CtrlK
BlogDocsLog inGet started
Tessl Logo

security

攻防秘典索引。渗透测试、代码审计、红队攻击、蓝队防御、威胁情报、漏洞研究。安全研究全授权,零废话直出技术细节+PoC。当魔尊提到安全、渗透、攻防、红队、蓝队、漏洞时路由到此。

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./templates/skills/domains/security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a compact, clearly navigable index with a sensible one-level progressive-disclosure design, but it is undermined by broken references (all six target files are absent from the bundle), decorative persona framing that pads the token budget, redundant routing sections, and a complete absence of validation/verification checkpoints for risky security operations. As written, following any instruction in this skill leads to a dead end.

Suggestions

Ship the six referenced manuals (pentest.md, code-audit.md, red-team.md, blue-team.md, threat-intel.md, vuln-research.md) in the bundle, or remove/collapse the links until they exist — the entire skill currently routes to nothing.

Merge the '快速选择' section into the '秘典矩阵' table to eliminate the duplicated routing rows and persona labels, and strip decorative framing ('三脉道统', '化身') that adds tokens without instruction.

Add validation checkpoints appropriate to the domain — e.g. confirm engagement scope/authorization before offensive steps, and verify findings (reproduced PoC, corroborated detection) before reporting — to lift workflow clarity above 3.

Resolve the dangling '紫霄脉' reference in '攻防协同', which names a lineage that appears nowhere else in the matrix.

DimensionReasoningScore

Conciseness

The body is short and table-based, but a noticeable share of tokens is spent on decorative persona framing — "三脉道统", "秘典矩阵", per-row "化身" labels, and emoji sigils — and the "快速选择" section substantially repeats the 秘典矩阵 table (e.g. 'Web/API 渗透 → pentest.md — 🗡 破阵化身' appears in both). These are unnecessary explanations/redundancy that could be trimmed, matching 'mostly efficient but includes some unnecessary explanation'.

3 / 5

Actionability

The routing guidance is concrete (each task maps to a named file: 'Web/API 渗透 → pentest.md', '检测规则 → blue-team.md'), but it is incomplete: the body contains no executable commands, no code, no concrete technique steps, and — critically — none of the six referenced files (pentest.md, code-audit.md, red-team.md, blue-team.md, threat-intel.md, vuln-research.md) exist in the bundle, so every pointer dead-ends. This fits 'some concrete guidance but incomplete; missing key details'.

3 / 5

Workflow Clarity

The kill-chain and defense-chain diagrams (侦察 → 武器化 → 投递 → 利用 → 安装 → C2 → 行动; 预防 → 检测 → 响应 → 恢复) present rough conceptual sequences, and the routing flow (pick task → open the matching manual) is a coherent single action, but there are no validation checkpoints anywhere and no error-recovery guidance — e.g. nothing on verifying scope/authorization before offensive actions or validating findings before reporting. That matches 'steps listed but validation gaps; checkpoints missing or implicit'.

3 / 5

Progressive Disclosure

The design intent is good — a lean one-level index pointing to six per-domain manuals — but scoring against the actual bundle structure, the referenced files do not exist: there is no references/, scripts/, or assets/ directory, so all six links ([pentest](pentest.md), [code-audit](code-audit.md), [red-team](red-team.md), [blue-team](blue-team.md), [threat-intel](threat-intel.md), [vuln-research](vuln-research.md)) are broken. A well-signaled index whose every target is missing leaves the skill with minimal effective structure, matching 'minimal structure; references…' at the low anchor rather than a 3, where references at least resolve to real content.

2 / 5

Total

11

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-constructed, concise description with an explicit trigger clause and natural Chinese-language trigger terms covering a distinct security niche. Its weaknesses are stylistic labeling of the 'what' ('攻防秘典索引'), an unverifiable blanket-authorization over-claim, and a few missing common synonyms (CTF, exploit, forensics).

Suggestions

Replace the stylistic opener '攻防秘典索引' with a plain functional statement, e.g. '安全攻防知识路由:按任务分发到六份子手册'.

Drop the over-claim '安全研究全授权' from the description — authorization is a runtime property, not a skill capability.

Add missing natural trigger synonyms such as CTF, exploit, 逆向/反编译, 应急响应, 取证 to the '当…提到' clause.

DimensionReasoningScore

Specificity

The description lists six concrete security activity areas ("渗透测试、代码审计、红队攻击、蓝队防御、威胁情报、漏洞研究") plus one explicit action ("直出技术细节+PoC"), giving specific capability coverage with minor gaps — it never states what the skill actually does within each area beyond outputting details/PoC. It is not a 5 because the actions are domain names rather than the multiple concrete verbs of the anchor example, and the blanket-authorization phrase "安全研究全授权" is an over-claim rather than a capability.

4 / 5

Completeness

Both parts are present: the 'what' is the six-domain capability list plus "直出技术细节+PoC", and the 'when' is explicit ("当魔尊提到安全、渗透、攻防、红队、蓝队、漏洞时路由到此"). It falls short of 5 because the 'what' opens with stylistic labeling ("攻防秘典索引") rather than a plain statement of function, leaving the actual behavior (routing to sub-manuals) only implied.

4 / 5

Trigger Term Quality

Trigger terms are natural and well-chosen: "安全、渗透、攻防、红队、蓝队、漏洞" are exactly the words a Chinese-speaking user would say when needing this skill. Not a 5 because common variations users would say — CTF, exploit, 逆向 (reverse engineering), 应急响应 (incident response), 取证 (forensics) — are absent even though the body covers them.

4 / 5

Distinctiveness Conflict Risk

The niche is clear — offensive and defensive security research — and the triggers (安全/渗透/红队/蓝队/漏洞) are terms virtually no other skill would claim, so conflict risk is minimal. It is not below 5 because the trigger list is distinct and unambiguous despite the breadth of the security domain.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 6 missing

Warning

Total

15

/

16

Passed

Repository
fengshao1227/ccg-workflow
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.