CtrlK
BlogDocsLog inGet started
Tessl Logo

web-attack-methods

Web全栈攻击:SQLi/命令注入/SSTI/XSS/SSRF/NoSQL,认证JWT/OAuth/SAML,LFI/上传,Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS挑战绕过。Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

80%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, highly actionable pentest cheat-sheet with concrete payloads and inline verification cues, but it is a monolithic single-file catalog rather than a structured workflow or a progressively disclosed multi-file bundle.

Suggestions

Break the monolithic code block into organized sections (Quick reference, Auth bypass, Server-side, CDN/WAF) with concise prose headers instead of one unstructured fenced block.

Move the long per-technique detail (e.g. the CDN-502 and 网宿 JS-challenge case studies) into reference files under ./references/ and link to them, so the main body stays an overview.

For the multi-step bypass chains, add explicit sequenced steps with validate→fix→retry checkpoints rather than inline comma-separated notes.

DimensionReasoningScore

Conciseness

Extremely token-dense, abbreviated reference notes (e.g. "绕过 SEL/**/ECT,大小写,CHAR() | 升级 OUTFILE→webshell") that assume expertise and omit concept explanations Claude already knows, matching the lean-and-efficient anchor.

3 / 3

Actionability

Provides copy-paste-ready commands and payloads such as "sqlmap -u URL --technique=BEUSTQ --risk=3 --level=5 --os-shell", SSTI "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}", and "X-Forwarded-For: 127.0.0.1, 10.0.0.1", matching the fully executable anchor.

3 / 3

Workflow Clarity

Individual techniques embed ordered chains and verification markers ("验证:", "检测:", "快检:sign:0"), but as a whole it is a flat catalog rather than a coherent sequenced workflow with explicit validate→fix→retry feedback loops.

2 / 3

Progressive Disclosure

Content is a single ~70-line monolithic code block with labeled sections but no referenced bundle files and no split into separate materials; it exceeds the 'under 50 lines' simple-skill allowance and lacks the file-level navigation the top anchor requires.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, concrete, and well-triggered: it names a broad but specific set of web attack/bypass domains and gives a clear 'Use when' clause. Voice is third-person throughout and free of vague fluff.

DimensionReasoningScore

Specificity

Enumerates many concrete attack categories ("SQLi/命令注入/SSTI/XSS/SSRF/NoSQL", "认证JWT/OAuth/SAML", "LFI/上传", "Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502"), matching the anchor for listing multiple specific concrete actions.

3 / 3

Completeness

Explicitly states what the skill covers (the enumerated attack families) and when to use it ("Use when testing..."), satisfying both what and when with an explicit trigger clause.

3 / 3

Trigger Term Quality

The clause "Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass" supplies natural trigger phrases a user would actually say, with good coverage across injection, auth, server-side, and WAF/CDN contexts.

3 / 3

Distinctiveness Conflict Risk

The niche is sharply scoped to advanced web-pentest bypass techniques, making it unlikely to trigger for unrelated skills; the listed tokens are highly specific rather than generic.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.