CtrlK
BlogDocsLog inGet started
Tessl Logo

specialized-attack-playbooks

专题实战利用:GoEdge私钥导出,灰产CDN取证,ARP MITM,CDN→S3 STS链,宝塔+UniApp,AI IDE API反代,OCS+MinIO;含references/scripts支持文件索引。Use when applying specialized playbooks for GoEdge, CDN, ARP MITM, BT Panel, OCS, MinIO.

66

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally dense, actionable playbook body with well-sequenced, validated workflows, but it violates progressive disclosure by keeping all eight playbooks inline and indexing bundle files that do not exist on disk. It also carries inline time-sensitive version notes that would benefit from a dedicated deprecated section.

Suggestions

Move each playbook into its own reference file under references/ and keep SKILL.md as a concise overview with one-level-deep links, so the signaled 支持文件索引 corresponds to files that actually exist.

Actually create the referenced references/*.md and scripts/*.py bundle files (or remove the index entries) so navigation is not broken.

Relocate time-sensitive notes (e.g. '2026-04起', '已废' items, '2024+') into a clearly labeled '已弃用/旧方案' section so they do not clutter the live guidance.

DimensionReasoningScore

Conciseness

The body is extremely lean and telegraphic with no concept-explanation padding, but it embeds time-sensitive version/date info inline (e.g. '2026-04起只剩gemini-3-flash', '2024+', '新版已修补') outside a dedicated deprecated section, and the dense shorthand occasionally trades clarity for brevity — the guideline penalizes such inline time-sensitive content.

2 / 3

Actionability

Provides concrete, copy-paste-ready guidance throughout — exact curl fingerprints, real API endpoints, a Python extraction loop, precise headers, and decrypt scripts (e.g. the GoEdge batch-extract loop, 'arpspoof×4', ChengZi XOR steps) — matching the 'fully executable code/commands' anchor.

3 / 3

Workflow Clarity

Multi-step chains are explicitly sequenced (numbered ①-⑥ for the CDN→S3 chain, the '五步' forensics flow, and 部署/持久化/验证/清理 for ARP MITM) with explicit validation checkpoints ('验证: pgrep -c arpspoof==4', 'curl ... → 返回文件内容') and error-recovery guidance ('🚨关键坑... 修复:'), satisfying the 'clear sequence with explicit validation steps' anchor.

3 / 3

Progressive Disclosure

The body is titled '全内联' and is a monolithic wall of text with eight full playbooks inline — 'content that should be separate is inline' — while the 支持文件索引 signals references/scripts paths that do not actually exist on disk (references/, scripts/, assets/ are missing), so the signaled one-level-deep navigation points at phantom files.

2 / 3

Total

10

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description that covers concrete pentest techniques and includes an explicit 'Use when' trigger, giving it strong completeness and distinctiveness. Its main weakness is trigger-term variety, since the 'when' keywords mostly restate the capability list rather than adding natural user phrasings.

DimensionReasoningScore

Specificity

Lists multiple concrete techniques as named actions — 'GoEdge私钥导出', '灰产CDN取证', 'ARP MITM', 'CDN→S3 STS链', '宝塔+UniApp', 'AI IDE API反代', 'OCS+MinIO' — matching the 'lists multiple specific concrete actions' anchor; voice is third-person imperative ('Use when applying...'), so no specificity penalty.

3 / 3

Completeness

Explicitly answers both 'what' (the enumerated technique list) and 'when' via a present 'Use when...' clause with explicit triggers, satisfying the 'clearly answers both what AND when' anchor.

3 / 3

Trigger Term Quality

The 'Use when applying specialized playbooks for GoEdge, CDN, ARP MITM, BT Panel, OCS, MinIO' clause names relevant product/system terms, but these largely duplicate the capability list and lack the natural phrasing variations anchor 3 expects; closer to 'some relevant keywords but missing common variations'.

2 / 3

Distinctiveness Conflict Risk

Triggers are tightly scoped to named systems (GoEdge, BT Panel, OCS, MinIO, ARP MITM), forming a clear niche unlikely to fire for unrelated skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

11

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 6 missing

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.