Content
72%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a tight, well-organized instruction-only overview with sound progressive disclosure to a real reference file, but it leans on methodology and artifact checklists rather than executable commands, and its workflow lacks explicit validation feedback loops.
Suggestions
Add at least one concrete, executable verification step (e.g., a command or check to confirm a reproduced privilege edge) to lift actionability and give the workflow an explicit checkpoint.
Include an explicit feedback loop after the reproduction step (e.g., 'if the chain does not reproduce, revisit the accepting-service or pivot-host step') so workflow validation is stated, not implied.
Optionally add 1–2 specific tool/command hints (e.g., for ticket parsing or hive inspection) to turn the artifact checklist into more directly actionable guidance.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean (~50 lines) with compact bullets and assumes Claude's knowledge of AD/Kerberos/Windows artifacts rather than explaining them, so every token earns its place; not below because there is no padded concept explanation. | 3 / 3 |
Actionability | It gives concrete directives and enumerates exact artifacts/fields to capture ('SAM, SECURITY, SYSTEM, NTDS, DPAPI, LSA secrets, ETW, Sysmon'), but provides no executable commands, tooling, or copy-paste repro steps, so guidance is specific yet incomplete; not score 3 because nothing is directly executable. | 2 / 3 |
Workflow Clarity | Quick Start provides a clear five-step sequence and sectioned workflow, and step 5 ('Reproduce the privilege edge or mail effect from the smallest viable chain') acts as a soft checkpoint, but there is no explicit validation/feedback loop ('if reproduction fails, return to step N'); not score 3 because checkpoints are implicit rather than explicit. | 2 / 3 |
Progressive Disclosure | SKILL.md is a concise overview pointing to a single one-level-deep reference ('Load `references/identity-windows.md`'), which exists as a real file, with well-organized sections and clear sibling-skill routing; not below because navigation is clean and content is appropriately split. | 3 / 3 |
Total | 10 / 12 Passed |