CtrlK
BlogDocsLog inGet started
Tessl Logo

chain-xss-to-takeover

Build chains from XSS into account takeover or privileged action execution.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/analyst/chains/xss-to-takeover/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably concise and well-structured for a simple skill, but its workflow steps are high-level goals rather than actionable techniques, and validation is noted generically rather than as explicit checkpoints.

Suggestions

Add concrete, actionable technique guidance for each step (e.g. specific payload/exfiltration approaches or commands) so Claude knows how, not just what, to do.

Convert the validation note into explicit per-step checkpoints with a fix-and-retry feedback loop, since the workflow performs privileged/destructive actions.

Specify what 'durable account impact' evidence looks like so the final validation step is unambiguous.

DimensionReasoningScore

Conciseness

The body is lean and free of padding or explanations of concepts Claude already knows; every line (canonical path steps plus a one-line validation note) earns its place.

3 / 3

Actionability

Steps name concrete artifacts ("session/CSRF token", "victim/admin account") but give no concrete methods, payloads, or commands, leaving the guidance more descriptive than executable.

2 / 3

Workflow Clarity

A clear 4-step sequence is present and a validation section exists, but for a destructive/privileged-action workflow the validation is a single general note rather than explicit per-step checkpoints or fix-and-retry feedback loops, so it is capped at 2.

2 / 3

Progressive Disclosure

The skill is under 50 lines with no bundle files and no need for external references, and its two well-organized sections (Canonical path, Validation) satisfy progressive disclosure for a simple skill.

3 / 3

Total

10

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive but incomplete: it states the capability clearly yet omits any explicit 'when to use' trigger guidance. Trigger term coverage is decent but limited.

Suggestions

Add an explicit 'Use when...' clause naming natural user triggers, e.g. 'Use when chaining an XSS finding into account takeover, cookie/session theft, CSRF token capture, or privileged action execution.'

Broaden trigger terms in the description to include common phrasings users would say, such as 'cookie theft', 'session hijacking', and 'CSRF'.

Rephrase as third-person voice ('Builds chains...') to match the recommended description style.

DimensionReasoningScore

Specificity

Quotes "Build chains from XSS into account takeover or privileged action execution" name the domain and two concrete outcomes, but describe essentially one chaining action rather than a list of multiple distinct capabilities.

2 / 3

Completeness

It clearly states what the skill does but lacks any "Use when..." clause or equivalent explicit trigger guidance in the description field, so completeness is capped at 2.

2 / 3

Trigger Term Quality

Terms like "XSS", "account takeover", and "privileged action execution" are relevant to a security tester, but common variations (cookie theft, session hijacking, CSRF) are absent from the description itself.

2 / 3

Distinctiveness Conflict Risk

The XSS-to-takeover chaining niche is specific with distinct triggers, making it unlikely to fire for unrelated skills.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.