CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-verification

验证铁律:搜索≠漏洞,confirmed Fact须证据,tentative表线索,禁止空泛推测,负结果也落库, 想象力拉满+单步验证零容忍。Use when writing project facts, validating findings, or avoiding hallucination.

62

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-verification/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is an extremely lean, high-signal rule set: concrete tool-level directives, an explicit verify-before-record checkpoint, and negative-result handling to prevent duplicate work. Its only weaknesses are compressed operational details (exact Fact formats, promotion path from tentative to confirmed) and a weakly signaled cross-skill reference.

DimensionReasoningScore

Conciseness

The body is ~12 lines with zero padding: it assumes Claude's competence, explains no background concepts, and every line encodes an operative rule ("搜索结果 ≠ 漏洞", "每个 confirmed Fact 必须在 body 附验证证据", "验证失败 → 写负结果 Fact"). This matches the 'lean and efficient; every token earns its place' anchor exactly.

5 / 5

Actionability

For an instruction-only skill, the guidance is largely executable: it names the exact tools and operations ("record_vulnerability", "confidence=confirmed", "upsert_project_fact" for negative results) and specifies acceptable evidence forms ("命令输出/HTTP响应/文件内容/回连记录"). Not a 5 because key details are compressed — e.g., the expected format of a negative-result Fact and when tentative notes should be promoted are left implicit.

4 / 5

Workflow Clarity

The five numbered rules encode a coherent verification loop with an explicit checkpoint: leads stay tentative → verify with real evidence → only then confirm/record, and failed verification produces a recorded negative result to prevent retries ("每段用真实证据钉死后再 confirmed"). Not a 5 because the decision sequence (what to do first when a search hit appears, how to retry after a failed verification) is implicit rather than laid out as an ordered workflow with error-recovery steps.

4 / 5

Progressive Disclosure

For a sub-50-line single-purpose policy skill with no bundle files (references/, scripts/, assets/ do not exist), the single well-organized section is appropriate, and the pointer to the sibling skill `pentest-blackboard` keeps alignment details out of the main body. Not a 5 because that cross-reference is a bare backtick mention rather than a clearly signaled link, and there is no navigation to the blackboard tool's rules it claims to align with.

4 / 5

Total

17

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is lean and specific about its verification discipline, with a proper 'Use when...' trigger clause, but its keyword coverage is narrow and the mixed Chinese/English telegraphic style reduces natural trigger-term quality. It is a solid, distinct description that would benefit from broader synonym coverage and a clearer capability statement.

Suggestions

Expand trigger-term coverage with natural English synonyms and variations users would actually say, e.g., "Use when recording pentest findings, writing project facts, verifying vulnerabilities, or deciding whether to mark a finding confirmed vs. tentative".

Replace the sloganistic compressed phrases ("想象力拉满+单步验证零容忍") with a plain statement of the skill's concrete capabilities so the 'what' is unambiguous.

Consider adding explicit keyword forms for both languages it might be triggered in (e.g., "验证漏洞/validated findings, evidence, POC, negative results") to improve trigger matching and reduce overlap with generic anti-hallucination skills.

DimensionReasoningScore

Specificity

The description lists several concrete behavioral rules — "搜索≠漏洞" (search results are not vulnerabilities), "confirmed Fact须证据" (confirmed facts require evidence), "tentative表线索" (tentative marks leads), "负结果也落库" (negative results are also recorded) — which are specific capability statements for a verification skill. It falls short of a 5 because the compressed, sloganistic phrasing ("想象力拉满+单步验证零容忍") leaves minor gaps in what the skill actually does operationally.

4 / 5

Completeness

Both parts are present: a "what" (the enumerated verification rules) and an explicit "Use when writing project facts, validating findings, or avoiding hallucination" clause, so the score-3 cap for a missing 'Use when...' does not apply. It is not a 5 because the "what" is a telegraphic rule list rather than a clear statement of what the skill does, and the "when" triggers could be more specific and varied.

4 / 5

Trigger Term Quality

The English trigger clause provides some natural phrases ("writing project facts", "validating findings", "avoiding hallucination"), but coverage is thin — no synonyms or common variations (e.g., "recording findings", "evidence", "pentest reporting"), and the bulk of the description is dense Chinese jargon rather than natural user keywords. Better than 2 (which would be only generic terms) but clearly below 4's "good keyword coverage".

3 / 5

Distinctiveness Conflict Risk

The niche (evidence-based verification of pentest findings, tentative-vs-confirmed discipline) is fairly distinct with domain-specific tool vocabulary (record_vulnerability implied, project facts). Minor overlap risk comes from broad English triggers like "avoiding hallucination" and "writing project facts", which could match general fact-recording or anti-hallucination skills; not a 5 for that reason.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.