CtrlK
BlogDocsLog inGet started
Tessl Logo

source-code-hunting

源码狩猎:.git泄露,危险函数grep,JS RC4解混淆,semgrep/CodeQL,trufflehog,patch diff,供应链/CI。Use when hunting source leaks, secrets, JS deobfuscation, or supply-chain issues.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/source-code-hunting/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An extremely token-efficient cheat sheet that packs real, domain-specific intelligence into every line, and its breadth of concrete commands is a strength. Its weaknesses are in executability — the flagship JS deobfuscation workflow is described rather than given as runnable code — and in the near-total absence of validation checkpoints across the techniques.

Suggestions

Add a short executable Node.js snippet for the RC4 string-array decoder rebuild (steps 1-4 currently read as pseudocode), so the flagship deobfuscation workflow is copy-paste ready.

Insert explicit verification checkpoints for scan outputs, e.g., confirm trufflehog findings are live via --only-verified and validate decoded strings against the app's API paths before reporting.

Break the single code block into labeled sections per technique so each hunting track can be navigated independently.

DimensionReasoningScore

Conciseness

The ~12-line body is a maximally dense cheat sheet with zero padding and no explanations of concepts Claude already knows — every token carries technique-specific information, matching the 'lean and efficient' anchor exactly.

5 / 5

Actionability

There are some concrete commands and patterns ('semgrep --config=auto', 'git-dumper → git log -p --all', 'sk-/ghp_/BEGIN RSA'), but the central RC4 deobfuscation track ('1)提取字符串数组 2)找解码函数 3)找rotation IIFE 4)Node.js重建解码器') is numbered methodology/pseudocode with no executable decoder snippet, matching the 'concrete but incomplete / pseudocode' anchor.

3 / 5

Workflow Clarity

The RC4 track has an explicit 1-4 step sequence, but the parallel technique one-liners have implicit ordering and no validation checkpoints (only the implicit '--only-verified区分死活密钥' liveness check), matching the 'sequence present but checkpoints missing or implicit' anchor.

3 / 5

Progressive Disclosure

With no bundle files present and a body well under 50 lines, the colon-labeled technique lines ('.git泄露:', '危险函数grep:', '供应链/CI:') function as sections; it falls short of anchor 5 because everything sits in a single monolithic code block under one heading rather than well-separated sections.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, bilingual, tool-specific description that covers its niche comprehensively and includes an explicit 'Use when' trigger clause. Its main weakness is that the capability list reads as shorthand fragments rather than clearly stated actions, and a few natural trigger synonyms are absent.

Suggestions

Rewrite the capability list as full third-person actions (e.g., 'Dumps exposed .git directories and greps for deleted sensitive files, dangerous functions, and hardcoded keys') instead of comma-separated fragments.

Add natural trigger synonyms such as 'credentials', 'hardcoded secrets', and 'exposed .git' to the 'Use when' clause to broaden keyword coverage.

DimensionReasoningScore

Specificity

The description names many concrete techniques and tools — '.git泄露,危险函数grep,JS RC4解混淆,semgrep/CodeQL,trufflehog,patch diff,供应链/CI' — giving broad domain coverage, but the 'what' is a comma-separated fragment list of technique nouns rather than fully stated concrete actions, so it sits between the anchor-4 and anchor-5 examples.

4 / 5

Completeness

Both 'what' (the technique/tool list) and an explicit 'Use when hunting...' trigger clause are present, satisfying anchor 4; it is not a 5 because the 'what' half is terse fragments rather than clearly articulated actions.

4 / 5

Trigger Term Quality

'Use when hunting source leaks, secrets, JS deobfuscation, or supply-chain issues' contains natural phrases users would say, but common synonyms such as 'credentials', 'hardcoded keys', or '.git exposure' are missing, keeping it below comprehensive anchor-5 coverage.

4 / 5

Distinctiveness Conflict Risk

The pentest source-hunting niche with triggers like 'source leaks', 'JS deobfuscation', and 'supply-chain issues' is mostly distinct, with only minor overlap risk against generic secrets-scanning or code-review skills.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.