CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-output-standards

输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。 Use when reporting findings, maintaining change ledger, or formatting pentest output.

62

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-output-standards/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured output-standards skill that delivers concrete templates, a change-ledger schema, and per-round checkpoints with a deadlock-break feedback loop, all within a single scannable block. The main gap is the absence of explicit validate-fix-retry gates and worked examples for destructive/batch actions.

Suggestions

Add an explicit validation checkpoint for destructive/batch actions (e.g. a 'verify before record_vulnerability' gate with pass/fail criteria) so workflow_clarity can exceed the batch-operation cap.

Provide one copy-paste-ready worked example of a vulnerability report and one台账 row to lift actionability from field-lists to executable templates.

Show a minimal one-click rollback script skeleton (reverse-order) instead of only describing it, to make the destructive-change guidance fully executable.

DimensionReasoningScore

Conciseness

The body is a dense, scannable spec block that assumes Claude's competence and adds only domain-specific conventions (台账 fields, 死锁突破 protocol) rather than padding; it is not 5 because a few clauses restate somewhat obvious hygiene (e.g. '勿臆造未 get 的 body') that could be tightened.

4 / 5

Actionability

It gives concrete, executable rules — a defined report template with required fields, a台账 column schema (#|时间|主机|类型|位置|内容|回滚命令), and explicit upsert targets (record_vulnerability, upsert finding/chain/exploit/poc Fact); not 5 because templates are field lists rather than copy-paste-ready worked examples and the rollback script is described rather than shown.

4 / 5

Workflow Clarity

Multi-step processes are clearly sequenced with per-round checkpoints (图状态总览每轮结束, 改动台账实时记账, 改配置前备份.bak) and a feedback loop (死锁突破: 重审→换域→请求授权); not 5 because validation is procedural guidance rather than an explicit validate→fix→retry gate with pass/fail criteria, which the destructive/batch nature warrants.

4 / 5

Progressive Disclosure

The single fenced block is well-organized under one heading with clear sub-rules and no nested references, appropriate for a short standards skill with no bundle files present; not 5 because the inlined rules (report/台账 templates) could arguably live in dedicated reference files with signaled links for deeper use, though the simple-skill exception largely applies.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, third-person description that pairs a concrete enumeration of output standards with an explicit 'Use when' trigger, covering both what and when. It is mostly specific and distinctive, with room only for richer natural-language trigger synonyms to reach the top anchor.

DimensionReasoningScore

Specificity

The description enumerates several concrete capabilities (中文分析, 思维链, 漏洞报告模板, 负结果, 黑板状态总览, 改动台账, 死锁突破) plus explicit reporting/maintenance actions, which matches the 'lists several specific actions with minor gaps' anchor; it falls short of 5 because the actions are listed as noun topics rather than fully enumerated verbs.

4 / 5

Completeness

Both 'what' (the seven output standards) and 'when' ('Use when reporting findings, maintaining change ledger, or formatting pentest output') are present and explicit; it stops at 4 because the 'when' clause is a single concise enumeration rather than the broader, concrete trigger-phrase coverage of the 5 anchor.

4 / 5

Trigger Term Quality

It surfaces natural phrases a pentest user would say ('reporting findings', 'maintaining change ledger', 'formatting pentest output') alongside domain terms, giving good keyword coverage; not 5 because synonym/extension variants are thin and the primary triggers lean on Chinese topic labels.

4 / 5

Distinctiveness Conflict Risk

The pentest-output niche (改动台账, 死锁突破, 黑板状态总览) is distinctive and unlikely to collide with unrelated skills; not 5 because the general 'reporting findings / formatting output' framing could overlap marginally with adjacent reporting skills.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.