CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-blackboard

CyberStrikeAI 项目黑板:跨会话 Fact 图(SQLite)+ upsert_project_fact/record_vulnerability 边渗透边记录节奏、关系边 links、confidence、与多代理协调落库。Use when managing project facts, blackboard index, writing evidence, or avoiding context-loss after compression.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured instruction skill with strong workflow clarity and validation discipline, held back by the absence of a worked tool-invocation example and any progressive-disclosure file structure.

Suggestions

Add one concrete worked example showing a complete upsert_project_fact call including a fact_key, summary, body, confidence, and a links array, so the guidance is copy-paste ready.

Move the tool quick-reference and link-type catalogue into a references/ file and link to it, giving the SKILL.md a leaner overview and earning progressive-disclosure credit.

DimensionReasoningScore

Conciseness

The body is terse, table-driven instruction with no padding about what pentesting or SQLite is; it assumes Claude's competence and every section earns its place, though minor redundancy exists between the primitives table and the writing-conventions section.

3 / 3

Actionability

It names concrete tools, fact_key formats, link types, and confidence values, but provides no worked example of an actual tool invocation showing argument shapes (e.g. a full upsert_project_fact call with a links array), leaving the most concrete 'copy-paste ready' tier unreached.

2 / 3

Workflow Clarity

The '强制节奏' section gives a clearly numbered sequence with explicit validation checkpoints ('验证后再 confirmed / record_vulnerability', '搜完才继续'), feedback loops (tentative→verify→deprecate), and per-step checklists in the behavior triggers.

3 / 3

Progressive Disclosure

It is well-organized into clear sections but is a single ~100-line self-contained file with no bundle files in references/scripts/assets and no offloading of detail; the under-50-line 'simple skill' exception for a 3 does not apply.

2 / 3

Total

10

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, complete description with an explicit trigger clause and a distinct niche, weakened only by jargon-heavy phrasing that limits natural trigger-term quality.

Suggestions

Lead with plain-language user-facing trigger phrases (e.g. 'Use when tracking pentest findings across sessions, recording evidence, or recovering context after compression') and keep tool/API names as supporting detail.

Replace internal terms like 'Fact 图' and '落库' in the user-facing portion with concrete phrasing such as 'structured findings database' and 'write to the blackboard'.

DimensionReasoningScore

Specificity

Names multiple concrete actions — 'upsert_project_fact/record_vulnerability', '关系边 links', 'confidence', '多代理协调落库' — rather than vague language, matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It answers both 'what' (Fact graph, upsert/record tools, edges, confidence, multi-agent coordination) and 'when' via the explicit 'Use when managing project facts, blackboard index, writing evidence...' clause.

3 / 3

Trigger Term Quality

The 'Use when managing project facts, blackboard index, writing evidence, or avoiding context-loss after compression' clause gives some natural triggers, but the bulk of the description is dense internal jargon ('Fact 图', '落库', 'confidence') that users would not naturally say, so it falls short of full coverage.

2 / 3

Distinctiveness Conflict Risk

It occupies a clear niche (pentest project blackboard / cross-session Fact graph) with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.