Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A lean, highly actionable operational checklist whose proxy-escalation workflow is exemplary — explicitly sequenced with HTTP-code validation gates and failure fallbacks. Its weaknesses are structural: one dense wall-of-text code block with no section headers, a buried cross-skill reference, and hint-level (rather than executable) guidance in the tool-bootstrap and wordlist portions.
Suggestions
Break the single fenced code block into markdown sections (## 代理换路 / ## 工具自举 / ## 字典生成 / ## OOB确认) so each topic cluster is clearly signaled and navigable — this also fixes the buried `pentest-blackboard` pointer by making it an explicit cross-reference.
Give the tool-bootstrap section one concrete executable pattern per fallback (e.g. a short requests-based port-scan snippet) instead of one-line hints like '无nmap→socket扫端口', matching the concreteness of the proxy half.
Deduplicate the ProxyScrape SOCKS5 URL and the SOCKS5-vs-HTTP-proxy guidance, which currently appear both in steps ②-③ and again in the trailing bullet lines.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is a dense, low-padding operational checklist with no explanation of concepts Claude already knows; nearly every line carries non-obvious operational detail (e.g. 'HTTP代理会插入自己的错误页...需探测时必须用SOCKS5'). It misses a 5 due to minor redundancy — the ProxyScrape SOCKS5 URL and SOCKS5-vs-HTTP guidance appear in both step ②/③ and the later bullet lines. | 4 / 5 |
Actionability | The proxy workflow is copy-paste ready with exact curl commands, URLs, timeouts, and per-tool proxy flags ('sqlmap --proxy=socks5://{P}', 'nmap --proxies', 'ffuf -x'). It is not a 5 because the tool-bootstrap and wordlist sections are one-line directives ('无nmap→socket扫端口', '爬虫requests+bs4') with library names but no executable code, unlike the fully concrete proxy half. | 4 / 5 |
Workflow Clarity | The escalation ladder ①-⑦ is clearly sequenced with an explicit validation checkpoint (③ 'curl ... -w "%{http_code}"', ④ '200=可用...非200=换下一个代理') and error-recovery loops (SOCKS5 fail→HTTP→Tor; rotate every 20 requests; OOB '看到OOB回连才算确认→写Fact'). It falls short of 5 because the second half (tool bootstrap, wordlist generation) is a flat unsequenced list with no validation steps. | 4 / 5 |
Progressive Disclosure | No bundle files exist (no references/, scripts/, assets/), and at ~24 lines the skill does not need external files, but the organization is weak: the entire body is one monolithic fenced code block with no markdown section headers, and the one external pointer ('见 `pentest-blackboard`') is buried parenthetically mid-sentence. It is above a 2 because the content is short and grouped by topic, but below a 4 because the topic clusters (proxy ladder / tool bootstrap / wordlist / OOB) are not clearly signaled as navigable sections. | 3 / 5 |
Total | 15 / 20 Passed |