CtrlK
BlogDocsLog inGet started
Tessl Logo

xxe

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/analyst/xxe/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured playbook that excels at conciseness and avoids over-explanation, but it is more of a checklist than an executable guide: it lacks runnable code and an explicitly sequenced workflow with feedback loops for a validation-heavy testing task.

Suggestions

Add a minimal executable payload-snippet or parser-instantiation example (e.g., a ready-to-send HTTP body or a feature-setting call) so actionability reaches 4-5.

Number the steps as an explicit hunt->confirm->validate workflow and add a validate/fix/retry loop, which is expected for batch security testing and would lift workflow_clarity above 3.

Optionally split large payload catalogs into a referenced payloads.md with clear one-level links to push progressive_disclosure to 5.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence: sink names, dangerous defaults, payloads, and validation controls are listed as terse bullets with no padding or explanation of what XML/XXE is.

5 / 5

Actionability

It names concrete parser sinks and payload targets (file:///etc/passwd, internal URL), but provides no executable code or commands to actually instantiate a parser, set features, or fire a payload; guidance stays at the conceptual/pseudocode level.

3 / 5

Workflow Clarity

There is an implied sequence (find sinks -> check dangerous defaults -> send payload -> validate), and a validation section with positive/negative controls, but steps are not explicitly numbered and there is no validate->fix->retry feedback loop despite this being a batch/destructive-adjacent testing task.

3 / 5

Progressive Disclosure

Well-organized into clear sections (sinks, defaults, payloads, validation) with no nested references and no bundle files to over-organize; under the simple-skill guidance this is good structure, though it could point to payload reference files for deeper coverage.

4 / 5

Total

15

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description for a narrow offensive-security niche, with good distinctiveness and concrete actions. Its main weakness is the missing explicit 'Use when...' trigger clause in the description field, which caps completeness.

Suggestions

Add an explicit 'Use when ...' trigger clause to the description (e.g., 'Use when auditing XML parsers for entity expansion, file read, or SSRF flaws'), so completeness can reach 4-5 without relying on metadata.

Surface a few more natural user-facing synonyms in the description itself (e.g., 'XML injection', 'billion laughs', '.xml') to lift trigger_term_quality to 5.

DimensionReasoningScore

Specificity

Names the domain (XXE) and lists several concrete actions ('Hunt XML External Entity flaws in parsers', 'validate file read / SSRF impact', 'strict negative controls'), though payload building and the validation framing could be more granular.

4 / 5

Completeness

The 'what' is clearly stated (hunt and validate XXE flaws), but there is no explicit 'Use when...' clause in the description itself; trigger guidance lives only in metadata, so completeness caps at 3 per the rubric.

3 / 5

Trigger Term Quality

The metadata.when_to_use provides strong natural terms ('xxe', 'xml external entity', 'parser', 'file read', 'ssrf', 'cwe-611', 'blind oob'), but the description itself lacks the common synonyms/extensions a user might verbalize.

4 / 5

Distinctiveness Conflict Risk

The XXE niche is highly specific with distinct triggers (CWE-611, DTD, parameter entity, blind OOB), making conflict with unrelated skills minimal.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.