CtrlK
BlogDocsLog inGet started
Tessl Logo

web-cookie-audit

Cookie-conditional sink discovery — bisect required cookies per sink, session-write timeline for race-condition challenges.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/web-recon/cookie-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, highly actionable recon workflow with explicit sequencing, validation gates, and feedback loops, appropriately structured as a single self-contained file. The only minor weakness is a touch of motivational framing that lightly dents conciseness.

DimensionReasoningScore

Conciseness

Efficient procedural prose with compact tables and a copy-paste handoff format; the brief sink definition and motivational opening line are minor over-explanation that could be trimmed, keeping it just below the lean anchor of 5.

4 / 5

Actionability

Fully actionable for a recon skill: concrete probe matrix (NO cookies vs FULL jar, drop-one bisect), exact output table schemas with a worked example, and a copy-paste 'Required session state' handoff line — specific guidance covers the common cases.

5 / 5

Workflow Clarity

Clear 1→2→3→4→4a→5 sequence with explicit validation/feedback gates (bisect re-probe loop, and 'exploit MUST flag handoff back as recon incomplete' completeness checks), matching the anchor for explicit validation steps and feedback loops.

5 / 5

Progressive Disclosure

Under 50 lines with no external references needed (no references/scripts/assets bundle exists) and well-organized sections; per the rubric's simple-skill guidance this earns 5 on well-organized structure alone.

5 / 5

Total

19

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and highly distinctive with good trigger keywords, but it omits an explicit 'Use when...' clause, which caps its completeness. Adding a trigger phrase would likely raise completeness and trigger_term_quality.

Suggestions

Append an explicit 'Use when...' trigger clause (e.g., 'Use when auditing which session cookies gate a sink, or when a challenge tag includes race_condition / toctou / session-mutation recon') to raise completeness above 3.

Add common natural synonyms users might say ('cookie audit', 'gating cookies', 'session-mutation recon') to broaden trigger_term_quality.

Consider listing one more concrete action (e.g., 'document sink preconditions table') to push specificity toward 4-5.

DimensionReasoningScore

Specificity

Names the domain ('Cookie-conditional sink discovery') and two concrete actions ('bisect required cookies per sink', 'session-write timeline for race-condition challenges'), matching the anchor for 1-2 concrete actions without comprehensive coverage.

3 / 5

Completeness

The 'what' is clear, but there is no explicit 'Use when...' trigger clause in the description field — only weakly implied 'when' via 'race-condition challenges', so per the rubric guideline completeness is capped at 3.

3 / 5

Trigger Term Quality

Good natural keyword coverage for the security-recon audience ('cookie', 'sink', 'session', 'race-condition', 'bisect'); a few common phrasings like 'cookie audit' or 'gating cookies' are absent, placing it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

A clear, narrow niche (cookie-gated sink discovery and session-write race-condition recon) with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.