CtrlK
BlogDocsLog inGet started
Tessl Logo

frida

Dynamic instrumentation via Frida - attach to or spawn a process, load a JS hook script, capture send() events into a lifecycle-managed run directory. Supports local, USB-attached, and remote frida-server targets.

66

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/frida/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands and code, a sensible section flow, and a strong error-recovery table; the main gaps are minor verbosity and the absence of an explicit numbered validation-checkpoint workflow.

Suggestions

Tighten the 'Untrusted-content envelope' paragraph and Pipeline-integration table to their essential rows to reclaim token budget.

Add a short numbered quick-start sequence (install → run wrapper → read metadata.json → consult failure modes) with an explicit 'verify metadata.json before interpreting events.jsonl' checkpoint.

Consider moving the Programmatic API and Pipeline-integration detail into a separate reference file linked from the body to improve progressive disclosure.

DimensionReasoningScore

Conciseness

The body is largely lean and action-oriented and assumes Claude's competence with Frida; minor over-explanation in the 'Untrusted-content envelope' and Pipeline-integration sections could be trimmed.

4 / 5

Actionability

Copy-paste-ready commands (install, libexec wrapper invocation, five worked examples) plus an executable programmatic API cover the common local/USB/remote/custom-script cases.

5 / 5

Workflow Clarity

A clear install → invoke → output → failure-recovery structure exists and the 'Failure modes' table provides error-recovery feedback, but there is no explicit numbered validate-then-proceed checkpoint sequence.

4 / 5

Progressive Disclosure

Sections are well-organized with a clearly signaled one-level reference (docs/frida.md) and no bundle files needed, though the Pipeline-integration and Programmatic API detail could arguably live in a separate reference file.

4 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, concrete, and occupies a clearly distinct niche, but it omits any 'Use when...' trigger guidance, which caps its completeness at 3 and leaves trigger-term coverage short of comprehensive.

Suggestions

Append a 'Use when...' clause naming concrete trigger phrases (e.g. 'Use when /scan or /agentic flagged a runtime sink to confirm, when a binary is opaque and an API trace would reveal its shape, or when a pinned mobile app blocks your MITM proxy').

Add natural synonyms / variants users might say ('instrument a process', 'runtime hooking', 'frida-server') to broaden trigger-term coverage.

Keep the existing concrete action list — it already anchors specificity well.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'attach to or spawn a process, load a JS hook script, capture send() events into a lifecycle-managed run directory' — with comprehensive coverage of the skill's core function.

5 / 5

Completeness

The 'what' is clearly and concretely stated, but there is no 'Use when...' clause or equivalent trigger guidance; per the rubric a missing 'when' caps completeness at 3.

3 / 5

Trigger Term Quality

Natural domain terms ('Dynamic instrumentation', 'Frida', 'hook script', 'frida-server') are present and would be said by a user needing this skill, but no synonyms or extension variants are included.

4 / 5

Distinctiveness Conflict Risk

'Dynamic instrumentation via Frida' is a clear, narrow niche with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
gadievron/raptor
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.