CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-lsass-ticket-material

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for LSASS-resident secrets, Windows logon sessions, Kerberos ticket caches, DPAPI-backed material, SSP artifacts, and replayable credential extraction. Use when the user asks to inspect LSASS memory, recover tickets or logon sessions, trace DPAPI or SSP material, distinguish which credential artifacts are replayable, or connect host-resident credential material to an accepted pivot or privilege edge. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured instruction-only skill with clear sequencing, an explicit prove-acceptance validation checkpoint, and a well-signaled one-level reference that actually contains the detail. Its only real gap is actionability: it specifies which evidence to capture but stays abstract on the executable extraction step.

Suggestions

Add one or two concrete extraction commands or tool invocations (e.g., the specific dump/ticket-parsing command) so the operational "how" is executable rather than implied, lifting actionability toward the copy-paste-ready anchor.

Optionally fold the overlapping Quick-Start and Workflow "distinguish replayable" and "smallest decisive chain" items so each framing adds distinct value and the body tightens further.

DimensionReasoningScore

Conciseness

The body is terse and assumes Claude's competence — it never explains what LSASS, DPAPI, or Kerberos are — and every section earns its place; the mild Quick-Start/Workflow restatement is intentional summary-plus-detail structure rather than concept-padding or token bloat.

3 / 3

Actionability

It is concrete about which artifacts to record (LUIDs, SPNs, encryption types, ticket flags, acceptance via SMB/WinRM/Schannel/DPAPI unwrap) but provides no executable commands or tool names for the extraction itself, leaving the operational "how" abstract; the instruction-only scoring note softens the code requirement, but the execution guidance is still incomplete versus the "copy-paste ready" anchor.

2 / 3

Workflow Clarity

A clear three-step sequence (Map → Prove Replay/Acceptance → Reduce) with an explicit validation checkpoint — "Distinguish material that is present from material that is actually replayable" — plus an evidence checklist ("What To Preserve") and a handoff rule for scope creep, matching the clear-sequence-with-validation anchor.

3 / 3

Progressive Disclosure

The SKILL.md is a lean overview with a well-signaled one-level-deep reference — "Load `references/lsass-ticket-material.md` for the session checklist, replay checklist, and evidence packaging" — and that file exists and holds the detailed checklists, exactly the clear-overview-with-one-level-references pattern.

3 / 3

Total

11

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, sharply scoped description that names concrete actions, surfaces natural trigger phrases, answers both what and when, and uses explicit downstream routing to avoid conflict. It hits the score-3 anchor on every dimension.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "inspect LSASS memory, recover tickets or logon sessions, trace DPAPI or SSP material, distinguish which credential artifacts are replayable" — over a clearly named domain, matching the "lists multiple specific concrete actions" anchor. Uses imperative/third-person voice ("Use when the user asks..."), consistent with the good examples, so no first/second-person penalty applies.

3 / 3

Completeness

It explicitly answers both "what" (the LSASS/ticket/DPAPI/SSP credential-extraction workflow) and "when" via an explicit "Use when the user asks to..." clause, satisfying the both-what-and-when-with-explicit-triggers anchor; a Use-when clause is present so completeness is not capped at 2.

3 / 3

Trigger Term Quality

The "Use when" clause surfaces natural verb-noun phrases a CTF user would actually say ("inspect LSASS memory", "recover tickets", "trace DPAPI or SSP material", "distinguish which credential artifacts are replayable"), giving good coverage of natural terms rather than abstract jargon.

3 / 3

Distinctiveness Conflict Risk

The niche is sharply scoped to LSASS-resident/ticket-cache credential material and explicitly routed ("Internal downstream skill for ctf-sandbox-orchestrator", "Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here"), making overlap with sibling skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.