CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-agent-os

渗透测试Agent操作系统。把渗透抽象成状态空间搜索:不预设固定路径,以项目黑板 Fact 图 (upsert_project_fact)+漏洞记录沉淀认知,路径从已验证事实上涌现。覆盖全杀伤链攻击手法 (联网情报/Web/认证/服务端/源码/社工/后渗透/二进制/内网域/云/区块链/AI/无线/硬件)+0day+ 组合拳+代理自举。核心:全网搜不到洞时现场推导独属于目标的攻击链。本文件为套件索引。 Use when starting a full-chain pentest engagement or needing the skill map for this suite.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured suite index that excels at progressive disclosure and provides concrete, navigable guidance. The opening philosophical blockquote and delegated validation are the only minor efficiency/clarity gaps.

Suggestions

Tighten the opening blockquote to one line so the mapping table — the index's real value — appears sooner.

Add a one-line inline validation cue (e.g. 'every claimed finding must pass pentest-verification before writing a confirmed Fact') so the workflow checkpoint is visible without loading another skill.

DimensionReasoningScore

Conciseness

The body is lean — a mapping table, four usage steps, and a trigger quick-ref — with only minor over-explanation in the opening manifesto blockquote ('渗透不是执行脚本,是搜索路径') which conveys the core mental model but could be trimmed.

4 / 5

Actionability

Provides concrete navigation guidance: exact skill names per attack surface, a 4-step loading sequence, and trigger→action mappings ('触发1[识别→搜] → 执行 component-vuln-intel 全部命令'); minor gaps in that actual command bodies live in the referenced skills.

4 / 5

Workflow Clarity

The '使用方式' section gives a clear 4-step loading sequence and the trigger quick-ref maps three triggers to concrete actions with validation cues ('验证后再 confirmed/漏洞', '不通则写负结果 Fact'); validation itself is delegated to the pentest-verification skill rather than inline, a minor gap.

4 / 5

Progressive Disclosure

As a suite index it is the ideal progressive-disclosure shape: a concise overview table mapping each topic to a one-level-deep skill name with its purpose, plus clearly signaled navigation; no nested references and no monolithic inlining.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that concretely enumerates the suite's coverage and mental model with an explicit 'Use when' trigger. The only weakness is a somewhat narrow trigger clause that omits common synonyms a user might naturally say.

Suggestions

Broaden the 'Use when' clause with synonyms users would naturally say, e.g. 'Use when starting a penetration testing / red-team engagement, planning a full-chain attack, or needing the skill map for this suite.'

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — state-space search, project blackboard Fact graph via upsert_project_fact, full kill-chain coverage (Web/auth/server-side/source/social/post-exploit/binary/AD/cloud/blockchain/AI/wireless/hardware), 0day, combination chains, and proxy bootstrap — matching the 'comprehensive coverage' anchor.

5 / 5

Completeness

Explicitly answers both 'what' (suite index abstracting pentest as state-space search over a Fact graph) and 'when' ('Use when starting a full-chain pentest engagement or needing the skill map for this suite') with a concrete trigger phrase, in third person.

5 / 5

Trigger Term Quality

Includes natural terms a user would say ('渗透测试', 'full-chain pentest engagement', 'skill map') but the 'Use when' clause is narrow and misses common synonyms like 'penetration testing', '红队 engagement', or 'vulnerability assessment'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (autonomous full-chain pentest orchestration) with distinct triggers and minimal overlap risk with other skills; the 'full-chain pentest engagement' trigger is unlikely to fire for unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.