CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-ad-certificate-abuse

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-organized instruction-only skill that defers detail to a single real reference file and sequences its workflow clearly. The main gap is actionability — it tells Claude what to record and reason about but provides no executable commands or reproduction tooling, and the workflow lacks explicit validation checkpoints.

Suggestions

Add at least one concrete reproduction command or tool invocation (e.g. a certutil/Certipy enrollment and mapping example) so the decisive issuance-to-acceptance chain is executable, not just described.

Insert an explicit validation checkpoint in the Workflow (e.g. 'Confirm the issued cert is accepted by the target service before declaring privilege') to close the validation gap.

Record the expected evidence artifact format (command output fields or a compact evidence block) so the 'Reproduce the smallest chain' step yields verifiable output.

DimensionReasoningScore

Conciseness

Lean body that assumes Claude's competence: no concept explanations, no padded preamble, every line is an actionable directive or a field to record, well under the token budget.

5 / 5

Actionability

Guidance is concrete in intent (named fields to record, named acceptance paths like PKINIT/Schannel/LDAPS/WinRM, a target reference file) but contains no executable commands, code, or tool invocations; it instructs what to capture rather than how to run anything.

3 / 5

Workflow Clarity

A clearly numbered Quick Start plus a three-stage Workflow with explicit sequencing and a hand-off rule back to the Kerberos skill, but there are no validation checkpoints or verify-before-proceed steps for the issuance-to-acceptance reproduction.

4 / 5

Progressive Disclosure

Well-structured overview with a single one-level-deep reference ('Load references/ad-certificate-abuse.md') that resolves to a real bundle file; sections are clearly signaled and the heavy detail is correctly deferred to the reference.

5 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with explicit 'what' and 'when' clauses, concrete domain-specific trigger terms, and a clear routing boundary against sibling skills. Slightly less granular in naming discrete actions than the top anchor, hence not a perfect specificity score.

DimensionReasoningScore

Specificity

Names the domain (AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping) and several concrete surfaces, but lists capability areas rather than discrete actions like 'enumerate', 'map', or 'reproduce'.

4 / 5

Completeness

Explicitly answers 'what' (CTF-sandbox workflow for AD CS, templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, cert-based privilege paths) and 'when' with a concrete 'Use when...' clause enumerating multiple trigger conditions.

5 / 5

Trigger Term Quality

Includes strong natural trigger phrases a user would say ('ESC-style abuse', 'certificate templates', 'enrollment agents', 'EKUs', 'SAN or subject controls', 'smartcard or PKINIT logon', 'CA policy'), though it lacks looser synonyms or file extensions.

4 / 5

Distinctiveness Conflict Risk

Carves a clear niche (cert-based privilege paths in an AD CS CTF sandbox) and adds a routing guard ('Use only after $ctf-sandbox-orchestrator has already established sandbox assumptions and routed here'), minimizing overlap with adjacent Kerberos/delegation skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.