CtrlK
BlogDocsLog inGet started
Tessl Logo

redos

Hunt ReDoS (CWE-1333, Catastrophic Backtracking) — identify regexes with nested quantifiers or overlapping alternation that cause super-linear matching time, trace tainted input paths to regex sinks, demonstrate timing PoC, and validate with response-time delta. Covers PCRE/RE2/V8/Python re engine differences. Triggers on: 'ReDoS', 'regex denial', 'catastrophic backtracking', 'redos', 'regex complexity', 'nested quantifiers', 'regex amplification', 'CWE-1333'.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced hunting playbook: concrete per-language commands, canonical catastrophic-pattern forms, an executable timing PoC, and an explicit validation contract with negative controls. Its only weaknesses are minor verbosity (intro re-explaining ReDoS basics, a rough AST snippet) and inlining reference-grade tables (engine matrix, CVSS) that could live in a references/ file.

Suggestions

Trim the 3-line intro paragraph that restates what ReDoS is — Claude already knows the O(2^n)/O(n^2) mechanics, and the engine table in section 1 conveys the practical stakes.

Clean up the quick pattern scanner snippet: remove the unused imports (subprocess, json, os, sys) and the exploratory comment, leaving a tidy AST-based regex-literal extractor.

Move the engine-specific notes table, section 7 engine notes, and the CVSS table into a references/ file (e.g., references/engines.md), keeping SKILL.md as a lean overview that points to it — this would tighten both conciseness and progressive disclosure.

DimensionReasoningScore

Conciseness

The body is dense and skill-specific (engine table, grep commands, evil-string construction, CVSS table) with almost no filler, but a few tokens could be trimmed: the 3-line intro restates what ReDoS is ("Regular Expression Denial of Service exploits O(2^n) or O(n^2) matching time..."), and the AST scanner snippet carries unused imports ("import subprocess, json, os, sys") and an exploratory comment. This fits the 4 anchor (efficient, minor over-explanation that could be trimmed) rather than 5, where every token would earn its place.

4 / 5

Actionability

Fully executable guidance throughout: per-language grep commands (e.g., "grep -rn 're\.match\|re\.search...' /workspace/src"), a copy-paste timing PoC script with scaling loop and confirmation halt, a ready one-liner test ("python3 -c \"import re,time; t=time.time(); re.match(r'(a+)+$','a'*25+'b')...""), a semgrep config, and concrete validate_finding success/negative patterns. Matches the 5 anchor (copy-paste ready, covers common cases) rather than 4, which allows minor gaps.

5 / 5

Workflow Clarity

A clear 9-step sequence from engine triage through source grep, pattern recognition, taint heuristics, PoC construction, validation, severity, and reporting. Validation is explicit: section 6 defines a finding contract with success_patterns, a negative_command control, and a 3-item minimum-bar checklist, and the PoC script embeds a feedback loop ("Scale the pump length until response time > 3x normal" with a halt "to avoid DoS"). Matches the 5 anchor (explicit validation steps, feedback loops, checklist); the destructive-operation cap at 3 does not apply since validation/negative controls are present.

5 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), and the single SKILL.md is well-organized into numbered sections with clear headers, matching the 4 anchor ('good structure; most content is appropriately placed'). It falls short of 5 because some reference-grade material — the 8-row engine table, engine-specific notes, and the CVSS table — is inlined where a references/ split would keep the overview leaner; it is well above the 3 anchor's 'content that should be separate is inline' since the core playbook reads fine as one file.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: it enumerates the full workflow from pattern identification through taint tracing to PoC and validation, states engine scope, and closes with an explicit trigger clause rich in synonyms. Both 'what' and 'when' are answered concretely with no fluff or over-claims.

DimensionReasoningScore

Specificity

Quotes multiple specific concrete actions: "identify regexes with nested quantifiers or overlapping alternation that cause super-linear matching time", "trace tainted input paths to regex sinks", "demonstrate timing PoC", and "validate with response-time delta", plus explicit engine coverage. This matches the 5 anchor (multiple specific concrete actions, comprehensive); it is well above the 4 anchor's 'minor gaps in coverage' since the full hunt-to-validate pipeline is enumerated.

5 / 5

Completeness

The 'what' is explicit and concrete (hunt, identify, trace, demonstrate, validate) and the 'when' is explicit via "Triggers on: 'ReDoS', 'regex denial', ..." — equivalent to a 'Use when...' clause with concrete trigger phrases. Clearly matches the 5 anchor; the 3-anchor cap for a missing trigger clause does not apply.

5 / 5

Trigger Term Quality

Trigger terms include 'ReDoS', 'regex denial', 'catastrophic backtracking', 'redos', 'regex complexity', 'nested quantifiers', 'regex amplification', and 'CWE-1333' — natural phrases with synonyms (ReDoS/redos, regex denial/catastrophic backtracking) and the canonical CWE identifier. Comprehensive per the 5 anchor; the 4 anchor's 'a few natural terms missing' doesn't apply.

5 / 5

Distinctiveness Conflict Risk

A clear niche (ReDoS/CWE-1333 specifically) with distinct trigger terms that no adjacent skill (general regex work, other DoS classes) would naturally claim. Matches the 5 anchor's 'clear niche with distinct triggers; minimal conflict risk'; it is far more specific than the 4 anchor's 'minor overlap risk with closely related skills'.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.