CtrlK
BlogDocsLog inGet started
Tessl Logo

redteam-opsec

OPSEC隐蔽作战纪律:IP黑名单绕过,速率时序,流量混淆,最小足迹,反取证,渐进暴露。Use when maintaining stealth, bypassing IP bans, or planning covert red-team ops.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/redteam-opsec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An impressively lean, dense operational checklist with genuinely concrete commands, tool flags, and a sensible passive-to-active escalation doctrine. The main weaknesses are structural: everything lives in one compressed code block rather than organized markdown sections, and the destructive anti-forensics steps (log deletion, timestamp tampering) lack validation checkpoints.

Suggestions

Add explicit validation checkpoints to the destructive/batch guidance: e.g., before selective log deletion, verify your own entries exist and confirm an untouched reference entry count; after timestamp tampering with 'touch -r', verify mtime matches with 'stat'. This would lift workflow_clarity above the destructive-ops cap of 3.

Break the single code block into markdown sections (one heading per discipline: 速率与时序, 流量混淆, 最小足迹, 反取证, 渐进暴露), keeping the compressed checklist lines inside each — this preserves token efficiency while making navigation effortless and would raise progressive_disclosure to 5 under the simple-skill exception.

Expand the few compressed hints into complete one-line commands, e.g. '工具用完即删' → '工具用完即删: shred/内存盘(/dev/shm)写盘的先 srm 再删', moving actionability from mostly-executable to copy-paste ready.

DimensionReasoningScore

Conciseness

The body is an extremely lean tactical checklist with zero padding and no explanation of concepts Claude already knows — '核心: 打得进 ≠ 打得稳。被发现即行动归零' is pure signal, and every line adds non-obvious operational detail. Every token earns its place, matching the lean/efficient anchor.

5 / 5

Actionability

Concrete commands and flags appear throughout ('nuclei -rl', 'nmap -T2 --max-rate', 'ffuf -p延迟', X-Forwarded-For/X-Real-IP/CF-Connecting-IP header names, 'unset HISTFILE', 'touch -r', '/dev/shm', DDexec/memfd), plus a concrete XFF verification procedure. Not fully copy-paste ready (5) because several items are compressed hints ('工具用完即删', '别动监控/审计服务') without complete commands.

4 / 5

Workflow Clarity

The '渐进暴露' line provides a sequenced escalation (passive recon → confirm no monitoring → active scan → exploitation) and the XFF bypass includes a verify loop, but destructive and batch operations (selective log deletion, timestamp tampering, automated batch exploitation) lack explicit validation checkpoints. Per the destructive-operations guideline, missing validation caps workflow clarity at 3.

3 / 5

Progressive Disclosure

The skill is self-contained, under 50 lines, with no external bundle files needed; labeled topic lines (速率与时序, 流量混淆, 最小足迹, 反取证) partition the material well. It falls short of 5 because those section labels are buried inside a single code block rather than surfaced as clear markdown sections, making navigation slightly less easy than the well-organized anchor.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names a distinct OPSEC/covert-operations niche with six concrete capability areas and an explicit 'Use when' trigger clause. Its main limitation is terseness — the capability list uses compressed noun labels rather than verb-framed actions, and it omits common trigger synonyms like 'OPSEC' or 'evade detection'.

DimensionReasoningScore

Specificity

The description lists six specific capability areas ("IP黑名单绕过,速率时序,流量混淆,最小足迹,反取证,渐进暴露"), which anchors to 'several specific actions; minor gaps'. It falls short of a 5 because these are terse noun labels rather than verb-framed concrete actions like the anchor's 'Extract text... fill forms'.

4 / 5

Completeness

It explicitly answers both what (six named capability areas) and when ('Use when maintaining stealth, bypassing IP bans, or planning covert red-team ops'). Not a 5 because the 'what' is a compressed label list rather than a fully stated set of actions, leaving the when/what pairing slightly less explicit than the anchor example.

4 / 5

Trigger Term Quality

The 'Use when' clause provides natural phrases users would say: 'maintaining stealth', 'bypassing IP bans', 'covert red-team ops'. Good keyword coverage, but common synonyms such as 'OPSEC', 'evade detection', or 'stay undetected' are missing, so it does not reach comprehensive coverage (5) while clearly exceeding 'some relevant keywords' (3).

4 / 5

Distinctiveness Conflict Risk

'Covert red-team ops', 'stealth', and 'OPSEC' carve a clear niche with distinct triggers and minimal conflict risk against general document- or code-handling skills. Minor overlap remains with general penetration-testing skills, keeping it just below the 'clear niche, minimal conflict' anchor (5).

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.