Content
90%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A lean, highly executable technique reference: nearly every line is a runnable command, detection/validation is front-loaded, and the pitfalls section doubles as error-recovery guidance. Weaknesses are minor — the blind-XXE verification step is a stub comment rather than a concrete check, and the inlined XLSX builder makes the single file longer than an overview-first structure would.
Suggestions
Replace the stub "# 3. Check listener for exfiltrated data" with a concrete verification step, e.g. inspecting the python http.server access log and URL-decoding the %file; value from the request line, so the blind-XXE workflow closes its feedback loop.
Add an explicit response-validation cue after each file-read payload (e.g., grep the response for an expected marker like 'root:' before iterating the credential-file loop) so failed reads are caught early.
Move the XLSX package construction into a scripts/ helper (e.g., build_xxe_xlsx.sh) and keep a one-line invocation in SKILL.md to keep the main file a lean overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is almost entirely executable commands; the only prose is a one-line framing sentence ("Exploits XML parsers that process external entity definitions, enabling local file reading, SSRF, or denial of service") and section comments. It assumes Claude's competence, explains no background concepts, and every block teaches a distinct vector — matching the 5 anchor "lean and efficient" rather than 4's "minor instances of over-explanation". | 5 / 5 |
Actionability | Every section is copy-paste-ready curl/bash: detection probes, the /etc/passwd confirm, a credential-file read loop, SOAP payloads with namespace matching, SVG and XLSX upload construction, a served evil.dtd with a python listener for blind OOB, and URL-encoded variants. Specific examples cover all common XXE cases, matching the 5 anchor; the only imperfection is the bare comment "# 3. Check listener for exfiltrated data", which is incomplete guidance rather than a missing executable step. | 5 / 5 |
Workflow Clarity | Sections sequence logically from Detection ("Read /etc/passwd (confirms XXE)" is an explicit validation checkpoint) through escalating vectors, and "Common Pitfalls" acts as error-recovery guidance ("If entity expansion disabled → try parameter entities"). Not 5: the blind-XXE workflow ends at the stub comment "# 3. Check listener for exfiltrated data" with no verification command, and the file-read loop has no explicit check that reflected entity content actually appeared in the response before iterating. | 4 / 5 |
Progressive Disclosure | No bundle files exist, and the body is cleanly sectioned (Detection, Basic, SOAP, Upload, Blind, Content Types, Pitfalls) with each block needed at exploitation time. Not 5: at ~133 lines with the multi-command XLSX package construction inlined, part of that detail would sit more naturally in a scripts/ helper so SKILL.md stays a lean overview — this is the 4 anchor's "minor organization gaps". | 4 / 5 |
Total | 18 / 20 Passed |