CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-identity-windows

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Active Directory, Kerberos, LDAP, OAuth, enterprise messaging, Windows host forensics, credential material, and lateral-movement challenges. Use when the user asks to trace tickets or tokens, inspect mailbox rules, analyze Windows host evidence, understand an AD trust path, or explain a lateral-movement chain across sandbox-linked nodes. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured analytical skill body that assumes Claude's competence, packs concrete artifact and field references without padding, and cleanly delegates detail to a single real reference file. The main gaps are minor internal redundancy and the lack of explicit validation feedback loops, which are less critical for a non-destructive analysis workflow.

DimensionReasoningScore

Conciseness

Dense, token-efficient artifact enumerations ('SAM, SECURITY, SYSTEM, NTDS, DPAPI, LSA secrets, ETW, Sysmon...') with no concept over-explanation; minor redundancy between Quick Start step 3 and Workflow section 3, and between 'What To Preserve' and the Workflow bullets, keeps it just below lean-and-perfect.

4 / 5

Actionability

Concrete, specific guidance with named fields to record ('ticket type, SPN, delegation mode, PAC or group data, encryption type, and cache location') and a concrete chain format ('foothold -> recovered artifact -> replay path -> pivot host -> resulting capability'); as an instruction-only skill the absence of code is acceptable, but some guidance remains abstract and there are no copy-paste-ready examples.

4 / 5

Workflow Clarity

A clear 5-step Quick Start sequence ending in a verification step ('Reproduce the privilege edge or mail effect from the smallest viable chain') plus a reference checklist and Common Pitfalls for error recovery; the skill is analytical rather than destructive/batch so the cap does not apply, but explicit validate-fix-retry feedback loops are absent.

4 / 5

Progressive Disclosure

A concise overview body with a clearly signaled one-level-deep reference ('Load references/identity-windows.md for the ticket, host, and enterprise-messaging checklist'), the referenced file verified to exist, plus well-organized sections and routing bullets to sibling skills for easy navigation.

5 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-constructed niche description that clearly states both purpose and trigger conditions with an explicit downstream-routing boundary. It is comprehensive in domain coverage and distinctiveness, held back only slightly by abstract action verbs and overlap with closely related sibling skills.

DimensionReasoningScore

Specificity

Lists several specific actions (trace, inspect, analyze, understand, explain) across a comprehensive identity/Windows/messaging domain, but the verbs are somewhat abstract and the framing 'workflow for X challenges' leaves minor coverage gaps.

4 / 5

Completeness

Explicitly answers both what ('CTF-sandbox workflow for Active Directory, Kerberos, LDAP, OAuth...') and when ('Use when the user asks to trace tickets or tokens, inspect mailbox rules...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural keyword coverage ('tickets or tokens', 'mailbox rules', 'Windows host evidence', 'AD trust path', 'lateral-movement chain') for the target audience, but lacks synonyms and file extensions that would push it to comprehensive.

4 / 5

Distinctiveness Conflict Risk

The explicit routing boundary ('Use only after $ctf-sandbox-orchestrator has already established sandbox assumptions and routed here') gives a clear niche, but many sibling skills cover overlapping identity/Windows ground, leaving minor overlap risk.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.