Content
78%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, token-dense attack cheat sheet whose concrete commands and verification signals are its strongest asset. Its weaknesses are structural: a single monolithic code block with no progressive disclosure, and some tokens spent on well-known basic payloads.
Suggestions
Split the monolithic code block into markdown sections per domain (注入 / 认证 / 服务端 / 杂项 / CDN) with headers, moving bulk per-technique detail into one-level-deep reference files (e.g., references/cdn-bypass.md) so SKILL.md serves as a navigable overview.
Trim basic-knowledge payloads (' OR 1=1--, {{7*7}}, generic XXE entities) and keep the tokens for the non-obvious material — bypass chains, fingerprints, and verification signals — that Claude would not reliably recall.
Add explicit validate-before-escalate checkpoints to the risky chains (e.g., confirm the 146B/16B or 403/404 fingerprint before chaining into webshell upload), turning the scattered 验证/检测 notes into a consistent loop.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is extremely dense shorthand with essentially no padding and no concept explanations, but it spends tokens on basics Claude already knows ("' OR 1=1--", "{{7*7}}", generic XXE/SSTI probes) alongside the genuinely novel bypass material, fitting anchor 4 rather than the fully lean anchor 5. | 4 / 5 |
Actionability | Fully concrete and copy-paste ready throughout: real commands ("sqlmap -u URL --technique=BEUSTQ --risk=3 --level=5 --os-shell"), exact headers ("X-Forwarded-For: 127.0.0.1, 10.0.0.1"), concrete paths, and observable verification signals like the 146B vs 16B response-size fingerprints. | 5 / 5 |
Workflow Clarity | Category sections plus numbered sub-procedures (STOMP 1-2, CDN bypass ①-⑤) and explicit verification steps ("验证: 正常/admin返回nginx 403, 用/api/v1/v/..;/admin返回Tomcat 404 = 绕过成功") provide clear sequence with most checkpoints, but there is no end-to-end workflow and several risky escalation paths lack an explicit validate-before-escalate step, so it does not reach anchor 5. | 4 / 5 |
Progressive Disclosure | Everything lives in one monolithic fenced code block (~80 lines) with no markdown headers, no navigable section anchors, and no reference files; the internal === markers give some structure, but content that clearly belongs in separate per-domain reference files is inlined, matching anchor 3. | 3 / 5 |
Total | 16 / 20 Passed |