CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-output-standards

输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。 Use when reporting findings, maintaining change ledger, or formatting pentest output.

74

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally dense, actionable output-standard spec that sequences multi-step processes with explicit validation and recovery checkpoints while staying token-efficient. It is a model lean instruction-only skill body.

DimensionReasoningScore

Conciseness

The body is a dense, label-driven specification with no concept padding and no explanation of things Claude already knows; every line carries an actionable rule, matching the 'lean and efficient' anchor.

3 / 3

Actionability

It gives concrete field schemas (漏洞名+严重程度+影响版本+…), exact tool calls (upsert_project_fact, record_vulnerability, list/search_project_facts), and an exact ledger format (#|时间|主机|类型|位置|内容|回滚命令) — fully actionable instruction-only guidance.

3 / 3

Workflow Clarity

Sequences are explicit (per-step chain-of-thought flow), with checkpoints (每轮结束 graph overview), validation (✓实际输出 evidence, .bak backup before config change), a rollback script, and a deadlock-recovery feedback loop, so destructive-op validation is not missing.

3 / 3

Progressive Disclosure

This is a sub-50-line single-purpose skill with no external references needed; the single well-organized '## 输出规范' section qualifies for the top anchor under the simple-skills scoring note.

3 / 3

Total

12

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A compact, well-scoped description that pairs a concrete capability list with an explicit 'Use when' trigger. Its main weakness is jargon-heavy terminology in the what-list that limits natural trigger-term coverage.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete output artifacts — '中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破' — which is a multi-item list of specific capabilities, matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It explicitly answers both what (the output-standards list) and when ('Use when reporting findings, maintaining change ledger, or formatting pentest output'), matching the 'clearly answers both' anchor.

3 / 3

Trigger Term Quality

The 'Use when reporting findings, maintaining change ledger, or formatting pentest output' clause supplies natural triggers, but the what-list is heavy with internal jargon (思维链, 黑板状态总览, 死锁突破) a user would rarely say and offers few variations, so coverage is partial.

2 / 3

Distinctiveness Conflict Risk

The pentest-output/reporting niche is clearly scoped with distinct triggers (findings, change ledger, pentest output), making conflicts with unrelated skills unlikely.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.