CtrlK
BlogDocsLog inGet started
Tessl Logo

windows-ad

Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/windows-ad/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured AD/Windows identity skill body with concrete commands, explicit safety checkpoints, and a real one-level reference file. It is consistently strong across dimensions, with only minor gaps in command completeness for some paths and external-reference organization.

DimensionReasoningScore

Conciseness

Lean, terse prose with checkbox lists and a compact tool table that assumes Claude already knows AD/Kerberos concepts; minor redundancy from the scenario list re-covering the description and the routing/self-check metadata adding overhead.

4 / 5

Actionability

Provides real executable commands ('nxc smb <range> -u user -p pass', 'bloodhound-python -d domain.local ...') and a tool-to-purpose table, but several attack paths are named only as technique+tool hints without copy-paste commands.

4 / 5

Workflow Clarity

Clear sequenced workflow (enumerate -> paths -> credentials/lateral) with explicit authorization/evidence/user-confirmation checkpoints and a completion self-check; lacks a true validate->fix->retry error-recovery loop, keeping it just below the top anchor.

4 / 5

Progressive Disclosure

Well-organized sections with a clearly signaled one-level-deep bundle reference (references/ad-attack-paths.md, verified present), but the 参考 section mixes that internal reference with several external cross-skill paths and seeds, slightly scattering navigation.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-targeted, third-person description that names a clear niche and concrete techniques with an explicit 'Use for' trigger. It is strong overall, with only minor room to improve trigger synonyms and to separate the 'when' guidance more explicitly.

DimensionReasoningScore

Specificity

Names the AD/Windows-identity domain and several concrete attack categories ('Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation'), but the governing verbs ('attacks', 'research') stay somewhat generic rather than naming discrete actions.

4 / 5

Completeness

Explicit 'Use for ...' trigger covers 'when' and the named techniques cover 'what', but the two are merged into one clause rather than separately enumerating user-mention trigger situations, so the 'when' could be more explicit.

4 / 5

Trigger Term Quality

Strong natural terms a pentest user would actually say ('Active Directory', 'Kerberos', 'BloodHound', 'NTLM relay', 'AD CS'), though common synonyms like 'Kerberoasting', 'domain controller', 'DCSync', or 'golden ticket' are absent.

4 / 5

Distinctiveness Conflict Risk

The 'authorized Active Directory and Windows identity attacks' niche with named techniques is a clear, distinct trigger set with minimal risk of firing for unrelated skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.