CtrlK
BlogDocsLog inGet started
Tessl Logo

windows-driver-assessment

Defensive Windows internals and driver exposure assessment for owner-authorized systems and disposable research VMs.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/reverser/windows-internals/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tightly written, well-structured defensive-assessment workflow with explicit validation and a promotion gate; its only gap is the absence of concrete executable commands/tool invocations in an otherwise actionable instruction set.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it never explains what HVCI/VBS, WinDbg, ETW, or Authenticode are — and every line (scope guardrails, five-step workflow, promotion rule) earns its place, matching the lean-and-efficient anchor.

5 / 5

Actionability

As an instruction-only skill it gives concrete, specific artifact lists to collect ("driver path, service name, publisher, Authenticode chain, file version, loaded state, device interface") and explicit steps, but provides no executable commands/tool invocations, leaving a minor gap versus copy-paste-ready guidance.

4 / 5

Workflow Clarity

Five clearly sequenced steps include explicit validation checkpoints — Step 4's pre/post mitigation verification, the negative-control requirement, and the Promotion Rule gate form a feedback loop — satisfying the explicit-validation-with-feedback-loops anchor and avoiding the destructive-skill cap.

5 / 5

Progressive Disclosure

The skill is under 50 lines, needs no external references, and is organized into clearly labeled sections (Scope, Evidence-first workflow, Promotion rule), meeting the simple-skill exception for a top progressive-disclosure score.

5 / 5

Total

19

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states a clear, distinctive niche and a concrete action, but is a single-action description with no explicit "Use when…" trigger and jargon-leaning terms that limit trigger-term quality and completeness.

Suggestions

Add an explicit "Use when…" clause naming concrete trigger phrases (e.g., "Use when assessing Windows kernel/driver exposure, auditing signed drivers, or checking HVCI/VBS blocklist state").

Expand the action list from the single verb "assessment" to 2-3 concrete actions (inventory drivers, verify mitigations, correlate against the vulnerable-driver blocklist) to lift specificity.

Include natural-sounding synonyms users would say (e.g., "driver audit", "check vulnerable drivers") alongside the technical jargon.

DimensionReasoningScore

Specificity

Names the domain ("Windows internals and driver exposure") plus one concrete action ("assessment"), but lists no further concrete actions, matching the 1-2-actions anchor rather than the comprehensive coverage of 5 or the minimal/generic action of 2.

3 / 5

Completeness

The "what" is clear (defensive Windows driver exposure assessment), but there is no explicit "Use when…" clause; the target environment ("for owner-authorized systems and disposable research VMs") only weakly implies when, so completeness is capped at 3 per the missing-trigger guideline.

3 / 5

Trigger Term Quality

Terms like "driver exposure assessment", "owner-authorized", and "disposable research VMs" are relevant but lean technical-jargon; common natural phrasings and synonyms a user would actually say are missing, fitting the some-keywords-but-missing-variations anchor.

3 / 5

Distinctiveness Conflict Risk

The defensive Windows-driver-assessment niche is clearly distinct from most skills, with only minor overlap risk against general reverse-engineering or security-assessment skills, placing it at the mostly-distinct anchor rather than the broad-overlap lower anchors or the minimal-conflict 5.

4 / 5

Total

13

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.