CtrlK
BlogDocsLog inGet started
Tessl Logo

cors

CORS misconfiguration exploitation — reflected origin, null origin, trusted-subdomain abuse, regex-validation bypass, and credentialed cross-origin data theft.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, highly actionable CORS exploitation playbook with executable examples and an explicit validation decision gate; only marginal gains available in progressive disclosure and trimming the opening framing.

DimensionReasoningScore

Conciseness

Lean, well-organized playbook that assumes Claude's competence; only a brief opening framing paragraph ('A permissive ACAO becomes critical...') could be trimmed, otherwise every token earns its place.

4 / 5

Actionability

Provides copy-paste-ready curl probing commands, an executable credentialed-fetch PoC, a sandboxed-iframe null-origin variant, and concrete tool invocations covering the common exploitation cases.

5 / 5

Workflow Clarity

Clear numbered sequence (detect → matrix → exploit → chains → tools → OPSEC) culminating in an explicit decision-gate checklist with an escalation/downgrade feedback loop that validates before exploitation.

5 / 5

Progressive Disclosure

Well-organized single-file structure with clear section headers and no nested references; slightly above the simple-skill threshold in length, with minor opportunity to split the PoC/matrix into separate reference files.

4 / 5

Total

18

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, distinctive description of CORS exploitation capabilities, weakened only by the absence of an explicit 'when to use' trigger clause and slightly incomplete keyword coverage.

Suggestions

Add an explicit 'Use when ...' clause naming natural trigger phrases (e.g., 'Use when testing for CORS misconfigurations, Access-Control-Allow-Origin reflection, or credentialed cross-origin data theft').

Include the common acronyms/terms 'ACAO' and 'Access-Control-Allow-Origin' in the description to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete exploitation techniques — 'reflected origin, null origin, trusted-subdomain abuse, regex-validation bypass, and credentialed cross-origin data theft' — giving comprehensive coverage of the CORS attack surface.

5 / 5

Completeness

The 'what' is clear and detailed, but there is no explicit 'Use when...' trigger clause; per the rubric, a missing explicit trigger guidance caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural terms users say ('CORS', 'cross-origin', 'origin', 'credentials') but omits common variations like 'Access-Control-Allow-Origin'/'ACAO' from the description itself; good but not comprehensive.

4 / 5

Distinctiveness Conflict Risk

Carves a clear CORS-exploitation niche with distinct triggers and minimal overlap risk with other web-testing skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.