Content
65%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a highly actionable, command-dense reference with excellent copy-paste guidance and worked examples, and it commendably avoids explaining concepts Claude already knows. Its weaknesses are structural: everything is inlined in one ~490-line file with no progressive disclosure, destructive operations lack verification/rollback checkpoints, and version-sensitive exploit catalogs and duplicated examples inflate the token budget.
Suggestions
Split the body into reference files (e.g., references/credential-locations.md, references/kernel-exploits.md, references/examples.md) and keep SKILL.md as a concise overview with one-level-deep, clearly signaled links, following the progressive-disclosure model.
Add verification checkpoints to destructive operations: after catching a shell run whoami to confirm SYSTEM/elevation, and before modifying a service with sc config, capture the original binpath (sc qc) with instructions to restore it if exploitation fails.
De-duplicate the Examples section (which repeats Core Workflow commands like accesschk, AlwaysInstallElevated reg queries, and JuicyPotato) and move version-sensitive lists (MS/CVE kernel exploits, per-Windows-version Potato tooling) into a dedicated reference file so stale version data can be maintained without bloating context.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is almost entirely dense, useful commands with no padding explanations of concepts Claude already knows, which is efficient. However, version-sensitive catalogs are inlined rather than isolated (MS-kernel-exploit list, "JuicyPotato (Windows Server 2019 and below)", CVE list), and the Examples section largely repeats Core Workflow commands, so it could be materially tightened. Not 4 because the version-drift material and duplication are more than minor instances. | 3 / 5 |
Actionability | Nearly everything is copy-paste executable: exact commands with flags (icacls C:\Windows\System32\config\SAM with an explicit "Vulnerable if: BUILTIN\Users:(I)(RX)" marker), full exploit command lines, msfvenom payload generation, and five worked end-to-end examples. Placeholders like <service> and 10.10.10.10 are appropriate parameterization; only one clearly broken line (dir /S /B *pass*.txt == *pass*.xml ...) detracts. | 5 / 5 |
Workflow Clarity | A clear 1-6 numbered sequence exists with pre-exploit vulnerability checks ("Both must return 0x1 for vulnerability") and a Troubleshooting table for error recovery. But destructive operations — service binpath modification, MSI install, kernel exploits that "may cause system instability" — lack post-action verification (e.g., confirming SYSTEM via whoami) and any rollback of the original service config, so the destructive-operations cap applies. Not 4 because the validation gaps here are more than minor. | 3 / 5 |
Progressive Disclosure | Section headers are clear and well-ordered, giving reasonable in-file navigation. But the skill is a ~490-line monolithic SKILL.md with no bundle files at all — the Examples section, quick-reference tables, kernel exploit catalog, and credential-search location lists clearly belong in separate reference files. Anchor 3 rather than 4 because content that should be separate is fully inlined and no references exist to signal. | 3 / 5 |
Total | 14 / 20 Passed |