CtrlK
BlogDocsLog inGet started
Tessl Logo

chain-credential-reuse

Build chains where leaked or weak credentials pivot across services to privileged access.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/analyst/chains/cred-reuse/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is exceptionally concise and well-organized for a simple skill, but its actionability and workflow clarity are limited by high-level, abstract steps with no concrete example chain or validation checkpoints.

Suggestions

Add one concrete worked example of a credential-reuse chain (e.g., leaked password → reuse on SSO → grants edge to admin service) to make the guidance executable rather than conceptual.

Tighten the canonical path into actionable steps and add a verification checkpoint (e.g., confirm the grants edge reaches the crown-jewel node before declaring success).

DimensionReasoningScore

Conciseness

The body is nine lean lines with no padding and no explanation of concepts Claude already knows; every token earns its place.

3 / 3

Actionability

It names concrete graph constructs ("credential" nodes, "auth_as" and "grants" edges) but provides no concrete example chain or executable walkthrough, leaving the guidance incomplete.

2 / 3

Workflow Clarity

The canonical path lists a sequenced three-step process (obtain → reuse → escalate) but the steps are high-level conceptual phases with no validation or verification checkpoints.

2 / 3

Progressive Disclosure

Under 50 lines with no bundle files and no need for external references, the body is well-organized into clear sections (Canonical path, Graph guidance), satisfying the simple-skill carve-out.

3 / 3

Total

10

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive with a clear security niche, but it lacks an explicit in-description "Use when..." trigger clause and has incomplete keyword coverage, capping completeness and trigger-term quality at 2.

Suggestions

Add an explicit trigger clause to the description, e.g. "Use when the user mentions credential reuse, leaked passwords, weak/default credentials, or pivoting from one service to another via shared auth."

Expand natural trigger terms in the description to include common variations like "password", "SSO", and "OAuth" so users' phrasing matches the skill.

DimensionReasoningScore

Specificity

"Build chains where leaked or weak credentials pivot across services to privileged access" names the domain and concrete actions (pivot, reach privileged access), but describes a single compound chain rather than a comprehensive list of multiple distinct actions.

2 / 3

Completeness

The description answers "what" (build credential reuse chains) but contains no explicit "Use when..." trigger clause within the description field itself, capping completeness at 2 per the judging guidelines.

2 / 3

Trigger Term Quality

The description contains relevant natural terms ("leaked or weak credentials", "pivot across services", "privileged access") but misses common variations a user might say such as "password", "SSO", or "OAuth" that appear only in the separate when_to_use metadata.

2 / 3

Distinctiveness Conflict Risk

"Credential reuse pivot chains to privileged access" carves a clear niche (credential-access / lateral pivoting) with distinct triggers unlikely to conflict with other skills.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.