CtrlK
BlogDocsLog inGet started
Tessl Logo

iot-overview

Use when the engagement target is IoT, embedded Linux, RTOS, or any device reachable via UART/JTAG/SWD or by extracting its firmware. Covers firmware acquisition, binwalk extraction, filesystem mounting, default-credential hunting, bootloader attacks, wireless protocol sidebands (BLE, Zigbee, Z-Wave, LoRaWAN, sub-GHz).

66

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-structured operator catalog that assumes Claude's competence, but it relies on external playbook paths for actionability and omits validation checkpoints for destructive hardware operations.

Suggestions

Add inline executable commands or a minimal worked example for the highest-value steps (e.g. SPI flash read with ch341a, squashfs mount) so the body is actionable without the external playbooks.

Insert explicit validation/verification checkpoints after destructive steps (chip-off, /dev/mem writes, MTD writes) — e.g. verify firmware integrity hash before extraction, confirm mount succeeds before triage.

Either bundle the referenced playbooks under references/ or note that they are sibling skills, so the cross-references resolve to real progressive-disclosure targets.

DimensionReasoningScore

Conciseness

Lean catalog format with no padding or explanation of concepts Claude already knows; every line carries operator-relevant signal.

5 / 5

Actionability

Mostly points to external playbook paths rather than giving inline executable steps; only one concrete command ('binwalk -eM <fw.bin>') appears, leaving the operator with high-level pointers.

3 / 5

Workflow Clarity

A clear six-step sequence exists, but destructive/batch operations (eMMC chip-off, /dev/mem and MTD writes, secure-boot bypass) lack validation checkpoints, capping this at 3 per the rubric.

3 / 5

Progressive Disclosure

Well-organized sections with a playbook table and one-level-deep pointers, but no bundle files exist and the referenced skill paths are external rather than bundled references.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, well-targeted description that concretely states both what the skill covers and when to invoke it, with strong domain-specific triggers. Only minor room to broaden natural-language synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'firmware acquisition, binwalk extraction, filesystem mounting, default-credential hunting, bootloader attacks, wireless protocol sidebands' — giving comprehensive coverage of the domain.

5 / 5

Completeness

Explicitly answers 'when' with 'Use when the engagement target is IoT...' and 'what' with 'Covers firmware acquisition...' — both halves are concrete and explicit.

5 / 5

Trigger Term Quality

Strong natural terms (IoT, embedded Linux, RTOS, UART, JTAG, SWD, firmware) but leans on technical jargon and omits common layperson synonyms a user might say.

4 / 5

Distinctiveness Conflict Risk

A clearly bounded niche (IoT/embedded hardware + wireless sidebands) with distinct trigger language and minimal overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.