CtrlK
BlogDocsLog inGet started
Tessl Logo

initial-access-phishing

初始访问/钓鱼/社工:凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing。Use when needing initial access, phishing, AiTM, device code, or social engineering.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/initial-access-phishing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An extremely token-efficient catalog that assumes Claude's competence and packs in dense, specific references, but it functions as a cheat-sheet index rather than a guided skill: no ordered workflow with checkpoints and no executable examples or pointers to detail files. Scoring 3 on actionability and workflow clarity reflects that a reader gets the map but not the steps.

Suggestions

Structure the catalog into per-technique subsections (or one reference file per technique family) so each entry can carry its own concrete steps, commands, and configuration examples instead of one undifferentiated block.

Present the implied flow (OSINT → pretext → technique selection → post-access handoff) as an explicitly numbered sequence with decision checkpoints for when to choose each technique family.

Make the handoff to related skills (redteam-opsec, capability-primitive-search) an explicit final workflow step with links, rather than a parenthetical note inside the code block.

DimensionReasoningScore

Conciseness

The body is telegraphically dense — every line carries tool names, parameters, or constraints ('每账号1-2次避锁定', 'evilginx3/Modlishka反代真站') with zero padding and no re-explanation of concepts Claude already knows. Every token earns its place.

5 / 5

Actionability

Concrete tool names and specifics are given (gophish, TokenTactics, phishlet configs, scope names), but there is no executable command, code, or step sequence — it reads as a knowledge index rather than actionable instructions, fitting 'some concrete guidance but incomplete'.

3 / 5

Workflow Clarity

A rough sequence is implied (OSINT → pretext → technique selection → hand off to 'redteam-opsec'/'capability-primitive-search') but steps are never explicitly ordered and validation checkpoints are absent or implicit, matching anchor 3 rather than 4's explicit sequenced workflow.

3 / 5

Progressive Disclosure

No bundle files exist and at ~11 lines nothing needs splitting, with sibling-skill cross-links clearly signaled. However organization is minimal — one heading wrapping a single undifferentiated block mixing six technique families — so structure is good with minor gaps rather than well-organized sections.

4 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A compact, bilingual description that clearly names its niche and includes an explicit 'Use when' trigger clause. Its main limitation is that the capability list reads as bare keywords rather than concrete action phrases, and a few natural trigger synonyms are missing.

Suggestions

Rewrite the capability half as concrete third-person action phrases (e.g. what the skill actually does for each technique) instead of a bare comma-separated keyword list.

Add commonly-used trigger synonyms such as 'spearphishing', 'credential spraying', 'MFA bypass', and 'pretexting' to the 'Use when' clause to broaden natural-language matching.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete technique categories ('凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing'), giving good coverage of the domain, but they are terse keyword nouns rather than explicit action phrases like the 5-anchor's 'extract/fill/merge' style.

4 / 5

Completeness

Both a 'what' (the technique enumeration) and an explicit trigger clause ('Use when needing initial access, phishing, AiTM, device code, or social engineering') are present. The 'what' half is a compressed keyword list rather than a clear statement of the skill's function, placing it between the 4 and 5 anchors.

4 / 5

Trigger Term Quality

'initial access, phishing, AiTM, device code, or social engineering' are natural terms a user would say, but common synonyms and variations (e.g. spearphishing, MFA bypass, credential spraying) are absent, so coverage is good rather than comprehensive.

4 / 5

Distinctiveness Conflict Risk

'初始访问/钓鱼/社工' plus its English triggers carves out a clear, narrow niche with distinct trigger phrases and minimal overlap with unrelated skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.