps destructive/batch-operation skills without validation at 3, and the 'Always have written authorization' bullet is a constraint list, not an enforced checkpoint, so it cannot exceed 3. | 3 / 5 |
Progressive Disclosure | The per-tool sections are clearly headed and navigable, but all ~430 lines live monolithically in SKILL.md with no references/ files at all — content that clearly belongs in separate per-tool references is inlined. This is the anchor-3 profile (structure present, content that should be separate is inline); not 2 because section headers make it navigable, not 4 because no material is split out. | 3 / 5 |
Total | 15 / 20 Passed |