CtrlK
BlogDocsLog inGet started
Tessl Logo

imds-pivot

Pivot from SSRF or RCE to cloud Instance Metadata Service (IMDS) — extract IAM role creds, instance identity, user-data secrets.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly actionable reference with executable commands across all major clouds and strong organization; the only gap is the absence of an explicit validate/retry feedback loop for extraction failures.

DimensionReasoningScore

Conciseness

Lean throughout: endpoint tables, copy-paste curl blocks, and compact OPSEC/CVSS/defender notes that assume Claude's competence with no padding or beginner-level concept explanations.

5 / 5

Actionability

Fully executable curl/jq commands for AWS IMDSv1 and IMDSv2, GCP service-account tokens, and Azure managed identities — copy-paste ready and covering the common cases per provider.

5 / 5

Workflow Clarity

A clear numbered sequence (identify provider → extract creds → user-data → promote) with a verification checkpoint ('aws sts get-caller-identity') and a boundary/reality-check in section 7, but no explicit error-recovery feedback loop for failed extraction.

4 / 5

Progressive Disclosure

Well-organized into sections 1–8 plus OPSEC/CVSS/Defender/Exemplars, with one-level-deep cross-skill pointers ('Pivot to aws-iam-enum/SKILL.md', 'see SSRF skill catalog') and no nested references; no bundle files are needed.

5 / 5

Total

19

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description with strong distinctiveness, but it lacks an explicit 'Use when...' trigger clause and omits cloud-name synonyms from the description text, capping completeness and trigger-term quality.

Suggestions

Add an explicit trigger clause, e.g. 'Use when you have SSRF, server-side fetch, or RCE on a cloud instance and need to extract metadata credentials.'

Include cloud-name keywords (AWS, GCP, Azure) and the 169.254.169.254 address in the description so users searching by provider find it.

Consider noting instance-identity and user-data as separate trigger phrases to broaden natural-term coverage.

DimensionReasoningScore

Specificity

Names the pivot plus three concrete extraction targets ('IAM role creds, instance identity, user-data secrets') — several specific actions, but no per-cloud enumeration, leaving minor coverage gaps.

4 / 5

Completeness

The 'what' is explicit ('Pivot from SSRF or RCE ... extract ...'), but there is no 'Use when...' clause; the 'when' is only implied through the pivot precondition, so per the missing-trigger-guidance cap it stays at 3.

3 / 5

Trigger Term Quality

Includes natural pentest terms a user would say ('SSRF', 'RCE', 'IMDS', 'IAM role creds', 'user-data') with acronym expansion, but omits cloud-name synonyms (aws/gcp/azure) and the 169.254 IP from the description itself.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (IMDS pivot from SSRF/RCE) with highly specific triggers, making conflict with unrelated skills minimal.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.