CtrlK
BlogDocsLog inGet started
Tessl Logo

cyberstrike-eino-demo

满配示例技能包:SKILL.md + scripts/、references/、assets/ 等可选目录;验证 Eino skill 与 HTTP 包内路径(仅授权安全测试与教学)。

53

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cyberstrike-eino-demo/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-structured instruction document with concrete API endpoints, payloads, tool tables, a sequenced authorization-first workflow, and a closing checklist. Its main defects are the dangling FORMS.md/REFERENCE.md references that fail progressive disclosure, and the absence of an explicit error-recovery loop in the workflow.

Suggestions

Remove or create the missing files referenced as '补充说明见 FORMS.md、REFERENCE.md' — currently these are dead references that break navigation.

Add a short error-recovery step to the workflow (e.g. '若授权边界不明确或发现超出范围的影响,立即停止并记录') to close the feedback-loop gap.

Show one complete example HTTP request/response pair inline (or in a reference file) so the API-validation steps are copy-paste executable.

DimensionReasoningScore

Conciseness

The body is efficient: table-driven tool listings, terse bullet sections, and no explanation of concepts Claude already knows; it respects the token budget. It is not 5 because the opening paragraph re-explains package-layout mechanics ('SKILL.md 为清单 + 主说明...同目录可有 scripts/、references/、assets/ 等任意子目录') that could be trimmed, adding minor meta-overhead.

4 / 5

Actionability

Most guidance is executable and specific: concrete HTTP queries ('GET /api/skills/cyberstrike-eino-demo?depth=summary|full', 'section=payload'), exact resource paths ('resource_path=scripts/check-env.sh'), sample payloads, and a report snippet template ('scripts/report-snippet.json'). It is not 5 because no full copy-paste command/example block is shown end-to-end for the API calls, leaving minor gaps.

4 / 5

Workflow Clarity

The '授权测试工作流' section gives a clear 5-step sequence (scope confirmation → baseline → classified testing → evidence/report → cleanup) with an authorization checkpoint before high-risk actions ('高风险操作前二次确认授权边界') and a final verification checklist ('清单与验证'). It is not 5 because there is no explicit feedback/error-recovery loop (e.g. what to do when a check fails or authorization is unclear).

4 / 5

Progressive Disclosure

Structure is good in intent — one-level-deep references clearly signaled in a table ('references/citations.md', 'assets/README.txt') and body pointers ('详细列表见 scripts/payloads.txt') — but the body cites '补充说明见 FORMS.md、REFERENCE.md' and neither file exists in the bundle, so navigation breaks for those references. Scored against the actual bundle structure, this drops it below 4.

3 / 5

Total

15

/

20

Passed

Description

46%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a coherent, scoped purpose but reads as package metadata rather than a trigger-optimized skill description: it names the domain and structure concretely yet gives almost no natural trigger terms and omits any 'use when' guidance. The niche is distinct, which limits conflict risk, but discoverability via user phrasing is weak.

Suggestions

Add an explicit trigger clause, e.g. '适用于:需要验证 Eino skill 包结构、测试 GET /api/skills 索引与包内 resource_path 读取时' (use when you need to validate Eino skill package structure or test skill API listing and in-package resource_path reads).

Replace structural jargon with natural keywords users would actually say — e.g. 'skill 包验证' (skill package validation), '安全测试技能包' (security-testing skill package), '授权渗透测试' (authorized pentest) — to improve trigger term coverage.

State 2-3 concrete capabilities in verb form (e.g. '演示授权测试工作流、提供 payload 占位与报告模板') instead of only listing directory names.

DimensionReasoningScore

Specificity

The description names the domain (Eino skill package with 'SKILL.md + scripts/、references/、assets/ 等可选目录') and one concrete action ('验证 Eino skill 与 HTTP 包内路径' — validate Eino skill and HTTP in-package paths), but the actions are minimal and coverage is not comprehensive. It sits at anchor 3 rather than 4 because it does not list several specific actions, and above 2 because it is more than a bare domain label.

3 / 5

Completeness

The 'what' is reasonably clear (an example skill package for validating Eino skill and HTTP in-package path handling), but there is no 'Use when...' clause or equivalent explicit trigger guidance — the parenthetical '仅授权安全测试与教学' is a scope restriction, not a usage trigger. Per the judging guideline, a missing 'Use when' clause caps completeness at 3.

3 / 5

Trigger Term Quality

The description is dominated by structural/technical jargon ('SKILL.md', 'scripts/', 'references/', 'Eino', 'HTTP 包内路径') that a user would not naturally say when needing this skill; only '安全测试' (security testing) and '教学' (education) approach natural phrasing. It is above anchor 1 because those two domain terms are somewhat natural, but below 3 because common variations and synonyms are missing.

2 / 5

Distinctiveness Conflict Risk

The niche is fairly distinct — validating Eino skill packaging and HTTP resource paths — so overlap risk with generic security or document skills is minor. It is not 5 because the security-testing framing ('授权安全测试') could overlap with other authorized-pentest skills that share similar trigger contexts.

4 / 5

Total

12

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.