CtrlK
BlogDocsLog inGet started
Tessl Logo

web-attack-methods

Web全栈攻击:SQLi/命令注入/SSTI/XSS/SSRF/NoSQL,认证JWT/OAuth/SAML,LFI/上传,Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS挑战绕过。Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/web-attack-methods/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, token-dense attack cheat sheet whose concrete commands and verification signals are its strongest asset. Its weaknesses are structural: a single monolithic code block with no progressive disclosure, and some tokens spent on well-known basic payloads.

Suggestions

Split the monolithic code block into markdown sections per domain (注入 / 认证 / 服务端 / 杂项 / CDN) with headers, moving bulk per-technique detail into one-level-deep reference files (e.g., references/cdn-bypass.md) so SKILL.md serves as a navigable overview.

Trim basic-knowledge payloads (' OR 1=1--, {{7*7}}, generic XXE entities) and keep the tokens for the non-obvious material — bypass chains, fingerprints, and verification signals — that Claude would not reliably recall.

Add explicit validate-before-escalate checkpoints to the risky chains (e.g., confirm the 146B/16B or 403/404 fingerprint before chaining into webshell upload), turning the scattered 验证/检测 notes into a consistent loop.

DimensionReasoningScore

Conciseness

The body is extremely dense shorthand with essentially no padding and no concept explanations, but it spends tokens on basics Claude already knows ("' OR 1=1--", "{{7*7}}", generic XXE/SSTI probes) alongside the genuinely novel bypass material, fitting anchor 4 rather than the fully lean anchor 5.

4 / 5

Actionability

Fully concrete and copy-paste ready throughout: real commands ("sqlmap -u URL --technique=BEUSTQ --risk=3 --level=5 --os-shell"), exact headers ("X-Forwarded-For: 127.0.0.1, 10.0.0.1"), concrete paths, and observable verification signals like the 146B vs 16B response-size fingerprints.

5 / 5

Workflow Clarity

Category sections plus numbered sub-procedures (STOMP 1-2, CDN bypass ①-⑤) and explicit verification steps ("验证: 正常/admin返回nginx 403, 用/api/v1/v/..;/admin返回Tomcat 404 = 绕过成功") provide clear sequence with most checkpoints, but there is no end-to-end workflow and several risky escalation paths lack an explicit validate-before-escalate step, so it does not reach anchor 5.

4 / 5

Progressive Disclosure

Everything lives in one monolithic fenced code block (~80 lines) with no markdown headers, no navigable section anchors, and no reference files; the internal === markers give some structure, but content that clearly belongs in separate per-domain reference files is inlined, matching anchor 3.

3 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, specific description that clearly delimits a niche domain and includes an explicit "Use when" trigger clause. Its main weaknesses are keyword-style compression of the capability list and a terse trigger clause missing common synonyms like "penetration testing".

Suggestions

Convert a few of the noun labels into explicit actions (e.g., "Exploits SQLi/command injection/SSTI/XSS/SSRF, bypasses JWT/OAuth/SAML auth") so the capability list reads as concrete actions rather than compressed tags.

Add common trigger synonyms to the when-clause, e.g., "Use when performing penetration testing, web security testing, or authorized attack simulation involving injection, auth bypass, or WAF/CDN bypass."

DimensionReasoningScore

Specificity

Enumerates many concrete technique families ("SQLi/命令注入/SSTI/XSS/SSRF/NoSQL", "认证JWT/OAuth/SAML", "LFI/上传", "Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS挑战绕过") with only minor coverage gaps, but they are compressed noun labels rather than explicitly stated actions, so it falls just short of the anchor-5 example of fully action-verb coverage.

4 / 5

Completeness

Both "what" (the enumerated attack families) and "when" (an explicit "Use when testing..." clause) are present, but the when-clause is terse and could be more specific about contexts, so it matches anchor 4 rather than the fully explicit anchor-5 example.

4 / 5

Trigger Term Quality

The trigger clause "Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass" plus named techniques (SQLi, XSS, SSRF, JWT) gives good natural keyword coverage, but common synonyms users would say such as "penetration testing", "pentest", or "web security testing" are absent from the trigger phrasing.

4 / 5

Distinctiveness Conflict Risk

A clear niche — offensive web attack techniques including unusual specific triggers like 网宿 JS 挑战, PATH_INFO, and CDN 502 bypass — makes it highly distinguishable from other skills with minimal conflict risk.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.