CtrlK
BlogDocsLog inGet started
Tessl Logo

unlimited-attack-scope

不设限原则:搜索/验证/串联/记录一切,全领域适用,被拦换路,不达不休。Use when reminding scope is unlimited across Web/APK/cloud/AI/wireless/social eng.

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/unlimited-attack-scope/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is lean and assumes Claude's competence, but it is more motivational aphorism than actionable guidance, with an only-implicit workflow and references to external concepts that are not defined here or in any bundle file.

Suggestions

Add one concrete, executable step or example for each directive (e.g. name specific search channels, a concrete verification check, or a chaining technique) to move from aphorism to actionable instruction.

Make the workflow sequence explicit (e.g. numbered steps) with an explicit validation checkpoint after the search/verify phase, rather than dot-separated parallel principles.

Either define or link the referenced concepts (OODA, 项目黑板Fact, 验证铁律, 组合拳) so the skill is self-contained, or move them into a referenced bundle file.

DimensionReasoningScore

Conciseness

The body is very short and dense with no padding of concepts Claude already knows, but the closing motivational lines ("这条链可能全世界只有你这一个目标适用...这就是跳出固有框架的真正含义") are inspiring rather than instructional and could be trimmed.

4 / 5

Actionability

Guidance is high-level aphorisms ("搜索一切", "串联一切", "被拦换路") with no concrete steps, tools, channels, or methods specified, leaving only minimal concrete direction for execution.

2 / 5

Workflow Clarity

The four directives (search → verify → chain → record) imply a loose sequence with one implicit validation checkpoint ("验证一切(搜索≠漏洞)"), but the sequence is not explicit and checkpoints are implicit rather than stated.

3 / 5

Progressive Disclosure

As a sub-50-line single-purpose skill with no external file needs, it is well-organized in one section, but it references undefined sibling concepts (OODA, 项目黑板Fact, 验证铁律, 组合拳) not present in this skill or any bundle, slightly reducing self-contained navigability.

4 / 5

Total

13

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description covers both what the skill advocates and when to invoke it, with a clear niche, but the trigger phrasing is unnatural and the stated actions are abstract verbs applied generically rather than concrete capabilities.

Suggestions

Rewrite the trigger as a phrase a user would naturally say, e.g. "Use when planning or scoping a pentest/red-team engagement across Web, APK, cloud, AI, wireless, or social-engineering surfaces."

Replace the generic "搜索/验证/串联/记录一切" with one or two concrete examples of what each action produces, so the capability reads as specific rather than aphoristic.

DimensionReasoningScore

Specificity

Names several concrete action verbs ("搜索/验证/串联/记录" = search/verify/chain/record) but applies them generically to "一切" (everything) without concrete objects, leaving it at the domain-plus-actions-but-not-comprehensive level rather than clearly comprehensive.

3 / 5

Completeness

Both "what" (the no-limits principle: search/verify/chain/record across all domains) and "when" (explicit "Use when..." with named domains) are present, but the "what" is an abstract principle and the trigger wording could be more natural and specific.

4 / 5

Trigger Term Quality

The "Use when" clause lists relevant domain keywords (Web/APK/cloud/AI/wireless/social eng), but the trigger phrasing "reminding scope is unlimited" is awkward and not a phrase users would naturally say, so keyword coverage is partial rather than strong.

3 / 5

Distinctiveness Conflict Risk

It carves a distinct niche (a pentest/red-team unlimited-scope mindset) with a distinctive trigger ("scope is unlimited"), though its very broad domain coverage (Web/APK/cloud/AI/wireless/social eng) creates minor overlap risk with other security skills.

4 / 5

Total

14

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.