CtrlK
BlogDocsLog inGet started
Tessl Logo

ctf-forensics

Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files and credentials.

63

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./ctf-forensics/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, action-oriented forensics reference with strong quick-start commands, but it is a catalog rather than a validated workflow, contains duplicated entries, and relies on reference files that are absent from the bundle.

Suggestions

Ship the referenced supporting files (windows.md, network.md, stego-*.md, disk-*.md, etc.) or remove the dangling links, since the body depends on them for full detail.

Deduplicate techniques that appear both in the "Additional Technique Quick References" list and in their own dedicated sections (packet interval timing, SMB RID recycling, Timeroasting).

Add explicit validation/verification checkpoints (e.g., verify a mounted image is read-only, confirm carved files have valid magic bytes before analyzing) for destructive or batch forensic operations.

DimensionReasoningScore

Conciseness

Mostly lean one-liners and copy-paste commands with no padding about concepts Claude already knows, but several techniques are duplicated across sections (e.g., packet interval timing, SMB RID recycling, Timeroasting each appear twice), so not every token earns its place.

4 / 5

Actionability

Quick-start sections provide concrete, executable commands (file, exiftool, binwalk, vol3, tshark, hashcat) and real code snippets, but many catalog entries are descriptions pointing to other files rather than the executable steps themselves.

4 / 5

Workflow Clarity

The skill is a technique catalog rather than a sequenced workflow; quick-start gives a rough command order but lacks explicit validation checkpoints or fix-retry feedback loops for destructive/batch operations like disk mounting and carving, which caps this dimension at 3.

3 / 5

Progressive Disclosure

References to supporting files are clearly signaled and one level deep, but the referenced files (windows.md, network.md, etc.) do not exist in the bundle, and a large catalog of per-technique detail is inlined in SKILL.md that would belong in those separate files.

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with an explicit "Use when" trigger clause and comprehensive concrete analysis targets. Minor room to add file extensions and a wider variety of action verbs.

DimensionReasoningScore

Specificity

Names the domain ("digital forensics and signal analysis techniques for CTF challenges") and enumerates many concrete analysis targets (disk images, memory dumps, Volatility, PCAP, DTMF audio spectrograms, side-channel power traces), though the action verbs are limited to "provides", "analyzing", and "recovering".

4 / 5

Completeness

Clearly answers "what" ("Provides digital forensics and signal analysis techniques for CTF challenges") and explicitly answers "when" with a concrete "Use when analyzing ..." trigger clause listing many specific scenarios.

5 / 5

Trigger Term Quality

Excellent natural keyword coverage including synonyms ("network captures"/"PCAP") and tool names ("Volatility"), but lacks file extensions (.dd, .dmp, .pcap, .evtx) that users would also naturally mention.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear CTF-forensics niche with distinct, specialized triggers (Volatility, PCAP, DTMF spectrograms, side-channel power traces) unlikely to fire for unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 117 missing

Warning

Total

14

/

16

Passed

Repository
ljagiello/ctf-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.