CtrlK
BlogDocsLog inGet started
Tessl Logo

dma-attack-techniques

Classify hardware DMA threats, host-driver memory acquisition and network or USB transport in game-security research. Use for PCIe/FPGA, IOMMU/VT-d, Thunderbolt/USB4, LeechCore, WinPmem, bridge-cable claims, device identity and acquisition forensics; select repository resources for architecture, remapping concepts and existing images. Identify the memory initiator and required access, then map observable artifacts, mitigation scope, benign uses and unresolved architecture claims.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/dma-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A technically rich, actionable reference with a clear layered detection workflow, but it is over-long and inlines large reference blocks that belong in separate bundle files. The lowest dimensions are conciseness and progressive disclosure.

Suggestions

Move the PCIe protocol stack, IOMMU architecture, FPGA hardware, and pcileech framework sections into dedicated reference files (e.g., references/pcie-protocol.md, references/iommu-architecture.md) and keep SKILL.md as an overview that links to them, mirroring the existing acquisition-and-transport/assurance-boundaries pattern.

De-duplicate the ASPM, ATS, and Link-Status material that recurs in the Physical Layer, Behavioral Validation, and Pre-Game sections — state each once and cross-reference.

Add an explicit validate→fix→retry feedback loop to the detection pipeline (e.g., re-baseline after a flagged anomaly fails benign-device exclusion) to lift workflow clarity to the top anchor.

DimensionReasoningScore

Conciseness

Most content is specialized, non-common knowledge that earns its place, but the ~1660-line body repeats ASPM, ATS, and Link-Status material across three or more sections, which is padding that could be tightened.

3 / 5

Actionability

Concrete register offsets, bit-field encodings, executable C (pcileech_read_phys, TranslateVA), named Windows APIs, and detection probes ('write Command[BME]=1 → read Command[BME]') give mostly executable guidance with minor gaps in the descriptive bypass catalog.

4 / 5

Workflow Clarity

The 'Layered Detection Pipeline' is a clear sequenced workflow with validation emphasis ('Each detection produces evidence, not a verdict', multi-signal correlation, validate baselines), missing only crisp validate→fix→retry feedback loops for a 5.

4 / 5

Progressive Disclosure

Three real, clearly-signaled reference files exist (acquisition-and-transport, assurance-boundaries, repository-resources), but ~1500 lines of PCIe/IOMMU/FPGA/pcileech reference detail are inlined in SKILL.md rather than split into reference files.

3 / 5

Total

14

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, well-crafted description that crisply states capabilities and triggers for a specialized game-security DMA niche. It is comprehensive on triggers and completeness; the only soft spot is a few abstract action verbs that keep specificity just below the top anchor.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Classify hardware DMA threats', 'Identify the memory initiator and required access', 'map observable artifacts, mitigation scope, benign uses'), but some remain abstract ('map…unresolved architecture claims'), leaving minor gaps versus comprehensive.

4 / 5

Completeness

Explicitly answers both what (classify/identify/map) and when via a concrete 'Use for PCIe/FPGA, IOMMU/VT-d, Thunderbolt/USB4, LeechCore, WinPmem…' trigger clause.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage for the niche with synonym pairs (PCIe/FPGA, IOMMU/VT-d, Thunderbolt/USB4) plus concrete tool names (LeechCore, WinPmem) a game-security researcher would actually say.

5 / 5

Distinctiveness Conflict Risk

A clear narrow niche (game-security DMA threats, bridge-cable claims, acquisition forensics) with distinct triggers and minimal overlap with other skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (1668 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 9 suspicious

Warning

Total

14

/

16

Passed

Repository
gmh5225/awesome-game-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.