CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-ad-certificate-abuse

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-organized instruction skill that assumes competence and uses a clean one-level reference. Its weakness is actionability and workflow checkpoints: guidance is specific but lacks executable commands, and validation steps are implicit.

Suggestions

Add at least one concrete, copy-paste-ready command or snippet for the highest-value step (e.g., the exact certutil/PowerShell to enumerate template enrollment rights or dump an issued cert) to lift actionability toward 3.

Insert an explicit verification checkpoint in the workflow — e.g., 'Confirm the cert is accepted by the target service before declaring privilege' as a distinct validate/confirm step — to make workflow clarity explicit.

Add a short 'common pitfalls / when to stop' validation block (mirroring the reference's pitfalls) so Claude re-checks cert acceptance rather than stopping at template misconfiguration.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it never explains what AD CS or a certificate is, and every line directs action. It is not 2 because there is no padding or unnecessary explanation to tighten.

3 / 3

Actionability

Guidance names concrete fields and acceptance paths ('Record EKUs, subject or SAN controls, issuance requirements, enrollment rights' and 'PKINIT, Schannel, LDAPS, WinRM'), but it stays at an instructional checklist level with no copy-paste-ready commands or code. It is not 3 because nothing is executable/ready-to-run, and not 1 because the direction is specific rather than abstract.

2 / 3

Workflow Clarity

Steps are clearly sequenced (Quick Start 1–5 and Workflow sections 1–3) and Quick Start step 5 acts as a reproduction check, but there is no explicit validate→fix→retry checkpoint. It is not 3 because checkpoints are implicit rather than stated, and not 1 because the sequence is unambiguous.

2 / 3

Progressive Disclosure

A clear overview points to a single one-level-deep, real reference ('Load references/ad-certificate-abuse.md'), and the body is appropriately split into well-organized sections. It is not 2 because the reference is well-signaled and there is no nested/inline overload.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and covers both what the skill does and when to use it with natural trigger terms. Its explicit downstream-routing clause sharply reduces conflict risk with sibling skills.

DimensionReasoningScore

Specificity

The description enumerates concrete capability surfaces — 'certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths' — rather than vague abstractions. It uses third-person voice and lists multiple specific actions, matching the top anchor.

3 / 3

Completeness

It explicitly answers both what the skill does (AD CS / cert-based privilege paths) and when to use it via an explicit 'Use when...' trigger clause. It is not capped at 2 because the trigger guidance is explicit, not merely implied.

3 / 3

Trigger Term Quality

The 'Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy' clause covers natural phrasings a user would actually say. It is not below 3 because coverage spans the common variations users invoke.

3 / 3

Distinctiveness Conflict Risk

The narrow AD CS niche, ESC-style triggers, and explicit routing ('Use only after $ctf-sandbox-orchestrator ... has already established sandbox assumptions') make it unlikely to fire for the wrong skill. It is clearly distinguishable rather than overlapping.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.