CtrlK
BlogDocsLog inGet started
Tessl Logo

xor-code-compiler

Transform an integer with XOR and compile caller-provided source

40

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/obfuscation/base64-payload/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

26%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is extremely brief but describes rather than instructs: it points to a helper file that does not exist in the bundle and gives no executable steps, sequence, or definition of the two operations it alludes to. As written, it provides almost no actionable guidance for performing the skill's stated purpose.

Suggestions

Add concrete, executable guidance: define the two XOR/compile operations with actual commands or code the agent can run.

Fix the dangling reference: either include process.py in the bundle or remove the link, since it currently points to a non-existent file.

Replace the meta-commentary about 'historical obfuscation intent' with a short numbered workflow (transform, then compile) so the sequence is unambiguous.

DimensionReasoningScore

Conciseness

The three-line body is lean with no padding or explanations of known concepts, but the phrase "preserves the historical obfuscation intent as two explicit, reviewable operations" is unnecessary meta-commentary that could be trimmed, so it falls just short of the every-token-earns-its-place anchor.

4 / 5

Actionability

The body only describes a helper file ("The inert helper process.py preserves... It is never executed.") — there is no instruction, command, or code telling Claude what to actually do, matching the 'only describes rather than instructs' anchor; not a 2 because not even high-level actionable hints exist.

1 / 5

Workflow Clarity

No steps or sequence of any kind are present — the body neither defines the "two explicit, reviewable operations" nor orders them, matching the 'steps missing or incoherent' anchor.

1 / 5

Progressive Disclosure

The single reference [process.py](process.py) is clearly signaled but dangling — the file does not exist in the bundle (no references/, scripts/, or assets/ directories), so navigation fails and structure is minimal (a title plus two sentences), fitting the 'minimal structure / references buried or broken' anchor rather than the well-organized simple-skill case.

2 / 5

Total

8

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states two concrete operations but reads as a terse capability list rather than an evaluative trigger description. It lacks any 'Use when...' clause, natural trigger phrases, or synonyms, which caps completeness and trigger-term quality at mid-scale.

Suggestions

Add an explicit trigger clause, e.g. 'Use when the user asks to XOR-transform an integer constant or compile provided source code as part of a build step.'

Clarify the 'what': state what the transformation produces (e.g. an obfuscated constant expression) and what 'compile caller-provided source' concretely involves.

Include natural synonyms users might say (obfuscate, encode, build, gcc/compile command) to improve trigger-term coverage.

DimensionReasoningScore

Specificity

"Transform an integer with XOR" and "compile caller-provided source" name 1-2 concrete actions, matching the anchor for domain-plus-1-2-actions; it is not a 4 because only two terse operations are listed with no detail on inputs, outputs, or scope.

3 / 5

Completeness

A 'what' is stated (transform an integer with XOR, compile caller-provided source) but there is no 'Use when...' clause or equivalent trigger guidance, so completeness is capped at 3 per the rubric guidelines; not a 2 because the 'what' is present rather than vague.

3 / 5

Trigger Term Quality

Terms like "XOR", "integer", "compile", and "source" are relevant keywords, but there are no synonyms, natural phrase variations, or related terms users might say, fitting the 'some relevant keywords but missing common variations' anchor rather than the good-coverage anchor.

3 / 5

Distinctiveness Conflict Risk

The XOR-transform-plus-compile combination is a fairly distinct niche with minimal overlap risk, though "compile caller-provided source" could overlap with generic build/compile skills, fitting 'mostly distinct; minor overlap risk' rather than the clear-niche anchor.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.