CtrlK
BlogDocsLog inGet started
Tessl Logo

component-vuln-intel

联网情报收集:识别组件后必做CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路。Use when a framework/component/version is identified and must search before exploit.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

92%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, lean, and well-sequenced intelligence-gathering workflow with strong error-recovery feedback loops. Its only weakness is structural: everything lives in one undifferentiated code block with no markdown sectioning or progressive disclosure.

Suggestions

Break the single fenced code block into markdown sections (e.g., ## 主搜索序列, ## 受阻换路, ## 兜底) so the overview is scannable before the dense command listing.

Move the long per-channel command lists into a references/ file (e.g. CHANNELS.md) and keep SKILL.md as a concise overview pointing to it, improving progressive disclosure.

Add a brief one-line validation note between search steps indicating how to mark a result as a tentative lead versus a confirmed Fact, reinforcing the workflow's verification checkpoint.

DimensionReasoningScore

Conciseness

The body is almost entirely executable commands with no concept-padding (no explanation of what a CVE is or how curl works), assuming Claude's competence and earning its tokens as actionable search channels. It is not a 2 because there is no unnecessary explanation to tighten.

3 / 3

Actionability

Every step is a concrete 'terminal:' or 'browser_navigate:' command with real URLs and {C}/{V} substitution templates, plus executable python one-liners, making it copy-paste ready.

3 / 3

Workflow Clarity

A clear numbered 1–7 sequence is paired with a ①–⑦ blocked-recovery feedback loop and a terminal negative-fact fallback ('全部受阻仍无结果→写负Fact→转 zero-day-discovery'), matching the anchor for explicit validation and error-recovery loops.

3 / 3

Progressive Disclosure

No bundle files exist and the body is a single monolithic fenced code block with no markdown sectioning, so it is not a 3 despite the skill being short; internal numbering and one-level sibling-skill references provide enough structure to avoid a 1.

2 / 3

Total

11

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-triggered pentest intelligence-gathering description that clearly answers both what and when for its niche. The main weakness is the dense bilingual channel enumeration, which reads as technical jargon rather than natural user phrasing.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions (CVE库, 搜索引擎, 中文社区, GitHub PoC, 资产引擎, 即时情报, 依赖扩展, 受阻换路), matching the anchor 'lists multiple specific concrete actions'.

3 / 3

Completeness

It explicitly states what it does (联网情报收集 with named channels and blocked-handling) and when to use it via a standard 'Use when...' trigger, satisfying both what and when. It uses the conventional 'Use when...' form, not penalizable second person.

3 / 3

Trigger Term Quality

The English 'Use when a framework/component/version is identified and must search before exploit' supplies relevant keywords (CVE, exploit, PoC), but the what-portion is a dense channel-name enumeration in mixed Chinese rather than natural user phrasing, so it is not a clean 3.

2 / 3

Distinctiveness Conflict Risk

It targets a clear red-team intel-gathering niche tied to component identification and references sibling skills (proxy-tool-bootstrap, zero-day-discovery), making it unlikely to trigger for the wrong skill.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.