Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is highly actionable — every phase is executable copy-paste commands — but it is a padded 480-line monolith that restates well-known SSH knowledge with redundant tool variants, and its batch/destructive operations lack validation checkpoints. Splitting reference material into bundle files and trimming to non-obvious content would address both weaknesses.
Suggestions
Trim redundant tool variants (keep 2-3 representative Hydra/Medusa invocations) and drop the "Required Knowledge" and port-forwarding-syntax explanations that restate what Claude already knows; target the non-obvious content (ssh-audit interpretation, CVE-specific techniques, evasion flags).
Add validation checkpoints to the workflow: verify found credentials with a single confirmed login before post-exploitation, and confirm written authorization as an explicit Phase 0 gate before any active attacks.
Move the full Paramiko script, the Metasploit module catalog, and the quick-reference tables into references/ files (e.g. references/scripts.md, references/metasploit.md) linked from SKILL.md, keeping the body as a lean overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~480-line body restates knowledge Claude already has: a "Required Knowledge" section listing "SSH protocol fundamentals / Public/private key authentication / Port forwarding concepts", seven near-duplicate Hydra variants, four Medusa variants, and full explanations of standard ssh -L/-R/-D syntax. Not 1 because the content is accurate and organized, but the padding and redundancy are extensive. | 2 / 5 |
Actionability | Every phase gives copy-paste-ready commands (nmap NSE invocations with script-args, hydra/medusa syntax including port and timing flags, a complete runnable Paramiko script) covering the common cases. Fully executable with no pseudocode. | 5 / 5 |
Workflow Clarity | Phases 1-10 are clearly sequenced, but the workflow involves batch and destructive operations (brute-force runs, appending a key to ~/.ssh/authorized_keys for persistence) with no validation or verification checkpoints — e.g. verifying credentials before post-exploitation or confirming authorization before attacks. Per the rubric cap, destructive/batch workflows without validation cannot score above 3. | 3 / 5 |
Progressive Disclosure | Section headers and quick-reference tables provide reasonable structure, but it is a monolithic single file with zero external references; the full Paramiko script and the Metasploit module catalog are inlined where they belong in separate reference files. Not 2 because the internal structure is genuinely well-organized, not 4 because nothing is split out. | 3 / 5 |
Total | 13 / 20 Passed |