CtrlK
BlogDocsLog inGet started
Tessl Logo

web

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API exploitation.

53

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/exploit/web/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-structured, actionable routing overview with concrete detection probes, a clear decision tree, and one-level-deep references to specialized sub-skills. Its main weakness is verbosity in several routing-table rows that could be trimmed without losing routing fidelity.

Suggestions

Tighten the longest routing-table rows (blind-sqli, smuggling, crypto, race-condition) by moving deep technique detail into the corresponding sub-skills and keeping only the routing signal in this overview.

Consider splitting the very large routing table into grouped sections (e.g., injection / auth / API / transport) so the overview is easier to scan.

Add a one-line 'after routing' reminder that the loaded sub-skill's own validation/verification steps must be followed, since this overview intentionally omits them.

DimensionReasoningScore

Conciseness

The body is mostly efficient with no padding about concepts Claude already knows, but several routing-table rows (e.g., blind-sqli, smuggling, crypto) carry long 'Covers'/'When to Load' cells that could be tightened for a routing overview.

3 / 5

Actionability

It provides concrete, copy-paste-ready curl detection probes, explicit load_skill() paths for every sub-skill, and a concrete payload-pacing pivot table; only the <TARGET> placeholders and minor gaps keep it from a 5.

4 / 5

Workflow Clarity

The Decision Flow tree gives a clear, well-sequenced routing procedure and the Payload Pacing rule defines explicit pivot/escalation logic; as a routing skill it does not require destructive-operation validation checkpoints, so the 3-cap does not apply.

4 / 5

Progressive Disclosure

The SKILL.md is a focused overview that points to one-level-deep sub-skills via clearly signaled load_skill() paths with no nested references; the large inline routing table is appropriate for a routing skill, leaving only minor organization gaps.

4 / 5

Total

15

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly communicates the skill's routing role and scope, but it omits an explicit 'Use when...' trigger clause and keeps most natural trigger keywords in metadata rather than the description field. Adding an explicit usage trigger with concrete terms would raise completeness and trigger-term quality.

Suggestions

Append an explicit 'Use when...' clause to the description naming concrete triggers (e.g., 'Use when the user mentions web exploitation, web vulnerabilities, injection, or HTTP/API attacks').

Fold a few high-signal natural keywords (e.g., 'web vulnerability', 'web attack', 'RCE', 'XSS', 'SSRF') from metadata.when_to_use into the description to improve trigger-term coverage.

Consider listing one or two more concrete routing actions or technique examples in the description to lift specificity above the 'names domain + 1-2 actions' band.

DimensionReasoningScore

Specificity

Names the domain ('Web application exploitation') and concrete routing actions ('identify the attack type', 'load the appropriate specialized sub-skill') plus four technique areas, but the actions are routing-oriented rather than a comprehensive list of exploitation capabilities.

3 / 5

Completeness

It clearly answers 'what' (a routing skill that identifies the attack type and directs to sub-skills covering 11 technique areas) but lacks an explicit 'Use when...' trigger clause, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

The description includes some relevant natural terms ('web-based attacks', 'injection', 'file access', 'authentication', 'API exploitation') but misses common variations and synonyms; the comprehensive keyword list lives in metadata.when_to_use rather than the description itself.

3 / 5

Distinctiveness Conflict Risk

It is positioned as 'the primary category skill' / 'routing skill' distinct from its specialized sub-skills, giving it a clear niche with only minor overlap risk against the sub-skills it routes to.

4 / 5

Total

13

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.