CtrlK
BlogDocsLog inGet started
Tessl Logo

ai-llm-app-attack

AI/LLM应用攻击:提示注入,Agent工具滥用RCE,RAG投毒,MCP供应链,torch.load pickle RCE。Use when testing LLM apps, agents, RAG, MCP plugins, or AI model file risks.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, information-dense attack-surface cheatsheet that is highly token-efficient and covers concrete vectors, but it reads as a reference enumeration rather than executable guidance and lacks a sequenced workflow or sectioned organization.

Suggestions

Add at least one concrete, runnable payload or command per high-value vector (e.g., a sample torch.load RCE payload or an indirect-prompt-injection proof) to lift actionability from enumeration to executable instruction.

Break the single ASCII block into labeled subsections (e.g., Prompt Injection, Agent Tool Abuse, Model Files) so the cheatsheet is well-organized into sections rather than one monolithic block.

Add a short numbered workflow for validating a finding (trigger side effect -> confirm via OOB/file read -> record Fact) with explicit checkpoints, since the skill involves risky/destructive operations.

DimensionReasoningScore

Conciseness

The body is maximally token-dense telegraphic notation using '|' separators and arrows, with no explanation of concepts Claude already knows; it assumes competence, matching the 'lean and efficient; every token earns its place' anchor despite minor editorializing phrases.

3 / 3

Actionability

It offers some concrete guidance — endpoint paths '/chat /agent /tool', named tools, and the verification requirement '实际触发工具副作用(OOB回连/读到文件)才写Fact' — but provides no executable payloads or commands, fitting the 'some concrete guidance but incomplete' anchor rather than fully copy-paste-ready.

2 / 3

Workflow Clarity

Content is organized into attack categories and includes one validation checkpoint (verify tool side effects before writing a Fact), but there is no multi-step sequenced workflow or feedback loop, so it sits below the score-3 anchor and above the no-sequence/no-validation score-1 anchor.

2 / 3

Progressive Disclosure

As a short (<50 line) reference with no bundle files it needs no external references, but it is a single monolithic ASCII block under one heading rather than well-organized sections, matching the 'some structure but could be better organized' anchor rather than the score-3 well-organized-sections case.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-constructed description that names concrete attack capabilities, supplies natural trigger terms, and explicitly covers both 'what' and 'when' in a distinct niche. It is one of the stronger descriptions in the reference set.

DimensionReasoningScore

Specificity

Lists multiple concrete attack techniques — '提示注入', 'Agent工具滥用RCE', 'RAG投毒', 'MCP供应链', 'torch.load pickle RCE' — rather than vague language, matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It states both what the skill does ('AI/LLM应用攻击:...') and an explicit 'Use when ...' trigger, satisfying the 'clearly answers both what AND when' anchor; the present trigger clause keeps it above the score-2 cap.

3 / 3

Trigger Term Quality

The clause 'Use when testing LLM apps, agents, RAG, MCP plugins, or AI model file risks' covers natural terms a user would actually say, matching the 'good coverage of natural terms' anchor rather than the score-2 'missing common variations' case.

3 / 3

Distinctiveness Conflict Risk

The niche (AI/LLM application attacks) with distinct triggers (LLM apps, agents, RAG, MCP plugins) is unlikely to conflict with general skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.