CtrlK
BlogDocsLog inGet started
Tessl Logo

proxy-tool-bootstrap

自找代理+工具自举:SOCKS5/HTTP/Tor换路序列,工具Python自举,字典自生成,OOB基础设施。Use when blocked by 403/429/WAF/timeout, missing tools, or needing OOB confirmation.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/proxy-tool-bootstrap/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable operational checklist whose proxy-escalation workflow is exemplary — explicitly sequenced with HTTP-code validation gates and failure fallbacks. Its weaknesses are structural: one dense wall-of-text code block with no section headers, a buried cross-skill reference, and hint-level (rather than executable) guidance in the tool-bootstrap and wordlist portions.

Suggestions

Break the single fenced code block into markdown sections (## 代理换路 / ## 工具自举 / ## 字典生成 / ## OOB确认) so each topic cluster is clearly signaled and navigable — this also fixes the buried `pentest-blackboard` pointer by making it an explicit cross-reference.

Give the tool-bootstrap section one concrete executable pattern per fallback (e.g. a short requests-based port-scan snippet) instead of one-line hints like '无nmap→socket扫端口', matching the concreteness of the proxy half.

Deduplicate the ProxyScrape SOCKS5 URL and the SOCKS5-vs-HTTP-proxy guidance, which currently appear both in steps ②-③ and again in the trailing bullet lines.

DimensionReasoningScore

Conciseness

The body is a dense, low-padding operational checklist with no explanation of concepts Claude already knows; nearly every line carries non-obvious operational detail (e.g. 'HTTP代理会插入自己的错误页...需探测时必须用SOCKS5'). It misses a 5 due to minor redundancy — the ProxyScrape SOCKS5 URL and SOCKS5-vs-HTTP guidance appear in both step ②/③ and the later bullet lines.

4 / 5

Actionability

The proxy workflow is copy-paste ready with exact curl commands, URLs, timeouts, and per-tool proxy flags ('sqlmap --proxy=socks5://{P}', 'nmap --proxies', 'ffuf -x'). It is not a 5 because the tool-bootstrap and wordlist sections are one-line directives ('无nmap→socket扫端口', '爬虫requests+bs4') with library names but no executable code, unlike the fully concrete proxy half.

4 / 5

Workflow Clarity

The escalation ladder ①-⑦ is clearly sequenced with an explicit validation checkpoint (③ 'curl ... -w "%{http_code}"', ④ '200=可用...非200=换下一个代理') and error-recovery loops (SOCKS5 fail→HTTP→Tor; rotate every 20 requests; OOB '看到OOB回连才算确认→写Fact'). It falls short of 5 because the second half (tool bootstrap, wordlist generation) is a flat unsequenced list with no validation steps.

4 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, assets/), and at ~24 lines the skill does not need external files, but the organization is weak: the entire body is one monolithic fenced code block with no markdown section headers, and the one external pointer ('见 `pentest-blackboard`') is buried parenthetically mid-sentence. It is above a 2 because the content is short and grouped by topic, but below a 4 because the topic clusters (proxy ladder / tool bootstrap / wordlist / OOB) are not clearly signaled as navigable sections.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly states concrete capabilities and pairs them with a clear, specific 'Use when...' trigger clause covering 403/429/WAF/timeout/missing-tools/OOB scenarios. Main weaknesses are compressed noun-phrase phrasing, some missing natural synonyms, and generic terms like 'missing tools' that raise mild conflict risk.

DimensionReasoningScore

Specificity

The description lists several concrete capability areas — 'SOCKS5/HTTP/Tor换路序列' (proxy route-switching sequence), '工具Python自举' (Python tool bootstrap), '字典自生成' (wordlist self-generation), 'OOB基础设施' — with specific protocol and implementation details. It falls short of a 5 because these are terse noun phrases rather than fully stated actions, leaving minor gaps in coverage.

4 / 5

Completeness

Both parts are explicit: 'what' is stated concretely ('自找代理+工具自举:SOCKS5/HTTP/Tor换路序列,工具Python自举,字典自生成,OOB基础设施') and 'when' is given as a concrete 'Use when...' clause with specific trigger conditions. This matches the 5 anchor; it is not a 4 because the 'when' clause is already fully explicit, not merely present.

5 / 5

Trigger Term Quality

Explicit triggers 'Use when blocked by 403/429/WAF/timeout, missing tools, or needing OOB confirmation' include natural incident terms (403, 429, WAF, timeout, blocked, missing tools, OOB confirmation) a user would actually say. Not a 5 because common synonyms like 'rate limited', 'banned', or 'blacklisted' are absent, and the front half of the description is Chinese, which limits keyword matching for English queries.

4 / 5

Distinctiveness Conflict Risk

The combination of proxy route-switching plus tool bootstrapping for blocking situations is a clear niche with distinctive triggers (403/429/WAF/OOB), giving minimal overlap with most skills. It is not a 5 because 'missing tools' and 'timeout' are broadly applicable phrases that could fire for unrelated tooling or connectivity skills.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.