Content
72%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable technique catalog with copy-paste-ready commands for every method, well organized with selection tables and troubleshooting. Its weaknesses are structural: no explicit exploit-verification workflow despite destructive operations, and a monolithic single-file layout where per-OS reference files would ease navigation and token cost.
Suggestions
Add an explicit workflow with verification checkpoints: enumerate (sudo -l, getcap -r /, PowerUp) → select via the quick-reference table → execute → verify success (id / whoami /groups) before persistence, which would satisfy the destructive-operation validation requirement.
Split the Linux, Windows, and AD technique catalogs into one-level-deep reference files (e.g. references/linux.md, references/windows.md, references/ad-attacks.md) with a well-signaled pointer from each section, keeping SKILL.md as the overview plus the quick-reference table.
Merge the overlapping 'Golden Ticket' and 'Golden Ticket with Scheduled Tasks' sections and drop the Examples section that duplicates Core Techniques content, replacing it with a single end-to-end worked example including verification output.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean and assumes Claude's competence — terse command blocks with inline comments, tables, and no explanation of concepts Claude already knows. It is not a 5 because of redundancy: 'Golden Ticket' and 'Golden Ticket with Scheduled Tasks' overlap heavily, and the Examples section repeats Core Techniques content (sudo vim shell, GetUserSPNs.py Kerberoasting). | 4 / 5 |
Actionability | Nearly every technique ships copy-paste-ready commands with real flags ('sudo find /etc/passwd -exec /bin/bash \;', 'GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.100 -request', 'hashcat -m 13100'), plus a technique-selection table and concrete troubleshooting pairs. Minor contextual gaps (e.g. 'execute-assembly sweetpotato.exe' assumes a C2 framework) do not detract from covering the common cases. | 5 / 5 |
Workflow Clarity | Order is implicit (prerequisites → technique catalog → selection table → constraints → examples → troubleshooting) and the Constraints section says to verify the target OS before selecting a technique, but there is no explicit enumerate → select → exploit → verify-success sequence, and success verification ('id') appears only in Example 1. Per the rubric guideline, destructive operations (chmod +s /bin/bash, GPO-created admin user, persistence) without validation checkpoints cap workflow clarity at 3. | 3 / 5 |
Progressive Disclosure | No bundle files exist and all ~330 lines live in SKILL.md. The per-OS technique catalogs (Linux, Windows, AD) are natural candidates for one-level-deep reference files, and the 'Additional Resources' pointers are external tools rather than navigable skill files. In-file structure is good (clear headers, quick-reference table), which keeps this at the midpoint rather than 2. | 3 / 5 |
Total | 15 / 20 Passed |