CtrlK
BlogDocsLog inGet started
Tessl Logo

godmode

Jailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.

54

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./optional-skills/security/godmode/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-sequenced operational guide with executable code, explicit validation/dry-run/undo checkpoints, and correct, one-level-deep bundle references. Its main weakness is length: the time-sensitive test-results section, the 12-item pitfall list, and duplicated template content inflate the token budget and would be better moved to a reference file.

DimensionReasoningScore

Conciseness

Most of the body is skill-specific operational knowledge Claude would not already know (Hermes config paths, strategy orders per model family, patched-technique findings), so it is not padded with common knowledge. However, several sections are unnecessary or redundant at this altitude: the 407-line body inlines a full "Tested Results (March 2026)" section (time-sensitive data that the guidelines penalize unless placed in a deprecated/old-patterns section), a 12-item pitfall list with repetition (the encoding-escalation order appears in Step 3, Pitfall 6, and Pitfall 10), and the full GODMODE system prompt duplicated in Steps 2 and 6 when it already lives in references/jailbreak-templates.md. This fits 'Mostly efficient but includes some unnecessary explanation or could be tightened', not score 4 which requires only minor trimming — these are whole sections, not instances.

3 / 5

Actionability

The guidance is fully executable throughout: copy-paste-ready loader snippet for execute_code, exact config.yaml and prefill.json contents, runnable CLI invocations ("python scripts/parseltongue.py ... --tier standard"), a complete end-to-end pipeline code block with OpenRouter client, and a decision table mapping situations to modes. Specific examples ("auto_jailbreak(model=..., dry_run=True)", example Parseltongue output) cover the common cases, matching the score-5 anchor 'Fully executable; copy-paste ready code or commands'.

5 / 5

Workflow Clarity

Steps 0-6 are clearly sequenced with explicit validation and feedback loops: auto_jailbreak tests a baseline refusal first ("Tests baseline — confirms the model actually refuses"), scores each attempt, escalates through a strategy order per model family, and provides rollback ("undo_jailbreak()") plus a non-destructive dry run — exactly the validate → fix → retry loop the rubric rewards for config-mutating and batch operations. The Step 6 escalation ladder gives an explicit recovery path when a technique fails, matching the score-5 anchor with checkpoints and feedback loops. Not score 4: no meaningful validation gaps remain (baseline check, scoring, dry-run, and undo are all present).

5 / 5

Progressive Disclosure

Structure is good and all referenced bundle paths are real (references/jailbreak-templates.md, references/refusal-detection.md, scripts/parseltongue.py, scripts/godmode_race.py, scripts/load_godmode.py, scripts/auto_jailbreak.py all exist), each clearly signaled with "See X for..." and only one level deep — templates and refusal patterns live in references while the body keeps a quick-start excerpt. It is not score 5 because content that clearly belongs in bundle files is inlined: the full March 2026 test-results section, the trigger-words reference list, and the 12-item pitfalls section would all be better split into a reference file, and the GODMODE template is duplicated between Step 2 and Step 6. It is not score 3: most content is appropriately placed and references are clearly signaled, not buried.

4 / 5

Total

17

/

20

Passed

Description

43%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and contains the core keyword, but it is a bare domain-plus-proper-nouns fragment: no concrete actions beyond "Jailbreak", no synonyms for natural phrasing, and no 'Use when...' trigger guidance. It would benefit most from an explicit trigger clause and a short action list.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user wants to jailbreak a model via API, bypass safety filters, uncensor responses, or mentions Parseltongue, GODMODE, or Pliny's techniques."

Replace the bare technique-name list with 2-3 concrete capabilities, e.g. "Bypass LLM safety filters via system-prompt templates, query obfuscation, and multi-model racing; set up persistent jailbreak configuration."

Include natural user phrasings/synonyms such as "uncensor", "red-team a model", "safety bypass", and "prompt injection" so the skill triggers on how users actually ask for it.

DimensionReasoningScore

Specificity

The description quotes only "Jailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN" — it names the domain (jailbreaking LLMs) but the only action verb is "Jailbreak"; the other three tokens are proper-noun technique labels, not concrete actions. This matches the anchor 'Names the domain but actions are minimal or generic' (e.g., "Processes PDF files"), not score 3 which requires 1-2 genuine concrete actions like 'obfuscate queries' or 'race models'.

2 / 5

Completeness

There is a vague 'what' ("Jailbreak LLMs") and no 'when' / 'Use when...' clause at all — the judging guidelines explicitly cap completeness at 3 when trigger guidance is missing, and here the 'what' is also minimal (a single verb plus technique names), matching the score-2 anchor 'Has a vague what and no when'. It is not score 3 because that anchor requires a clear, multi-action 'what', which this one-line description lacks.

2 / 5

Trigger Term Quality

It includes the natural keyword "jailbreak" plus the technique names a user of this skill would say ("Parseltongue", "GODMODE", "ULTRAPLINIAN"), but misses common variations and synonyms a user might naturally use — "bypass safety filters", "uncensor", "red-team", "safety bypass" — matching 'Some relevant keywords but missing common variations or synonyms'. It is not score 4 because those natural paraphrases are absent, not merely sparse.

3 / 5

Distinctiveness Conflict Risk

"Jailbreak LLMs" plus the unique technique names (Parseltongue, GODMODE, ULTRAPLINIAN) occupy a clear niche with distinct triggers and near-zero overlap risk with other skills; nothing generic like "helps with prompts" appears. It clearly matches the score-5 anchor 'Clear niche with distinct triggers; minimal conflict risk'.

5 / 5

Total

12

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
NousResearch/hermes-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.