CtrlK
BlogDocsLog inGet started
Tessl Logo

redteam-mindset

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again whenever feeling stuck or considering "stopping" on a defended target. The single most important skill to load when scope is "external red team" not "bug bounty / WAPT".

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/redteam-mindset/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An operationally rich, highly actionable red-team discipline skill with strong checklists and validation. Its weaknesses are token-efficiency (rhetorical repetition) and progressive disclosure (a 28KB monolith with no reference-file split despite clearly separable content).

Suggestions

Split bulk reference material into one-level-deep bundled files (e.g. references/cadence-checklist.md, references/cve-target-list.md, references/blocker-decision-trees.md) and summarize them in SKILL.md with clear links, instead of inlining ~28KB into one file.

Trim rhetorical padding ('read this twice', 'THIS is the core', repeated bold imperatives) and the recurring red-team-vs-WAPT contrast that is already stated in the one-line summary and correction #3.

For the blocker decision trees (captcha/WAF/rate-limit), include the exact commands or tool invocations for each step rather than structured prose, to push actionability from mostly-executable to copy-paste-ready.

DimensionReasoningScore

Conciseness

Dense operational content with real specifics, but noticeable rhetorical padding ('read this twice', 'THIS is the core') and repetition of the red-team-vs-WAPT distinction across multiple sections that could be tightened without losing meaning.

3 / 5

Actionability

Highly concrete guidance — exact probe/path lists, named CVE families, specific decision trees, executable commands ('brew install jadx'), and a concrete JSONL journal format — with minor gaps where decision trees remain structured prose rather than exact commands.

4 / 5

Workflow Clarity

Sequenced mindset corrections (#1-#9) plus pre/during/post-engagement checklists and a 30-minute self-check feedback loop, with explicit validation (2+ technique confirmation, reproducibility) appropriate for this destructive-testing skill.

4 / 5

Progressive Disclosure

No bundle files exist (references/scripts/assets all absent) and the 28KB body inlines bulk reference material — CVE lists, the full cadence checklist, Pattern Library details — into a single monolithic file rather than splitting into one-level-deep reference files.

2 / 5

Total

13

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with clear what/when structure, natural trigger terms, and explicit differentiation from sibling skills. The main gap is that it describes mindset corrections narratively rather than enumerating concrete capabilities.

DimensionReasoningScore

Specificity

Names the domain ('red-team operator discipline') and concrete specifics ('findings missed', 'incorrectly retracted', 'considering stopping'), but does not enumerate distinct actionable capabilities — it describes mindset corrections rather than a comprehensive list of concrete actions.

3 / 5

Completeness

Explicitly answers both 'what' (mindset corrections separating offensive testing from WAPT) and 'when' ('Use at the START of any red-team engagement and again whenever feeling stuck or considering stopping on a defended target') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural keywords a user would say ('red team', 'red-team engagement', 'stuck', 'stopping', 'external red team', 'bug bounty', 'WAPT') with the key red-team-vs-WAPT contrast present, though a few natural variants ('adversary emulation', 'assume breach') are absent.

4 / 5

Distinctiveness Conflict Risk

Clear niche with explicit differentiation — it actively contrasts red-team scope against bug-bounty and WAPT scope, giving it distinct triggers and minimal conflict risk with sibling skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.