CtrlK
BlogDocsLog inGet started
Tessl Logo

exploitability-analyzer

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Use when users need to: (1) Determine if a vulnerability is actually exploitable in practice, (2) Assess severity and impact of security issues, (3) Prioritize vulnerability remediation, (4) Understand attack vectors and exploitation conditions, (5) Generate exploitability reports with proof-of-concept scenarios. Focuses on injection vulnerabilities (SQL, command, XSS, path traversal, LDAP) with detailed analysis of reachability, controllability, sanitization, and impact.

89

1.32x
Quality

85%

Does it follow best practices?

Impact

97%

1.32x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced analysis skill with executable examples and a clear report template. Its main weaknesses are verbosity (repeated rating criteria and four full examples) and a body that could offload more to the bundled reference.

Suggestions

Remove the standalone 'Exploitability Rating Scale' section or fold it into the workflow steps, since it duplicates the Step 3-6 criteria already given inline.

Trim from four full worked examples to one or two representative ones, moving the rest into references/assessment_criteria.md to shrink the SKILL.md footprint.

Add an explicit final validation step to the workflow (e.g., re-check that reachability, controllability, and sanitization ratings are consistent with the stated overall exploitability before reporting).

DimensionReasoningScore

Conciseness

The body is mostly concrete and useful rather than padded with basics Claude knows, but at ~500 lines it carries real verbosity: the 'Exploitability Rating Scale' section restates the Step 3-6 criteria, and four full worked examples could be trimmed.

3 / 5

Actionability

Provides executable vulnerable and remediation code, concrete proof-of-concept commands, a copy-paste report-format template, and an explicit decision matrix covering common cases.

5 / 5

Workflow Clarity

A clear 7-step sequence with guiding questions, rating levels, a synthesis matrix, and a Tips checklist; the gap is the absence of an explicit validate/review-your-conclusion feedback loop on the final assessment.

4 / 5

Progressive Disclosure

Sections are well organized and the reference file is one level deep with clear 'Load this reference when' guidance, but the body itself is heavy-most content (four full examples, rating scale) is inlined rather than offloaded to the reference.

4 / 5

Total

16

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that explicitly covers what the skill does and when to use it, with concrete actions and natural trigger terms. Its only weakness is mild overlap risk with broader security-analysis skills.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('examining control flow, input sources, sanitization logic, and execution context') plus five distinct analysis tasks and a four-factor assessment breakdown, giving comprehensive coverage of capabilities.

5 / 5

Completeness

Explicitly answers both 'what' (analyze vulnerabilities to assess exploitability via the four factors) and 'when' (a five-item 'Use when users need to' clause with concrete triggers).

5 / 5

Trigger Term Quality

Covers natural user phrases ('is a vulnerability actually exploitable', 'assess severity and impact', 'prioritize remediation', 'attack vectors', 'exploitability reports', 'proof-of-concept') alongside the specific injection types users name.

5 / 5

Distinctiveness Conflict Risk

The exploitability-assessment niche (post-detection, injection-focused) is clearly distinct, but the broad security framing ('assess severity', 'vulnerability remediation') carries minor overlap risk with general security-review skills.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (506 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
ArabelaTso/Skills-4-SE
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.