CtrlK
BlogDocsLog inGet started
Tessl Logo

capability-primitive-search

能力原语+状态空间搜索:read/write/exec/ssrf等原语凑RCE等式A-F,低危映射,正反向搜索,跨域兑现。Use when no single RCE, chaining low-severity vulns, or deriving novel attack chains.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/capability-primitive-search/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an extremely token-dense methodology — six RCE equations, a low-severity-to-primitive mapping table, bidirectional search procedures, and a tentative-vs-confirmed validation rule — with essentially no waste. Its weaknesses are structural: a single wall-of-text code block with no section headers, and no worked example showing the search procedure applied end-to-end.

Suggestions

Break the single code block into markdown sections (e.g. '## 能力原语', '## RCE等式A-F', '## 低危→原语映射', '## 状态空间搜索', '## 突破口') so the body is navigable at a glance.

Add one compact worked example showing the backward search applied to a concrete target (facts → chosen equation → missing primitive → candidate chain → per-segment verification), which would make the abstract search procedure fully actionable.

Expand the validation guidance into an explicit checkpoint: what to record when a segment fails (note/chain tentative state), when to switch equations, and when to abandon a chain.

DimensionReasoningScore

Conciseness

Every line carries a heuristic, mapping, or concrete target ('SSRF(哪怕只GET)→打内网Redis/Consul/K8s/云元数据'); there is zero padding and no explanation of concepts Claude already knows (SSRF, SSTI, TOCTOU are assumed).

5 / 5

Actionability

Concrete, executable guidance throughout — specific primitive mappings, a concrete sink list ('写crontab/.bashrc/CI配置/LD_PRELOAD/authorized_keys/systemd unit都=RCE'), and a stepwise backward-search procedure — but there is no worked example walking one target from facts to a verified chain, and some directives stay abstract ('逐段验证').

4 / 5

Workflow Clarity

The state-space search is sequenced with arrows ('锁定Goal→选最接近现状的等式当模板→缺哪个原语设为子目标→…→正反向在中间相遇=完整链浮现→逐段验证') and validation is explicit ('实际执行+证据后才写 confirmed Fact', '整条链每步都验证过才成立'), but the sequence is compressed inside a single block rather than enumerated as clear steps, and error-recovery branching (what to do when a segment fails validation beyond '换等式') is thin.

4 / 5

Progressive Disclosure

At ~36 lines with no bundle files, everything appropriately lives in SKILL.md, and the block has internal labeled sections (心法, RCE equations, mappings, search, breakthroughs); however the entire body is one monolithic code block with no markdown headers, which falls short of 'well-organized sections'.

4 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description explicitly covers both what the skill does and when to use it, with natural trigger phrases like 'no single RCE' and 'attack chains'. Its main weakness is heavy telegraphic compression of the 'what' half, which relies on jargon shorthand instead of plainly stated capabilities.

Suggestions

Expand the compressed shorthand ('凑RCE等式A-F', '低危映射', '跨域兑现') into plainly stated capabilities, e.g. 'decompose vulnerabilities into capability primitives (read/write/exec/ssrf) and combine them into RCE chains via six equation patterns'.

Add a few natural trigger synonyms users might say, such as 'privilege escalation', 'initial access', or 'foothold', to broaden trigger coverage.

Consider stating the deliverable (e.g. 'derives and validates complete attack chains') so the outcome is explicit, not just the method.

DimensionReasoningScore

Specificity

Lists several concrete capabilities — 'read/write/exec/ssrf等原语', '凑RCE等式A-F', '低危映射', '正反向搜索', '跨域兑现' — but they are presented as compressed telegraphic shorthand ('凑RCE等式A-F', '跨域兑现') that is opaque without reading the body, falling short of the comprehensive clarity of the 5 anchor.

4 / 5

Completeness

Both 'what' (primitives, RCE equations, low-severity mapping, bidirectional search, cross-domain redemption) and an explicit 'when' ('Use when no single RCE, chaining low-severity vulns...') are present, but the 'what' half is cryptic shorthand rather than clearly stated concrete actions, so it does not reach the explicit clarity of the 5 anchor.

4 / 5

Trigger Term Quality

'Use when no single RCE, chaining low-severity vulns, or deriving novel attack chains' includes natural phrases users would say, plus technical terms (RCE, ssrf); a few natural synonyms like 'privilege escalation' or 'initial access' are missing.

4 / 5

Distinctiveness Conflict Risk

The niche of chaining low-severity vulnerabilities into RCE chains is mostly distinct from generic skills, though it could overlap with a broader web-exploitation or general penetration-testing skill.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.