CtrlK
BlogDocsLog inGet started
Tessl Logo

initial-access-phishing

初始访问/钓鱼/社工:凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing。Use when needing initial access, phishing, AiTM, device code, or social engineering.

68

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a lean, tool-rich reference cheat-sheet that is highly token-efficient and mostly actionable, but it lacks an explicit sequenced workflow with validation checkpoints and has minimal internal organization.

Suggestions

Add a brief numbered workflow with validation/verification checkpoints (e.g., confirm session token validity after AiTM, verify token scope after device-code flow) to lift workflow clarity above the destructive-skill cap of 3.

Provide one or two concrete command invocations (e.g., a sample evilginx3 phishlet launch or TokenTactics device-code request) to move actionability from playbook-level to copy-paste executable.

Break the monolithic code block into labeled sub-sections (Credential spraying / AiTM / Device code / Payloads / OAuth / Social engineering) to improve navigability within the single file.

DimensionReasoningScore

Conciseness

The body is an extremely dense cheat-sheet where every token earns its place and assumes Claude's competence, with no over-explanation of what phishing or MFA is.

5 / 5

Actionability

Names concrete tools (evilginx3, Modlishka, TokenTactics, AADInternals, gophish), payload types (lnk/iso/宏/HTA/OneNote), and bypass methods, giving mostly actionable guidance, but stops short of copy-paste command sequences.

4 / 5

Workflow Clarity

Techniques are presented as a flat unordered list with only an implicit chaining hint at the end and no explicit validation checkpoints; for a destructive/attack skill, the missing validation feedback loop caps this at 3.

3 / 5

Progressive Disclosure

A short (<50 line) self-contained single-section cheat sheet with no nested references, which is appropriate for a simple skill, though it is one undivided code block that could use internal sub-headers.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and distinct, clearly stating both the capabilities and a natural 'Use when' trigger clause. Trigger-term coverage is strong but could add a few more natural synonyms.

DimensionReasoningScore

Specificity

Lists multiple specific concrete capabilities (凭据喷洒, AiTM, 设备码, OAuth同意钓鱼, 载荷, vishing) giving comprehensive coverage of the initial-access domain, matching the anchor for several specific concrete actions.

5 / 5

Completeness

Clearly answers 'what' (the enumerated techniques) and explicitly answers 'when' via the 'Use when needing initial access, phishing, AiTM, device code, or social engineering' clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

The 'Use when' clause includes natural terms (initial access, phishing, AiTM, device code, social engineering) with good coverage, but a few natural synonyms (MFA bypass, OAuth) are missing from the trigger phrasing.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear, narrow niche (external-to-internal initial access phishing/social engineering) with distinct triggers and minimal overlap risk against other skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.