CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

70%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable TSK commands and concrete Autopsy workflows, but it is held back by redundant tool/concept tables that duplicate the api-reference.md bundle and by missing validation/feedback loops for destructive forensic operations. Progressive disclosure is undermined because the provided references are never linked from the body.

Suggestions

Add explicit validation checkpoints to the destructive steps — e.g. verify image hash/integrity before ingest and confirm recovered file integrity after icat/tsk_recover — to satisfy the workflow-clarity feedback-loop requirement.

Replace the inlined 'Tools & Systems' table and repeated TSK syntax with links to references/api-reference.md, and link scripts/agent.py for the automated workflow, so the body acts as an overview and avoids duplication.

Trim the 'Key Concepts' table (MFT, file carving, hash filtering, etc.) since these are concepts Claude already knows, keeping the body lean.

DimensionReasoningScore

Conciseness

Mostly efficient and code-forward, but it repeats tool descriptions already in the api-reference.md (e.g. fls, mmls, mactime rows duplicated in the 'Tools & Systems' table) and includes conceptual explanations (MFT, file carving, hash filtering) Claude already knows.

2 / 3

Actionability

Each step provides concrete, executable commands and specific Autopsy menu paths with real example values (offsets, regexes, inode numbers), making the guidance copy-paste ready.

3 / 3

Workflow Clarity

Steps are clearly sequenced across six phases, but for destructive/batch operations like deleted-file recovery and ingest there are no validation checkpoints or error-recovery feedback loops (e.g. verify image integrity before ingest, confirm recovered file integrity), which caps clarity at 2.

2 / 3

Progressive Disclosure

Real bundle files exist (references/api-reference.md, scripts/agent.py) but the body never signals or links them — the duplicated TSK syntax and command tables that already live in api-reference.md are inlined instead of referenced, so content that should be separate stays inline.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that specifies concrete forensic capabilities and gives an explicit 'Use for...' trigger covering structured analysis and visual reports. It earns full marks on all dimensions with only minor room to add more natural trigger phrasings.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports' — going well beyond a single domain mention.

3 / 3

Completeness

It answers both 'what' (forensic analysis of disk images, recovery, timelines, reports) and 'when' via the explicit 'Use for...' clause naming when stakeholders need visual reports from evidence.

3 / 3

Trigger Term Quality

It surfaces natural terms users would say — 'forensic disk image', 'visual reports', 'evidence', 'deleted files', 'E01', 'dd' — giving good coverage of common variations.

3 / 3

Distinctiveness Conflict Risk

The Autopsy/Sleuth Kit forensic-disk niche with E01/AFF/dd formats is clearly distinct and unlikely to trigger for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.