CtrlK
BlogDocsLog inGet started
Tessl Logo

clickjacking

UI redressing — missing X-Frame-Options / frame-ancestors, frame-buster bypass, drag-and-drop, cursorjacking, double-clickjacking, and sensitive-action framing.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The playbook is concise, highly actionable, and well-sequenced with a validation decision gate, all without bundle-file overhead. It is a strong, self-contained skill body with no notable weak dimensions.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — no padding explaining what iframes or CSP are — and uses compact tables and code where every token earns its place, matching the 'lean and efficient' anchor.

3 / 3

Actionability

Provides copy-paste-ready executable detection (curl + header grep), concrete HTML PoCs with exact sandbox attributes, and named tools (Burp Clickbandit, clickjacker.io), matching 'fully executable code/commands; copy-paste ready'.

3 / 3

Workflow Clarity

A clear detection-to-exploitation sequence is laid out across numbered sections and capped by a 'Decision Gate' checklist with validation checkboxes ('If all checked, escalate...otherwise downgrade'), providing an explicit feedback checkpoint.

3 / 3

Progressive Disclosure

No bundle files are present, so per the simple-skills note a single well-organized file with clear numbered sections and a decision gate qualifies for the top anchor; content is appropriately inline rather than artificially split.

3 / 3

Total

12

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, well-targeted, and distinct, but omits an explicit 'when to use' clause, which caps completeness. Adding a 'Use when...' trigger clause would raise it to full marks.

Suggestions

Append an explicit trigger clause such as 'Use when testing a web app for UI redressing, missing frame protections, or sensitive-action framing.'

Mention the layman term 'clickjacking' directly in the description so a user who says that word gets an unambiguous match.

DimensionReasoningScore

Specificity

Names the domain ('UI redressing') and lists many concrete sub-techniques — 'missing X-Frame-Options / frame-ancestors, frame-buster bypass, drag-and-drop, cursorjacking, double-clickjacking, and sensitive-action framing' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It strongly answers 'what' but contains no 'Use when...' clause or equivalent explicit trigger guidance, so per the judging guideline completeness is capped at 2.

2 / 3

Trigger Term Quality

Covers natural terms a user would say in this niche — 'UI redressing', 'frame-ancestors', 'frame-buster', 'cursorjacking', 'double-clickjacking' — alongside the common 'frame' phrasing, giving good coverage rather than only technical jargon.

3 / 3

Distinctiveness Conflict Risk

The UI-redressing/clickjacking niche has distinct triggers and is unlikely to fire for unrelated skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.