CtrlK
BlogDocsLog inGet started
Tessl Logo

component-vuln-intel

联网情报收集:识别组件后必做CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路。Use when a framework/component/version is identified and must search before exploit.

69

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands, a well-sequenced workflow, and a strong error-recovery feedback loop. Its weakness is structure: everything sits in one monolithic code block with no progressive disclosure or section navigation.

Suggestions

Break the single monolithic code block into markdown sub-sections (e.g., ## CVE/漏洞库, ## 搜索引擎, ## 中文社区, ## GitHub PoC, ## 资产引擎, ## 即时情报, ## 受阻换路) so the workflow is navigable rather than a wall of commands.

Move the long per-channel URL enumerations into a references/ table file and keep SKILL.md as a concise overview pointing to it, enabling one-level-deep progressive disclosure.

Trim the redundant parenthetical justifications (e.g., "中文首发多且深度分析好") and consolidate near-identical search-engine URLs into a templated loop to tighten token usage.

DimensionReasoningScore

Conciseness

The body is command-dense with no concept padding Claude already knows, but the exhaustive enumeration of many near-identical search URLs (5 engines, 6 Chinese community sites, 4 asset engines) plus brief parenthetical justifications is more than minimal and could be trimmed, fitting the efficient-but-minor-over-explanation anchor 4 rather than the lean anchor 5.

4 / 5

Actionability

Fully executable, copy-paste-ready guidance: concrete terminal curl commands with python3 one-liners and browser_navigate URLs templated with {C}/{V}, covering the common cases across every channel.

5 / 5

Workflow Clarity

A clearly sequenced mandatory 1–7 process with an explicit error-recovery feedback loop ("搜索受阻处理序列" ①–⑦) and a final escalation path to zero-day-discovery when all channels fail, matching the anchor requiring feedback loops for error recovery.

5 / 5

Progressive Disclosure

No bundle files exist and the entire workflow is inlined as one monolithic fenced code block under a single H2 heading with no markdown sub-sections or navigation; internal numbering provides some structure, but content that could be split (channel table vs. fallback sequence) is inlined, fitting anchor 3.

3 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, explicitly pairs a concrete 'what' with an explicit 'when' trigger, and occupies a distinct pentesting niche with low conflict risk. Its main limitation is that the 'what' is a terse slash-separated channel list rather than verb-stated actions.

DimensionReasoningScore

Specificity

Lists several specific concrete channels ("CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路") rather than vague language, but they are stated as channel nouns with the search action implied rather than as explicit verbs, leaving minor coverage gaps versus the comprehensive anchor 5.

4 / 5

Completeness

It explicitly answers both what (联网情报收集 across the enumerated channels) and when ("Use when a framework/component/version is identified and must search before exploit") with concrete trigger phrases, and uses third-person voice throughout.

5 / 5

Trigger Term Quality

The trigger phrase "Use when a framework/component/version is identified and must search before exploit" plus terms like CVE and PoC give good keyword coverage a pentester would naturally say, though a few common English variations/synonyms are absent.

4 / 5

Distinctiveness Conflict Risk

It carves a clear niche — post-identification exploit intel gathering — with distinctive triggers (component/version identified, search before exploit, CVE/PoC/asset engines) that minimize overlap with other skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.