CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/analyzing-disk-image-with-autopsy/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete forensic commands, but it is verbose in places, lacks explicit validation checkpoints for evidence-handling operations, and does not use the provided bundle files for progressive disclosure.

Suggestions

Add explicit validation checkpoints (e.g., verify image hash/integrity before analysis, confirm recovered files open correctly) so destructive/batch forensic steps have feedback loops.

Trim the Key Concepts table and ingest-module descriptions that restate forensics fundamentals Claude already knows, or move them to references/api-reference.md.

Link to the bundled references/api-reference.md and scripts/agent.py from the relevant workflow steps instead of inlining all detail in SKILL.md.

DimensionReasoningScore

Conciseness

Mostly efficient command examples, but the Key Concepts table and ingest-module descriptions re-explain forensics basics Claude already knows, and the mock output block adds length without proportional instruction.

3 / 5

Actionability

Provides concrete, mostly copy-paste-ready Sleuth Kit commands (fls, icat, mmls, mactime) and real regex patterns, though several GUI steps remain prose-numbered rather than scriptable.

4 / 5

Workflow Clarity

A clear six-step sequence exists, but validation/checkpoint steps are largely absent for batch and destructive-adjacent forensic operations, which caps this dimension per the destructive/batch rule.

3 / 5

Progressive Disclosure

Headers give some structure, but the body is monolithic and never links to the bundled references/api-reference.md or scripts/agent.py, so detailed material is inlined rather than split out.

3 / 5

Total

13

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is comprehensive, concrete, and explicitly provides both capability and trigger guidance in third person. It is among the strongest example patterns, with only minor room to broaden trigger synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports') tied to specific tools and image formats, giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers 'what' (the action list) and 'when' ('Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.') in third person, with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Strong natural/technical terms ('disk images', 'raw (dd), E01, AFF', 'forensic', 'file recovery', 'visual reports', 'timeline') with format extensions, but a few common user synonyms are not exhaustively covered.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Autopsy/The Sleuth Kit forensic disk image analysis) with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.