CtrlK
BlogDocsLog inGet started
Tessl Logo

anti-reversing-techniques

AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.

36

Quality

33%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-anti-reversing-techniques/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is essentially a safety policy document: the authorization gate is thoughtfully designed, but the skill delivers no actual anti-reversing technique content, deferring everything to a playbook file that is missing from the bundle. Structure and scoping sections are solid; substance and reference integrity are the failures.

Suggestions

Add concrete, executable guidance for the core task — e.g., specific tool invocations (debugger detection checks, common anti-debug flags, unpacking commands) or copy-paste snippets for the most common anti-reversing scenarios — instead of 'choose safe analysis methods'.

Fix the broken reference: either include the referenced 'resources/implementation-playbook.md' in the bundle (in the expected references/ directory, with the path corrected) or remove the pointer so navigation does not dead-end; also deduplicate the pointer, which appears twice.

Merge the two overlapping authorization blocks into one gate section to remove the near-duplicated boilerplate, freeing token budget for actual technical content.

DimensionReasoningScore

Conciseness

The body is short and sectioned, but the authorization material is stated twice in near-duplicate (the 'Mandatory confirmation gate' block and the second 'AUTHORIZED USE ONLY' block repeat the same checks), and it lectures on legal concepts Claude already knows ('may violate laws (CFAA, DMCA anti-circumvention, etc.)'). This matches anchor 3 (mostly efficient but includes unnecessary explanation or could be tightened); it is not 2 because there is no padding beyond the safety boilerplate and no basic-concept tutoring.

3 / 5

Actionability

For the skill's core purpose there is no concrete guidance at all — 'Identify protection mechanisms and choose safe analysis methods' is a high-level hint with no commands, tools, or technique names, and every detail is deferred to a playbook file that does not exist. The only concrete instruction is the confirmation-gate procedure, which keeps this above anchor 1 ('entirely vague... only describes rather than instructs') at anchor 2 (minimal concrete guidance, missing the specific steps to execute).

2 / 5

Workflow Clarity

A rough 4-step sequence exists ('Confirm written authorization... Identify protection mechanisms... Document findings... Provide defensive recommendations') and the confirmation gate is an explicit checkpoint before risky operations. However, the analysis steps themselves are vague with no validation of findings or error-recovery guidance, matching anchor 3 (steps listed but validation gaps; sequence present but checkpoints missing or implicit) rather than 4.

3 / 5

Progressive Disclosure

The body is short and cleanly sectioned, but its only external reference — 'resources/implementation-playbook.md', mentioned twice (inline at the end of Safety and again in the Resources section) — does not exist in the bundle (no references/, scripts/, assets/, or resources/ directory), so navigation dead-ends. This sits between anchor 2 (references broken/buried) and anchor 4 (good structure, references mostly clear): the structure is genuinely good but the single reference is dangling and duplicated, landing at 3.

3 / 5

Total

11

/

20

Passed

Description

25%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a truncated safety warning, not a capability description: it says nothing about what the skill does, when to use it, or which natural trigger terms apply. It reads as a broken copy of the body's authorization boilerplate rather than a functional skill description.

Suggestions

State the concrete capabilities in the description, e.g.: 'Detects and handles anti-debugging, anti-VM, and obfuscation techniques in protected binaries (anti-reversing), including unpacking and deobfuscation workflows.'

Add an explicit trigger clause: 'Use when performing authorized reverse engineering, malware analysis, CTF challenges, or analyzing anti-debugging/obfuscation techniques for defense.'

Remove the truncated gate text ('Before proceeding with any bypass or analysis: > 1.') and any duplicated warning language — keep authorization caveats short and put the full gate in the body.

DimensionReasoningScore

Specificity

The description names a domain ("dual-use security techniques", "any bypass or analysis") but states zero concrete actions — it never says what the skill actually does (e.g., detect anti-debugging checks, unpack binaries, deobfuscate). It is cut off mid-sentence ("Before proceeding with any bypass or analysis: > 1."), landing between anchor 1 (no concrete actions) and anchor 2 (domain named, actions minimal) — it earns 2 only because a domain is named.

2 / 5

Completeness

It offers only a vague 'what' ("contains dual-use security techniques") and no 'when' clause at all, matching anchor 2 (vague what, no when); the per-guideline cap of 3 for missing a 'Use when...' clause is not even reached because the 'what' is also extremely vague and the text is truncated. It is not a 1 only because a (vague) domain statement is present.

2 / 5

Trigger Term Quality

Only "bypass" and the generic phrase "security techniques" are present; the natural terms a user would say for this skill — reverse engineering, anti-debugging, obfuscation, unpacking, CTF, malware analysis — are all absent. This matches anchor 2 (one or two generic keywords, missing the natural phrases users say), not 3, because even the domain's common synonyms are missing.

2 / 5

Distinctiveness Conflict Risk

"Dual-use security techniques" is very broad and would overlap with virtually any offensive-security, pentest, or malware-analysis skill, matching anchor 2 (very broad; high overlap risk). The skill name's niche (anti-reversing) never appears in the description, so it cannot earn 3 ('somewhat specific').

2 / 5

Total

8

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.