CtrlK
BlogDocsLog inGet started
Tessl Logo

windows-kernel-security

Analyze Windows driver trust boundaries and kernel evidence for game-security research. Use for IOCTL authorization, callbacks and IRQL, driver provenance, DSE/PatchGuard, VBS/HVCI, build-specific internals, and crash or memory forensics; select repository resources for symbol comparison, ETW metadata, driver-unit coverage and offline dumps. Distinguish documented contracts, observed host state and inferred internals; report privilege prerequisites, mitigation scope, missing coverage and benign alternatives.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/windows-kernel/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-organized reference skill with good progressive disclosure and a real on-demand reference file, but it carries significant verbosity cataloging concepts Claude already knows and provides more list-style enumeration than executable guidance. Validation checkpoints appear in the rigor sections but are not uniformly applied to risky operations.

Suggestions

Trim the catalog-style enumerations of widely known internals (EPROCESS/KTHREAD fields, VMCS control-field lists, hypervisor type examples) down to what is build-specific or non-obvious, or move them into a separate reference file to improve conciseness.

Convert the symbol-walking methodology and exploitation-steps bullets into concrete, copy-pasteable commands/code (e.g., a runnable dbghelp snippet) so the guidance is executable rather than descriptive.

Add explicit validate->fix->retry feedback loops for the destructive or batch operations (vulnerable-driver loading, kernel read/write, pool-corruption analysis) to lift workflow clarity above the validation cap.

DimensionReasoningScore

Conciseness

The 780-line body catalogs many structures, callbacks, and concepts Claude largely already knows (EPROCESS, VMCS fields, hypervisor types) with padded bullet lists, which is noticeably verbose even though it avoids prose tutorial fluff; it could be tightened into leaner reference tables.

3 / 5

Actionability

Many sections list API names and struct names in fenced blocks but offer incomplete executable guidance (e.g., symbol walking is a pseudocode bullet list, exploitation steps are high-level), fitting the 'some concrete guidance but incomplete / pseudocode' anchor.

3 / 5

Workflow Clarity

Research-rigor and pool/VBS review sections impose validation checkpoints ('use research-rigor before generalizing', 'Verify them against symbols'), and the data-source section sequences source selection, but several destructive/batch operations (driver loading, kernel r/w) lack explicit validate->fix->retry feedback loops, capping the score at 3.

3 / 5

Progressive Disclosure

Clear sectioned overview with a real one-level-deep reference (references/repository-resources.md, verified to exist) and well-signaled cross-skill links; most content is appropriately placed though a fair amount of inline reference material could arguably live in separate files, leaving minor organization gaps.

4 / 5

Total

13

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, third-person description that explicitly covers what the skill does and when to use it with concrete trigger phrases. It distinguishes well from sibling skills, with only minor overlap risk and a few missing natural synonyms.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'IOCTL authorization, callbacks and IRQL, driver provenance, DSE/PatchGuard, VBS/HVCI, build-specific internals, and crash or memory forensics' plus 'select repository resources for symbol comparison, ETW metadata, driver-unit coverage and offline dumps' — matching the comprehensive-coverage anchor.

5 / 5

Completeness

Explicitly answers both 'what' (analyze driver trust boundaries and kernel evidence) and 'when' ('Use for IOCTL authorization... crash or memory forensics') with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Strong natural keyword coverage (IOCTL, PatchGuard, DSE, VBS/HVCI, ETW, callbacks, IRQL, crash forensics), but lacks common synonyms/file extensions a user might say; a few natural phrasings are missing, so it sits just below the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

The niche is fairly clear (Windows kernel + game-security research) with distinct triggers, but adjacent security skills (DMA, reverse-engineering, anti-cheat) share some surface terms, creating minor overlap risk rather than the minimal-conflict top anchor.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (780 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 11 suspicious

Warning

Total

14

/

16

Passed

Repository
gmh5225/awesome-game-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.