CtrlK
BlogDocsLog inGet started
Tessl Logo

windows-privilege-escalation

This skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows misconfigurations," or "perform post-exploitation privilege escalation." It provides comprehensive guidance for discovering and exploiting privilege escalation vulnerabilities in Windows environments.

60

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/windows-privilege-escalation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a highly actionable, command-dense reference with excellent copy-paste guidance and worked examples, and it commendably avoids explaining concepts Claude already knows. Its weaknesses are structural: everything is inlined in one ~490-line file with no progressive disclosure, destructive operations lack verification/rollback checkpoints, and version-sensitive exploit catalogs and duplicated examples inflate the token budget.

Suggestions

Split the body into reference files (e.g., references/credential-locations.md, references/kernel-exploits.md, references/examples.md) and keep SKILL.md as a concise overview with one-level-deep, clearly signaled links, following the progressive-disclosure model.

Add verification checkpoints to destructive operations: after catching a shell run whoami to confirm SYSTEM/elevation, and before modifying a service with sc config, capture the original binpath (sc qc) with instructions to restore it if exploitation fails.

De-duplicate the Examples section (which repeats Core Workflow commands like accesschk, AlwaysInstallElevated reg queries, and JuicyPotato) and move version-sensitive lists (MS/CVE kernel exploits, per-Windows-version Potato tooling) into a dedicated reference file so stale version data can be maintained without bloating context.

DimensionReasoningScore

Conciseness

The body is almost entirely dense, useful commands with no padding explanations of concepts Claude already knows, which is efficient. However, version-sensitive catalogs are inlined rather than isolated (MS-kernel-exploit list, "JuicyPotato (Windows Server 2019 and below)", CVE list), and the Examples section largely repeats Core Workflow commands, so it could be materially tightened. Not 4 because the version-drift material and duplication are more than minor instances.

3 / 5

Actionability

Nearly everything is copy-paste executable: exact commands with flags (icacls C:\Windows\System32\config\SAM with an explicit "Vulnerable if: BUILTIN\Users:(I)(RX)" marker), full exploit command lines, msfvenom payload generation, and five worked end-to-end examples. Placeholders like <service> and 10.10.10.10 are appropriate parameterization; only one clearly broken line (dir /S /B *pass*.txt == *pass*.xml ...) detracts.

5 / 5

Workflow Clarity

A clear 1-6 numbered sequence exists with pre-exploit vulnerability checks ("Both must return 0x1 for vulnerability") and a Troubleshooting table for error recovery. But destructive operations — service binpath modification, MSI install, kernel exploits that "may cause system instability" — lack post-action verification (e.g., confirming SYSTEM via whoami) and any rollback of the original service config, so the destructive-operations cap applies. Not 4 because the validation gaps here are more than minor.

3 / 5

Progressive Disclosure

Section headers are clear and well-ordered, giving reasonable in-file navigation. But the skill is a ~490-line monolithic SKILL.md with no bundle files at all — the Examples section, quick-reference tables, kernel exploit catalog, and credential-search location lists clearly belong in separate reference files. Anchor 3 rather than 4 because content that should be separate is fully inlined and no references exist to signal.

3 / 5

Total

14

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit, well-phrased trigger clause with natural user phrasings and a clearly distinct Windows-privesc niche. Its main weakness is a generic what-statement that never enumerates the skill's concrete capabilities (enumeration, credential harvesting, service exploitation, token impersonation, kernel exploits), which are instead only visible in the body.

Suggestions

Replace "provides comprehensive guidance" in the what-clause with the concrete capability areas the skill actually covers, e.g. "Enumerates system and service misconfigurations, harvests credentials, exploits unquoted service paths and AlwaysInstallElevated, performs token impersonation (Potato attacks), and applies kernel exploits on Windows."

Add one or two common natural phrasings users would say, such as "get a SYSTEM shell" or "gain Administrator on a Windows box," to round out trigger coverage.

DimensionReasoningScore

Specificity

The what-clause "provides comprehensive guidance for discovering and exploiting privilege escalation vulnerabilities in Windows environments" names the domain plus two actions (discovering, exploiting) but lists no concrete sub-capabilities such as credential harvesting, service exploitation, or token impersonation. It fits anchor 3 (1-2 concrete actions, not comprehensive) rather than 4, which requires several specific actions.

3 / 5

Completeness

Both what and when are present, and the "should be used when the user asks to..." clause is highly explicit with concrete trigger phrases. Not 5 because the what-side is generic ("comprehensive guidance") rather than enumerating the skill's concrete capabilities.

4 / 5

Trigger Term Quality

Five quoted natural triggers ("escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows misconfigurations," "perform post-exploitation privilege escalation") give good keyword coverage including the "privesc" synonym. Not 5 because common variations like "get SYSTEM" or "gain Administrator access" are missing.

4 / 5

Distinctiveness Conflict Risk

Windows privilege escalation is a clear niche with distinct quoted trigger phrases ("Windows privesc vectors," "Windows misconfigurations"), so it is unlikely to fire for unrelated skills and is clearly distinguishable from e.g. Linux privesc skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.