CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-agent-os

渗透测试Agent操作系统。把渗透抽象成状态空间搜索:不预设固定路径,以项目黑板 Fact 图 (upsert_project_fact)+漏洞记录沉淀认知,路径从已验证事实上涌现。覆盖全杀伤链攻击手法 (联网情报/Web/认证/服务端/源码/社工/后渗透/二进制/内网域/云/区块链/AI/无线/硬件)+0day+ 组合拳+代理自举。核心:全网搜不到洞时现场推导独属于目标的攻击链。本文件为套件索引。 Use when starting a full-chain pentest engagement or needing the skill map for this suite.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured suite index that is token-efficient, clearly sequenced, and uses progressive disclosure to route to sibling skills. As an index it is appropriately pointer-based, which limits raw executable actionability but fits its role.

DimensionReasoningScore

Conciseness

Lean and table-driven with no concept explanation or filler — every line earns its place (skill map, usage steps, trigger cheat-sheet), matching the 'lean and efficient; every token earns its place' anchor.

3 / 3

Actionability

Provides concrete skill names and a clear load sequence, but guidance is pointer-based rather than executable code/commands — appropriate for an index but not copy-paste ready, matching the 'some concrete guidance but incomplete' anchor.

2 / 3

Workflow Clarity

Gives an explicit numbered usage sequence (1–4) plus a trigger→action mapping table; the index workflow (load index → load skill by surface → keep residents) is unambiguous, matching the simple/index-skill allowance for a clear single-purpose flow.

3 / 3

Progressive Disclosure

The body itself is the overview and points one level deep to named sibling skills via a well-organized table with clear navigation, matching the 'clear overview with well-signaled one-level-deep references' anchor.

3 / 3

Total

11

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, specific description that explicitly states both capability and trigger; the only soft spot is trigger-term breadth. It reads as a focused, distinctive suite index rather than a generic skill.

Suggestions

Broaden trigger terms to natural phrasings users would actually say (e.g. add 'penetration test', 'red team engagement', 'vulnerability hunt', 'exploit chain') so the skill surfaces for a wider range of real requests.

The English 'Use when...' clause is currently appended after a long Chinese block; consider foregrounding it or providing both languages symmetrically to keep the trigger parseable at a glance.

DimensionReasoningScore

Specificity

Enumerates many concrete capabilities and coverage areas — '联网情报/Web/认证/服务端/源码/社工/后渗透/二进制/内网域/云/区块链/AI/无线/硬件 + 0day + 组合拳 + 代理自举' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Clearly answers what (suite OS abstracting pentest as state-space search with full kill-chain coverage) and when (explicit 'Use when...' clause), matching the 'clearly answers both what AND when' anchor.

3 / 3

Trigger Term Quality

Has an explicit trigger ('Use when starting a full-chain pentest engagement or needing the skill map for this suite') but the natural phrasing is narrow and lacks common variations like 'penetration test', 'red team', or 'vuln hunt', matching the 'some relevant keywords but missing common variations' anchor.

2 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (full-chain autonomous pentest suite index) with distinct triggers unlikely to fire for unrelated skills; uses third-person voice with no first/second person penalty.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.