CtrlK
BlogDocsLog inGet started
Tessl Logo

mid-engagement-ir-detection

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external attacker locked multiple new accounts during a single test session. Use when (a) running ANY active engagement against a monitored target, (b) a previously-confirmed finding stops reproducing, (c) baseline timing shifts unexpectedly, or (d) you notice response patterns changing during testing.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/mid-engagement-ir-detection/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced methodology with strong validation checkpoints, weakened by inline bulk (finding templates, scripts) that would benefit from reference files and by some redundant cross-referencing sections.

Suggestions

Move the three full finding templates and the bash/python watcher scripts into separate reference files under references/ and link to them one level deep to improve progressive disclosure.

Collapse the duplicate 'Bridge to neighboring skills' and 'Related Skills & Chains' sections into a single concise cross-reference list to cut redundancy.

Replace placeholder values in the pre-test fingerprint snippet with concrete example values or a clearly parameterized function signature so the code is executable as written.

DimensionReasoningScore

Conciseness

Mostly efficient and assumes Claude's competence (no basic concept explanations), but noticeable padding from two overlapping neighbor-skill sections ('Bridge to neighboring skills' and 'Related Skills & Chains') and a sales-oriented 'Why this is a finding' section that restate the core insight.

3 / 5

Actionability

Provides copy-paste-ready finding templates, JSONL schemas, and a bash/python watcher, but the pre-test fingerprint snippet uses placeholders like '<measure>', '<capture set>', '<count from o365_attempts.json>' rather than fully executable code.

4 / 5

Workflow Clarity

Clear before/during/after sequence with explicit validation checkpoints (math-check for lockouts, WAF-evasion retry) and a 5-step 'single signal recanted' checklist with feedback loops, so the batch-operation cap does not apply.

5 / 5

Progressive Disclosure

Well-organized into clear sections but at ~345 lines it exceeds the simple-skill exception, and bulky content that could live in separate reference files (three full finding templates, the tooling scripts) is fully inlined with no one-level-deep references.

3 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with explicit what-and-when triggers and a clear niche; the only deduction is a second-person voice usage that the rubric penalizes on specificity.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('detecting client SOC patches, attacker activity, and security-state changes', 'converting those observations into deliverable findings') for comprehensive coverage, but penalized one point for second-person voice ('you notice response patterns changing').

4 / 5

Completeness

Explicitly answers both what (detect/convert mid-engagement observations into findings) and when via the enumerated 'Use when (a)-(d)' concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural operator-facing terms like 'red-team engagement', 'finding stops reproducing', 'baseline timing shifts', and 'response patterns changing' give good coverage, though a few common phrasings are absent.

4 / 5

Distinctiveness Conflict Risk

Narrow, well-defined niche (mid-engagement IR detection on monitored red-team targets) with triggers unlikely to fire for unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.