CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-blackboard

CyberStrikeAI 项目黑板:跨会话 Fact 图(SQLite)+ upsert_project_fact/record_vulnerability 边渗透边记录节奏、关系边 links、confidence、与多代理协调落库。Use when managing project facts, blackboard index, writing evidence, or avoiding context-loss after compression.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-blackboard/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A disciplined, rule-dense instruction skill: concrete tool usage, exact key/link schemas, a forced write-as-you-go cadence with per-step checklists and error-recovery paths, and well-organized sections. The gaps are modest — some repetition across sections and no worked example of a complete fact payload.

Suggestions

Add one worked example of a full upsert_project_fact call (fact_key, summary, body, links JSON) to make the write spec copy-paste concrete.

Deduplicate the links rules — state them once in 写入规范 and reference that section from the 原语 table and 节奏 rules to trim repeated tokens.

DimensionReasoningScore

Conciseness

The body is rule-dense with zero concept-explanation padding ('同 fact_key 覆盖更新', the tool quick-reference table) and assumes competence, but has minor repetition — the links requirement appears in the 原语 table, the dedicated links section, and the 节奏 rules, and '摘要不足必须 get_project_fact' is stated twice — placing it at the 'efficient with minor trims' anchor rather than 5.

4 / 5

Actionability

Concrete guidance throughout: exact key formats ('target/primary_domain', 'finding/sqli-login'), enumerated edge types with minimums ('finding 至少 1 条 {from: target/*, type: discovered_on}'), and a forbidden-summary example ('禁止只写「存在 SQLi」'). It stops short of 5 because there is no worked example of a complete upsert payload or links JSON.

4 / 5

Workflow Clarity

The 强制节奏 is a clear numbered sequence with immediate-write checkpoints, per-mode guidance, and 每步必检 checklists with explicit error-recovery paths (拒绝→换路 fallback order, 卡住时 recovery, 违反判定 criteria). The 3-cap for destructive/batch operations without validation does not apply (writes are idempotent upserts with a pre-write dedup check), but a post-write verification loop is absent, so it sits at 4 rather than 5.

4 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent), and the ~100-line body is well-sectioned with clear headers and one-level, clearly signaled cross-skill references ('详见 pentest-verification'). It is not 5 because the detailed 写入规范/links schema is fully inline where a separate reference file would keep SKILL.md a leaner overview.

4 / 5

Total

16

/

20

Passed

Description

76%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, concrete description that explicitly covers both what the skill does (tool-level mechanics) and when to use it. Its main weakness is trigger-term coverage: the keywords are domain-jargon-heavy and miss natural user phrasings and synonyms.

Suggestions

Add natural trigger phrases and synonyms users would actually type, e.g. '记录渗透发现', '保存漏洞/POC', 'fact 图/知识库', alongside the current product-jargon terms.

Briefly mention the deprecate/restore and search capabilities (e.g. '查重、废弃误报') so the 'what' covers the skill's full scope.

Split the long run-on first sentence into separate what-it-does and key-mechanics sentences for faster scanning during skill selection.

DimensionReasoningScore

Specificity

The description names several concrete actions and tools — 'upsert_project_fact/record_vulnerability', '关系边 links、confidence、与多代理协调落库' — in third person, but omits parts of the skill's scope (search/deprecate, evidence handling), so it falls short of the comprehensive-coverage anchor at 5 and above the 1-2-actions anchor at 3.

4 / 5

Completeness

It clearly answers 'what' with concrete mechanisms (SQLite fact graph, upsert_project_fact/record_vulnerability, links, confidence, multi-agent coordination) and explicitly answers 'when' with an explicit 'Use when managing project facts, blackboard index, writing evidence, or avoiding context-loss after compression' trigger clause, matching the 5 anchor; it is well above the 4 anchor where 'when' is only adequate.

5 / 5

Trigger Term Quality

'project facts, blackboard index, writing evidence, context-loss after compression' are relevant domain keywords, but they lean jargon-ward and miss the natural phrasings and synonyms a user would actually say (e.g. saving pentest findings, recording vulnerabilities, fact graph, SQLite), matching the 'some relevant keywords but missing common variations' anchor.

3 / 5

Distinctiveness Conflict Risk

Terms like '项目黑板', 'blackboard index', and 'context-loss after compression' carve a distinct product-specific niche with dedicated triggers, leaving only minor overlap risk with generic note-taking/context-management skills — the 'mostly distinct' anchor rather than the fully clean niche at 5.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.