CtrlK
BlogDocsLog inGet started
Tessl Logo

unlimited-attack-scope

不设限原则:搜索/验证/串联/记录一切,全领域适用,被拦换路,不达不休。Use when reminding scope is unlimited across Web/APK/cloud/AI/wireless/social eng.

48

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/unlimited-attack-scope/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

47%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably lean and free of padding, and its single-section short form is appropriate for a principle/reminder skill. However, it is composed almost entirely of abstract directives with no concrete examples or procedures, and it depends on four undefined external frameworks (OODA, project blackboard, verification rules, combination attacks) that have no accompanying reference files, so Claude cannot actually execute the guidance without outside context.

Suggestions

Add one concrete mini-example per directive (e.g. what 'search everything (multi-channel)' looks like: cert transparency logs, GitHub dorks, app-store metadata, Shodan — or what an entry on the 'blackboard Fact' record should contain) to lift actionability.

Either define or link the referenced frameworks (OODA, 项目黑板Fact, 验证铁律, 组合拳) — create a references/ file for each, or drop the names and state the operative rule inline — so the guidance is self-contained.

Order the directives into a repeatable loop (e.g. enumerate surfaces → verify each finding → chain verified facts → record results → switch route when blocked) so the body conveys a usable sequence rather than a flat principle list.

DimensionReasoningScore

Conciseness

The body is ~10 lines with no explanation of concepts Claude already knows — every directive line is compact. It falls short of anchor 5 because the closing blockquote ("这条链可能全世界只有你这一个目标适用...这就是跳出固有框架的真正含义") is motivational commentary rather than instruction, so not every token earns its place; it is clearly above anchor 3, which requires unnecessary explanation.

4 / 5

Actionability

The body is entirely principle statements — "搜索一切(多渠道)" (search everything, multi-channel), "被拦换路" (switch routes when blocked), "不达不休" (persist until done) — with no concrete commands, examples, or procedures, and it leans on undefined external frameworks ("OODA/项目黑板Fact/验证铁律/组合拳") with no pointers to them. This matches anchor 2 ('high-level hints but missing the specific steps to execute') better than anchor 1 only because the directives do tell Claude what behavior to adopt.

2 / 5

Workflow Clarity

There is no sequence or structure to follow: the directives are a flat list of principles inside a code block, and the referenced frameworks (OODA loop, project blackboard, verification rules, combination attacks) are never sequenced or linked. The simple-skill exception does not fully apply because the single action (apply the unlimited-scope principle) is ambiguous without those undefined framework definitions; this is above anchor 1 only because the principles themselves are individually coherent.

2 / 5

Progressive Disclosure

The skill is well under 50 lines with a single section header and no need for external reference files, so the short inline body is appropriately placed — matching the guidelines' simple-skill exception. It falls short of anchor 5 because the body names four external concepts (OODA, 项目黑板Fact, 验证铁律, 组合拳) that are neither defined here nor linked to any bundle file (references/ does not exist), leaving those references unresolved.

4 / 5

Total

12

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has the right structure — an explicit 'Use when' clause plus a what-summary — and is appropriately concise, but the 'what' is a set of abstract directives (search/verify/chain/record everything) rather than concrete capabilities, and its trigger surface spans all security domains, creating overlap risk with general pentest skills. It is a functional but middling-quality description.

Suggestions

Replace the generic directive list with concrete capabilities, e.g. 'Expands any authorized pentest engagement to every applicable surface (Web, APK, cloud, firmware, wireless, AI, social engineering) — enumerating, verifying, chaining, and logging findings across domains' so the 'what' states specific actions.

Broaden trigger terms with natural user phrasings like 'pentest scope', 'red team engagement', 'out of scope?', 'can we test X too' rather than the single clause 'reminding scope is unlimited'.

Narrow the trigger context (e.g. 'Use when a user questions whether a target/surface is in scope or asks to broaden an authorized engagement') to reduce conflict risk with general penetration-testing skills.

DimensionReasoningScore

Specificity

The description lists four action verbs ("搜索/验证/串联/记录一切" — search/verify/chain/record everything) but these are generic directives rather than concrete capabilities, and the domain is the vague "全领域适用" (applies to all domains) with only a domain acronym list (Web/APK/cloud/AI/wireless/social eng). This matches the 'names domain and 1-2 concrete actions, but not comprehensive' anchor better than anchor 2 (which expects minimal actions) or anchor 4 (which expects several specific, well-scoped actions).

3 / 5

Completeness

Both parts are present: 'what' via the principle summary (search/verify/chain/record everything, all domains) and an explicit 'when' clause ("Use when reminding scope is unlimited across Web/APK/cloud/AI/wireless/social eng"). It falls short of anchor 5 because the 'what' is abstract rather than concrete capabilities and the 'when' trigger phrasing ('reminding scope is unlimited') is unusual as a user utterance; it clearly exceeds anchor 3 since the 'when' is explicit.

4 / 5

Trigger Term Quality

Keywords like "unlimited", "scope", and the domain list (Web/APK/cloud/AI/wireless/social eng) are relevant to pentest users, but the phrasing is technical shorthand; the Chinese portion provides natural phrasing only for Chinese-language users and common synonyms (e.g. pentest, red team, engagement scope) are absent. Fits anchor 3 ('some relevant keywords but missing common variations or synonyms') better than anchor 4's 'good keyword coverage'.

3 / 5

Distinctiveness Conflict Risk

The intent (a scope-unlimited reminder for offensive security work) is somewhat distinctive, but the trigger spans virtually every security domain (Web/APK/cloud/AI/wireless/social eng), so it risks firing alongside any general pentest/red-team skill. Matches anchor 3 ('somewhat specific but could still overlap with similar skills') rather than anchor 4, which requires minor overlap risk only with closely related skills.

3 / 5

Total

13

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.