CtrlK
BlogDocsLog inGet started
Tessl Logo

initial-access-phishing

初始访问/钓鱼/社工:凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing。Use when needing initial access, phishing, AiTM, device code, or social engineering.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an impressively concise reference catalog naming real tools and techniques, but it stops short of executable, copy-paste guidance and lacks workflow checkpoints or any file-based progressive disclosure structure.

Suggestions

Add at least one concrete, runnable command or example per technique (e.g., an evilginx3 phishlet invocation or a gophish campaign send snippet) to lift actionability from descriptive to executable.

Introduce a short validation/verification checkpoint for the batch/risky operations (e.g., confirm spray-rate lockout avoidance before proceeding) so workflow clarity can score higher.

Break the monolithic code block into a few short headed sections (e.g., 'Credential spraying', 'AiTM', 'Device code') to give the content navigable structure and improve progressive disclosure.

DimensionReasoningScore

Conciseness

A dense, token-efficient cheatsheet with no padded explanation of concepts Claude already knows; every token earns its place, matching the score-3 anchor.

3 / 3

Actionability

Names concrete tools (evilginx3, Modlishka, TokenTactics, AADInternals, gophish) and payload types, but gives descriptive shorthand rather than copy-paste executable commands, fitting the score-2 anchor of incomplete concrete guidance.

2 / 3

Workflow Clarity

Provides a loose entry-to-handoff flow ('→ 初始access落地即转 redteam-opsec') but no explicit validation checkpoints for the batch/risky operations it describes, capping it at 2 per the guidelines.

2 / 3

Progressive Disclosure

No bundle files exist and the body is a single monolithic code block with no section headers or navigation; the pipe-separated rows give minimal internal organization but no file-level structure.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise yet complete, naming concrete capabilities alongside an explicit 'Use when...' trigger clause. It is distinctive and unlikely to conflict with sibling skills.

DimensionReasoningScore

Specificity

Enumerates multiple concrete techniques — '凭据喷洒,AiTM,设备码,OAuth同意钓鱼,载荷,vishing' — matching the score-3 anchor of listing several specific concrete actions.

3 / 3

Completeness

Clearly answers both 'what' (enumerated initial-access techniques) and explicit 'when' via the 'Use when...' clause, matching the score-3 anchor.

3 / 3

Trigger Term Quality

The 'Use when needing initial access, phishing, AiTM, device code, or social engineering' clause gives good coverage of natural terms a red-team operator would actually say.

3 / 3

Distinctiveness Conflict Risk

A clearly defined niche (initial access/phishing/social engineering) with distinct, specific triggers unlikely to conflict with other skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.