CtrlK
BlogDocsLog inGet started
Tessl Logo

privilege-escalation-methods

This skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "Kerberoasting", "pass-the-ticket", "token impersonation", or needs guidance on post-exploitation privilege escalation for Linux or Windows systems.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/privilege-escalation-methods/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable technique catalog with copy-paste-ready commands for every method, well organized with selection tables and troubleshooting. Its weaknesses are structural: no explicit exploit-verification workflow despite destructive operations, and a monolithic single-file layout where per-OS reference files would ease navigation and token cost.

Suggestions

Add an explicit workflow with verification checkpoints: enumerate (sudo -l, getcap -r /, PowerUp) → select via the quick-reference table → execute → verify success (id / whoami /groups) before persistence, which would satisfy the destructive-operation validation requirement.

Split the Linux, Windows, and AD technique catalogs into one-level-deep reference files (e.g. references/linux.md, references/windows.md, references/ad-attacks.md) with a well-signaled pointer from each section, keeping SKILL.md as the overview plus the quick-reference table.

Merge the overlapping 'Golden Ticket' and 'Golden Ticket with Scheduled Tasks' sections and drop the Examples section that duplicates Core Techniques content, replacing it with a single end-to-end worked example including verification output.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — terse command blocks with inline comments, tables, and no explanation of concepts Claude already knows. It is not a 5 because of redundancy: 'Golden Ticket' and 'Golden Ticket with Scheduled Tasks' overlap heavily, and the Examples section repeats Core Techniques content (sudo vim shell, GetUserSPNs.py Kerberoasting).

4 / 5

Actionability

Nearly every technique ships copy-paste-ready commands with real flags ('sudo find /etc/passwd -exec /bin/bash \;', 'GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.100 -request', 'hashcat -m 13100'), plus a technique-selection table and concrete troubleshooting pairs. Minor contextual gaps (e.g. 'execute-assembly sweetpotato.exe' assumes a C2 framework) do not detract from covering the common cases.

5 / 5

Workflow Clarity

Order is implicit (prerequisites → technique catalog → selection table → constraints → examples → troubleshooting) and the Constraints section says to verify the target OS before selecting a technique, but there is no explicit enumerate → select → exploit → verify-success sequence, and success verification ('id') appears only in Example 1. Per the rubric guideline, destructive operations (chmod +s /bin/bash, GPO-created admin user, persistence) without validation checkpoints cap workflow clarity at 3.

3 / 5

Progressive Disclosure

No bundle files exist and all ~330 lines live in SKILL.md. The per-OS technique catalogs (Linux, Windows, AD) are natural candidates for one-level-deep reference files, and the 'Additional Resources' pointers are external tools rather than navigable skill files. In-file structure is good (clear headers, quick-reference table), which keeps this at the midpoint rather than 2.

3 / 5

Total

15

/

20

Passed

Description

72%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A trigger-term-first description with excellent natural keyword coverage and a well-defined niche, but it never articulates what the skill actually provides, leaving the 'what' half generic. Adding a concrete capability statement before the 'use when' clause would make it fully complete.

Suggestions

Lead with a concrete 'what' statement before the trigger list, e.g. 'Provides ready-to-run privilege escalation techniques for Linux (sudo, cron, capabilities, NFS) and Windows (token impersonation, service abuse, AD attacks)' instead of the generic 'needs guidance on...'.

State the deliverables a user gets from invoking the skill — enumeration commands, per-technique exploitation commands, and a technique-selection quick reference — so the description answers 'what' as explicitly as it answers 'when'.

Trim the quoted trigger list to the highest-signal phrases and fold the named attack techniques into the capability statement, which would raise specificity without adding length.

DimensionReasoningScore

Specificity

The description names the domain ('post-exploitation privilege escalation for Linux or Windows systems') and lists concrete technique names ('abuse sudo', 'exploit SUID binaries', 'Kerberoasting', 'pass-the-ticket'), but only as trigger phrases — it never states what the skill itself does (e.g., enumerates misconfigurations, provides ready-to-run commands per technique). This matches the anchor for naming the domain with limited concrete action coverage; it falls short of 4 because the skill's own capabilities are unstated.

3 / 5

Completeness

The 'when' half is explicit and trigger-rich ('This skill should be used when the user asks to...'), but the 'what' half is only the generic phrase 'needs guidance on post-exploitation privilege escalation' — no statement of deliverables such as enumeration, technique reference, or commands. One half is strong while the other is weak, which sits at the midpoint rather than clearly answering both.

3 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including slang and synonyms a user would actually say: 'escalate privileges', 'get root access', 'become administrator', 'privesc techniques', 'abuse sudo', plus named techniques like 'Kerberoasting' and 'token impersonation'. No common variation is missing.

5 / 5

Distinctiveness Conflict Risk

Clear niche (post-exploitation privilege escalation on Linux/Windows) with distinct technique-named triggers ('Kerberoasting', 'pass-the-ticket', 'exploit SUID binaries') that are unlikely to fire for unrelated skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.