CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-lsass-ticket-material

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for LSASS-resident secrets, Windows logon sessions, Kerberos ticket caches, DPAPI-backed material, SSP artifacts, and replayable credential extraction. Use when the user asks to inspect LSASS memory, recover tickets or logon sessions, trace DPAPI or SSP material, distinguish which credential artifacts are replayable, or connect host-resident credential material to an accepted pivot or privilege edge. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, lean instruction skill that delegates detail to a single clearly signaled reference and lays out a sequenced analysis workflow with an embedded verification checkpoint. The main weaknesses are Quick-Start/Workflow content overlap and tool-agnostic guidance that stops short of executable commands.

Suggestions

Tighten the overlap between Quick Start and Workflow so each field/artifact list appears in one place, or have Quick Start explicitly defer to the Workflow phases for detail.

Add a few concrete tool-agnostic or named-tool invocations (e.g., a sekurlsa/tickets dump or Rubeus export command) so the actionability reaches fully executable guidance for the common extraction cases.

Make the verify→retry dynamic explicit in the Prove Replay step (e.g., "if no accepting service is found, return to step 1 to re-scope the artifact") to strengthen the workflow feedback loop.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's knowledge (no explanations of what LSASS/Kerberos/DPAPI are), but the Quick Start steps and the Workflow phases cover overlapping ground—distinguishing replayable material and recording the same artifact fields appear in both—so a few tokens repeat rather than each earning its place uniquely.

4 / 5

Actionability

Concrete field-level checklists (LUIDs, SPN, ticket flags, encryption type, package names) and named acceptance edges (SMB, WinRM, Schannel, DPAPI unwrap) give specific guidance; as an instruction-only skill no-code is not penalized, but it stops short of any tool-specific command, leaving minor gaps versus fully executable guidance.

4 / 5

Workflow Clarity

A clear Map → Prove Replay → Reduce sequence with a verification checkpoint ("Prove Replay Or Acceptance" / "Reproduce the smallest host-artifact-to-accepted-privilege path that proves the decisive edge"); the destructive/batch cap does not apply to this read-only analysis skill, but there is no explicit validate→fix→retry loop, keeping it at 4 rather than 5.

4 / 5

Progressive Disclosure

A well-structured overview (Quick Start, Workflow, Read This Reference, What To Preserve) with a clearly signaled one-level-deep reference to the verified `references/lsass-ticket-material.md` whose contents (session checklist, replay checklist, evidence packaging) are named in the body, matching the score-5 anchor.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-triggered description that clearly states both capability and activation conditions while staking out a distinct niche with explicit parent/sibling boundaries. The only gap is the absence of a few common attacker-style trigger phrases that users would naturally say.

Suggestions

Add natural attacker phrasing to the trigger clause (e.g., "dump LSASS", "pass-the-ticket", "pass-the-hash", "Kerberoasting", "golden/silver tickets") so the description matches how users actually phrase these requests.

DimensionReasoningScore

Specificity

Lists multiple concrete actions—"inspect LSASS memory, recover tickets or logon sessions, trace DPAPI or SSP material, distinguish which credential artifacts are replayable, or connect host-resident credential material to an accepted pivot or privilege edge"—with comprehensive domain coverage, matching the score-5 anchor rather than 4 (which expects minor gaps).

5 / 5

Completeness

Explicitly answers both what ("CTF-sandbox workflow for LSASS-resident secrets, Windows logon sessions, Kerberos ticket caches, DPAPI-backed material, SSP artifacts, and replayable credential extraction") and when ("Use when the user asks to inspect LSASS memory...") with concrete trigger phrases, matching the score-5 anchor.

5 / 5

Trigger Term Quality

Good natural-term coverage (LSASS memory, tickets, logon sessions, DPAPI, SSP, replayable credentials, pivot/privilege edge), but common attacker phrasing users would say—"dump LSASS", "pass-the-ticket", "pass-the-hash", "Kerberoasting", golden/silver tickets—is missing, so it sits at 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

A clear niche (LSASS/ticket-cache/DPAPI/SSP credential material) with explicit boundary guidance—"Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here"—minimizing conflict risk with sibling skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.