CtrlK
BlogDocsLog inGet started
Tessl Logo

zero-day-discovery

0day自主发现引擎:变体分析/补丁间隙/差分/Fuzzing/污点推理/N-day武器化/猎人思维。Use when public vulns not found and need to discover 0day or weaponize N-day.

54

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/zero-day-discovery/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a dense, token-efficient method map for 0day discovery that correctly names the right tools and includes a verification checklist, but it stops short of being actionable: no executable commands, example queries, or harness code. Formatting everything into one code block also hurts navigability despite the small size.

Suggestions

Convert the code block into headed markdown sections (one per approach, plus 'Hunter mindset' and 'Verification') so the map is scannable.

Add one concrete executable artifact per major path — e.g., a minimal CodeQL taint-tracking query for the taint approach, an AFL++/libFuzzer harness skeleton, and a variant-analysis grep/semgrep command line.

Add a selection heuristic (which path to try first given source access, patch availability, or protocol access) and a failure-handling loop for the verification step (e.g., what to do when a crash is not reproducible).

DimensionReasoningScore

Conciseness

The body is very dense and token-efficient: it assumes competence (names AFL++, libFuzzer, boofuzz, radamsa, restler, CodeQL, Semgrep, Joern, bindiff, diaphora without explaining them) and wastes little on background. Minor trimming is possible (e.g., the parenthetical tool annotations), and the choice to pack everything into one code block makes it harder to scan than plain markdown would be.

4 / 5

Actionability

Concrete method outlines are present ('拿一个CVE补丁→提炼漏洞模式→全库grep同模式其它位置') and specific tools are named per approach, but there are no executable commands, no example CodeQL/Semgrep queries, no harness skeleton, and no crash-triage procedure — the guidance reads as a high-level method map rather than steps Claude can directly execute.

3 / 5

Workflow Clarity

The five approaches are enumerated and a verification section exists ('0day验证: 可复现(最小PoC)+根因清楚+影响可证+排除误报'), which serves as a validation checkpoint. However, there is no guidance on selecting among the five paths, no ordering across them, and no feedback loop (what to do when verification fails or a crash is not reproducible), so checkpoints remain implicit.

3 / 5

Progressive Disclosure

At ~30 lines with no bundle files (no references/, scripts/, or assets/ exist), the skill could qualify for a 5 with well-organized sections, but the entire body is a single monolithic code block under one heading — the five methods, hunter-mindset checklist, and verification criteria are not separated into scannable sections, so structure is present but poorly organized.

3 / 5

Total

13

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description covers a clear, distinctive niche with an explicit use-when clause and a broad list of capability areas. Its main weaknesses are the heavily compressed, jargon-dense capability list and missing natural trigger synonyms (zero-day, exploit, PoC), which keep it from top scores.

Suggestions

Expand the capability list into short concrete action phrases (e.g., 'Performs variant analysis from CVE patches, builds fuzzing harnesses, traces taint flows with CodeQL') so the 'what' is unambiguous.

Add natural trigger synonyms users would actually say: 'zero-day', 'exploit development', 'no public PoC available', 'CVE analysis'.

Keep the description primarily in one language to maximize trigger matching; if bilingual, mirror the key English keywords.

DimensionReasoningScore

Specificity

The description lists several concrete capability areas — '变体分析/补丁间隙/差分/Fuzzing/污点推理/N-day武器化/猎人思维' (variant analysis, patch-gap, differential testing, fuzzing, taint reasoning, N-day weaponization, hunter mindset) — giving good coverage of the domain, though the slash-delimited list gives no indication of what each method actually involves, leaving minor gaps.

4 / 5

Completeness

Both parts are present: 'what' via the terse capability list, and an explicit 'when' — 'Use when public vulns not found and need to discover 0day or weaponize N-day'. The 'when' clause is explicit and reasonably specific, but the 'what' is a compressed label list rather than a clear statement of actions, so it falls short of the level-5 anchor.

4 / 5

Trigger Term Quality

It includes relevant terms ('0day', 'N-day', 'weaponize', 'Fuzzing') and an explicit trigger phrase, but misses common natural variations users would say: 'zero-day' spelled out, 'exploit development', 'PoC', 'CVE analysis'. The mixed Chinese/English phrasing ('0day自主发现引擎') further limits natural English trigger matching.

3 / 5

Distinctiveness Conflict Risk

The 0day discovery / N-day weaponization niche is clear and the trigger ('public vulns not found') is distinct, so it is unlikely to fire for unrelated skills. Minor overlap risk remains with general penetration-testing or vulnerability-analysis skills tagged in metadata.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.