CtrlK
BlogDocsLog inGet started
Tessl Logo

windows-ad

Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-organized, token-efficient overview with concrete enumeration commands and good progressive disclosure into a real reference file. Its weaknesses are incomplete command-level guidance for the attack paths and missing validation feedback loops for destructive credential operations.

Suggestions

Replace the checkbox-style attack-path descriptions (e.g., '□ Kerberoast / AS-REP → 离线破解') with concrete, copy-paste-ready commands (e.g., the actual impacket/Certipy/Rubeus invocation) so guidance is fully executable.

Add an explicit validate→fix→retry checkpoint for destructive credential operations (secretsdump/mimikatz/golden ticket), such as verifying authorization scope and confirming output integrity before proceeding, to lift workflow clarity above 2.

Clarify or remove cross-skill external references (../field-journal/, ../attack-chain/) by either linking to concrete sections or noting they are optional context, so navigation stays one level deep and unambiguous.

DimensionReasoningScore

Conciseness

The body is lean — short workflow sections, a compact tool table, and checkbox lists — with no explanation of concepts Claude already knows; every section earns its place and it assumes Claude's competence.

3 / 3

Actionability

It includes some concrete executable commands ('nxc smb <range> -u user -p pass', 'bloodhound-python -d domain.local ...') and a specific tool table, but many attack paths are listed as checkbox descriptions (□ Kerberoast / AS-REP → 离线破解) rather than copy-paste-ready commands, leaving guidance incomplete.

2 / 3

Workflow Clarity

A clear sequence is present (1. 枚举 → 2. 路径 → 3. 凭证与横向) with an ACTION REQUIRED ordering block and a self-check checklist, but destructive credential operations (secretsdump, mimikatz, golden ticket) lack an explicit validate→fix→retry feedback loop, capping clarity at 2.

2 / 3

Progressive Disclosure

The body acts as an overview pointing one level deep to the real, confirmed reference file 'references/ad-attack-paths.md' plus clearly signaled cross-skill paths, with content appropriately split rather than monolithic.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise yet specific, naming concrete attack techniques and providing an explicit 'Use for' trigger clause that answers both what and when. Voice is appropriately third person with no first/second-person phrasing to penalize.

DimensionReasoningScore

Specificity

It lists multiple concrete attack categories — 'Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation' — matching the anchor for listing several specific concrete actions rather than vague language.

3 / 3

Completeness

It answers both what (AD/Windows identity attack techniques) and when via the explicit 'Use for authorized... attacks' trigger clause, satisfying the requirement for an explicit use-when clause rather than only implying it.

3 / 3

Trigger Term Quality

Terms like 'Active Directory', 'Kerberos', 'AD CS', 'BloodHound', 'NTLM relay', and 'domain privilege escalation' are natural keywords a security tester would actually say, giving good coverage of common variations.

3 / 3

Distinctiveness Conflict Risk

It carves out a clear niche — authorized AD/Windows identity attacks — with distinct triggers unlikely to fire for unrelated skills, and is unlikely to overlap with broader pentest skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.