CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-output-standards

输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。 Use when reporting findings, maintaining change ledger, or formatting pentest output.

62

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-output-standards/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exceptionally lean, dense set of output standards with concrete field templates, explicit tool-call hooks, and well-defined per-step/per-round/deadlock workflows including backup-and-rollback safeguards for destructive changes. Remaining gaps are minor: no worked examples and no internal section structure within the single code block.

DimensionReasoningScore

Conciseness

The ~15-line body is lean and dense: no explanation of concepts Claude already knows, no padding, and every line states a rule or template. It matches anchor 5 ('lean and efficient; every token earns its place') and is clearly not anchor 4, which requires some over-explanation to trim — there is none.

5 / 5

Actionability

Concrete, executable guidance throughout: exact report fields (漏洞名+严重程度+影响版本+利用条件+利用步骤(请求/响应)+验证证据+影响+修复建议), ledger row format (#|时间|主机|类型|位置|内容|回滚命令), and specific tool calls (record_vulnerability, upsert_project_fact, list/search_project_facts). It stops short of anchor 5 because there are no worked examples — a filled-in vulnerability report or ledger row the agent could copy verbatim.

4 / 5

Workflow Clarity

Clear sequencing with most checkpoints present: a per-step chain-of-thought template, a per-round graph-state summary, real-time ledger entries for every write with a .bak backup before config changes, and an explicit deadlock-escalation path (re-review facts → switch domain → ask user). Destructive operations do have safeguards (backup + rollback script), so the cap-at-3 rule does not apply; it misses 5 only because there is no explicit validate-fix-retry loop or end-of-run checklist ordering.

4 / 5

Progressive Disclosure

At ~15 lines with no external references needed, the single-section form is appropriate, and the skill qualifies for the simple-skill exception. It sits at 4 rather than 5 because everything lives in one undifferentiated fenced code block under a single heading — minor section breaks (e.g., separate blocks for reporting, ledger, and deadlock handling) would make navigation clearer.

4 / 5

Total

17

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description covers a distinct pentest-output niche with several concrete named capabilities and an explicit 'Use when...' trigger clause, placing it above the midpoint. Its main weaknesses are the compressed keyword-style 'what' statement and trigger-term coverage that misses common synonyms a user might naturally say.

Suggestions

Expand the 'what' from a keyword list into concrete third-person action statements, e.g. 'Formats pentest output in Chinese: per-step reasoning chains, vulnerability reports, negative-result records, graph-state summaries, change ledgers, and deadlock-breaking procedures.'

Broaden trigger terms to natural synonyms users would say: 'Use when writing or formatting pentest reports, vulnerability reports or writeups, recording findings or negative results, or maintaining a change/rollback ledger.'

State the agent modes or engagement contexts it applies to (single-agent, deep, plan_execute, supervisor) so the 'when' is explicit rather than implied.

DimensionReasoningScore

Specificity

Enumerates several concrete capabilities — 漏洞报告模板 (vulnerability report templates), 负结果 (negative results), 黑板状态总览 (graph-state overviews), 改动台账 (change ledger), 死锁突破 (deadlock breaking) — matching anchor 4's 'several specific actions; minor gaps'. It falls below anchor 5 because the capabilities are compressed keywords rather than complete, comprehensive action statements.

4 / 5

Completeness

Both 'what' (the enumerated output standards) and 'when' (an explicit 'Use when reporting findings, maintaining change ledger, or formatting pentest output') are present, satisfying anchor 4. It does not reach 5 because the 'what' is a terse keyword list rather than clearly stated actions, and the 'when' triggers could be more specific (e.g., naming the agent modes or pentest context it applies to).

4 / 5

Trigger Term Quality

'reporting findings, maintaining change ledger, or formatting pentest output' gives some natural phrases, but common variations and synonyms are missing — no 'vulnerability report', 'writeup', 'pentest report', or file-extension equivalents. This matches anchor 3 ('some relevant keywords but missing common variations') better than 4's good-but-slightly-incomplete coverage.

3 / 5

Distinctiveness Conflict Risk

The pentest-output niche with tool-specific terms (record_vulnerability, upsert_project_fact, blackboard/graph state) is mostly distinct with minimal conflict risk, matching anchor 4. It is not 5 because phrases like 'reporting findings' and 'maintaining' could weakly overlap with generic reporting or note-keeping skills.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.