CtrlK
BlogDocsLog inGet started
Tessl Logo

deep-analysis

Depth-first RE investigation loop for a single binary or function cluster: decompile→rename→retype→comment→re-read, with context-rot guards and on-task checks. Use when triage has already identified the interesting area and the goal is full understanding: what does function X do, identify cryptographic primitives, locate C2 protocol, recover data structures. Triggers on: 'deep analysis', 'understand function', 'recover struct', 'crypto identification', 'C2 protocol', 'reverse this binary fully', 'what does this function do'.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong operational skill: the decompile→rename→retype→comment→re-read loop is fully executable, guarded by an on-task check cadence, context-rot rules, and a completion gate. The only weaknesses are mild — some content restates knowledge Claude already has (crypto constants), and reference material is kept fully inline in a long single file rather than split out.

Suggestions

Trim or compress the crypto-constants table to only the non-obvious entries (e.g., keep TEA Δ and RC5/RC6 magic; drop MD5/SHA-256 init and AES S-box start, which Claude already knows) to lift conciseness to lean.

Move the per-question strategies (§4) and/or the crypto-constants reference into a references/ file (e.g., references/strategies.md) with well-signaled links from SKILL.md, keeping the main file as a tight overview of the core loop.

Cut hortatory asides like "Read the full output before touching anything" and "Correct types catch bugs in decompiler reasoning" — the imperative steps already imply them.

DimensionReasoningScore

Conciseness

The body is directive and free of concept re-teaching, but parts restate what Claude already knows — the crypto-constants table (AES S-box, MD5/SHA-256 init values, ChaCha sigma) and lines like "Read the full output before touching anything" and "Correct types catch bugs in decompiler reasoning" add tokens without new information. This fits 'Efficient; minor instances of over-explanation that could be trimmed' rather than 5, where every token would earn its place.

4 / 5

Actionability

Guidance is fully executable throughout: parameterized tool calls (ghidra_batch_rename with a concrete renames dict, ghidra_retype with symbol/type syntax, ghidra_set_comment with an address), a runnable capa JSON-filter one-liner, and a complete pefile entropy-scanning script. Per the anchor, copy-paste ready commands cover the common cases (crypto ID, C2 discovery, struct recovery).

5 / 5

Workflow Clarity

The core loop (2a–2e) is explicitly sequenced with a repeat condition ("Repeat 2a–2e until the function's purpose is unambiguous"), backed by a timed on-task check (§3, every 3–5 tool calls with four explicit questions), blocked-status escalation in §6, and a completion-gate checklist in §7. These are explicit validation checkpoints and feedback loops, matching the top anchor rather than 4 where checkpoints would only be mostly present.

5 / 5

Progressive Disclosure

The single file is well-sectioned (numbered phases, per-question strategies, tools table) with no nested references, and no bundle files exist so nothing is mis-filed. However, ~225 lines are entirely inline with no split-out of reference material (crypto constants table, per-question strategy details), so it fits 'Good structure; most content appropriately placed; minor organization gaps' rather than the 5 anchor's clean overview-plus-externalized-references shape.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete capability enumeration, an explicit 'Use when...' clause with concrete goal states, natural quoted trigger phrases, and a clear boundary against the related triage skill. It scores at the top of every dimension with no vagueness, over-claims, or voice violations.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions ("decompile→rename→retype→comment→re-read", "context-rot guards", "on-task checks") with comprehensive coverage of the deep-analysis workflow. It matches the anchor 'Lists multiple specific concrete actions; comprehensive coverage' rather than 4, since there are no meaningful gaps in coverage of the skill's capabilities; third-person voice is used so no penalty applies.

5 / 5

Completeness

Both what ("Depth-first RE investigation loop... decompile→rename→retype→comment→re-read") and when ("Use when triage has already identified the interesting area and the goal is full understanding: what does function X do, identify cryptographic primitives, locate C2 protocol, recover data structures") are explicitly answered with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Explicit quoted trigger phrases cover natural user language with synonyms: "'deep analysis', 'understand function', 'recover struct', 'crypto identification', 'C2 protocol', 'reverse this binary fully', 'what does this function do". This matches the anchor for comprehensive natural-term coverage; nothing a user would naturally say is missing.

5 / 5

Distinctiveness Conflict Risk

The description carves a clear niche (depth-first full understanding after triage has identified the area) and explicitly bounds it against the sibling breadth-first triage workflow, with distinct trigger terms, giving minimal conflict risk per the top anchor.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.