CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-identity-windows

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Active Directory, Kerberos, LDAP, OAuth, enterprise messaging, Windows host forensics, credential material, and lateral-movement challenges. Use when the user asks to trace tickets or tokens, inspect mailbox rules, analyze Windows host evidence, understand an AD trust path, or explain a lateral-movement chain across sandbox-linked nodes. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, well-organized instruction-only overview with sound progressive disclosure to a real reference file, but it leans on methodology and artifact checklists rather than executable commands, and its workflow lacks explicit validation feedback loops.

Suggestions

Add at least one concrete, executable verification step (e.g., a command or check to confirm a reproduced privilege edge) to lift actionability and give the workflow an explicit checkpoint.

Include an explicit feedback loop after the reproduction step (e.g., 'if the chain does not reproduce, revisit the accepting-service or pivot-host step') so workflow validation is stated, not implied.

Optionally add 1–2 specific tool/command hints (e.g., for ticket parsing or hive inspection) to turn the artifact checklist into more directly actionable guidance.

DimensionReasoningScore

Conciseness

The body is lean (~50 lines) with compact bullets and assumes Claude's knowledge of AD/Kerberos/Windows artifacts rather than explaining them, so every token earns its place; not below because there is no padded concept explanation.

3 / 3

Actionability

It gives concrete directives and enumerates exact artifacts/fields to capture ('SAM, SECURITY, SYSTEM, NTDS, DPAPI, LSA secrets, ETW, Sysmon'), but provides no executable commands, tooling, or copy-paste repro steps, so guidance is specific yet incomplete; not score 3 because nothing is directly executable.

2 / 3

Workflow Clarity

Quick Start provides a clear five-step sequence and sectioned workflow, and step 5 ('Reproduce the privilege edge or mail effect from the smallest viable chain') acts as a soft checkpoint, but there is no explicit validation/feedback loop ('if reproduction fails, return to step N'); not score 3 because checkpoints are implicit rather than explicit.

2 / 3

Progressive Disclosure

SKILL.md is a concise overview pointing to a single one-level-deep reference ('Load `references/identity-windows.md`'), which exists as a real file, with well-organized sections and clear sibling-skill routing; not below because navigation is clean and content is appropriately split.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is precise, third-person, and gives both a clear capability scope and explicit natural-language triggers, with a downstream-routing guard that sharply reduces conflict risk. It is concise despite covering a broad identity/security domain.

DimensionReasoningScore

Specificity

Lists multiple concrete capability domains ('Active Directory, Kerberos, LDAP, OAuth, enterprise messaging, Windows host forensics, credential material, and lateral-movement challenges') and specific actions ('trace tickets or tokens, inspect mailbox rules, analyze Windows host evidence'), matching the 'multiple specific concrete actions' anchor; not below because it goes well beyond naming only a domain.

3 / 3

Completeness

Explicitly answers both what ('CTF-sandbox workflow for...') and when via an explicit 'Use when the user asks to...' clause, satisfying the 'both what AND when with explicit triggers' anchor.

3 / 3

Trigger Term Quality

Triggers use natural phrasings a CTF user would actually say ('trace tickets or tokens', 'inspect mailbox rules', 'analyze Windows host evidence', 'understand an AD trust path', 'explain a lateral-movement chain'), giving good coverage; not below because the terms are concrete and varied rather than generic jargon.

3 / 3

Distinctiveness Conflict Risk

It carves a clear niche (identity/Windows/enterprise-messaging within a sandbox) and adds an explicit guard ('Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here'), making conflict with sibling skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.