CtrlK
BlogDocsLog inGet started
Tessl Logo

firmware-analyst

Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete, executable commands and a clear phased workflow, but it is a dense monolith that restates some known concepts and lacks explicit validation checkpoints and external reference structure.

Suggestions

Add explicit validation/verification checkpoints to the workflow (e.g., confirm extraction completeness before analysis, validate emulated services respond) and a validate→fix→retry loop for risky operations like extraction and flashing.

Move the long tool-proficiency and vulnerability-class catalogs into reference files (e.g., tools.md, vuln-classes.md) and link to them from SKILL.md to improve progressive disclosure and reduce token load.

Trim concept restatements Claude already knows (e.g., definitional descriptions of buffer overflows and what each analysis tool is) to tighten conciseness.

DimensionReasoningScore

Conciseness

The body is largely concrete commands and tables, but it restates concepts Claude already knows (e.g., the Common Vulnerability Classes and Tool Proficiency sections describe what each tool/class is) and could be tightened, matching the 'mostly efficient but includes some unnecessary explanation' anchor rather than the fully lean one.

2 / 3

Actionability

Provides fully executable bash commands, specific tool invocations (binwalk -eM, unsquashfs, qemu-arm-static chroot, firmadyne scripts), working cross-compilation commands and injection test payloads, and a copy-paste reporting template, matching the executable copy-paste-ready anchor.

3 / 3

Workflow Clarity

A clear phased sequence (Identification → Extraction → File System Analysis → Binary Analysis) plus a checklist exists, but validation/verification checkpoints within phases are implicit and there is no validate→fix→retry feedback loop for risky extraction/flash operations, matching the 'sequence present but checkpoints missing or implicit' anchor.

2 / 3

Progressive Disclosure

Everything is inline in a single monolithic file with no bundle files and no signaled external references; content that could be split out (tool catalog, reporting template, vulnerability-class reference) is all inline, matching the 'some structure but content that should be separate is inline' anchor.

2 / 3

Total

9

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and distinctive: it states concrete capabilities, covers natural trigger terms, and gives an explicit 'Use when' clause. It is a strong, well-targeted description.

DimensionReasoningScore

Specificity

Names the domain and multiple concrete actions across device classes — 'Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers' — matching the anchor listing several specific concrete actions.

3 / 3

Completeness

Explicitly answers both what (extraction, analysis, vulnerability research) and when via 'Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research', matching the highest anchor.

3 / 3

Trigger Term Quality

Includes natural user-facing terms ('firmware', 'IoT', 'embedded systems', 'routers', 'vulnerability research', 'penetration testing') with good coverage of what a user would actually say, matching the strong-coverage anchor.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (firmware/embedded reverse engineering) with distinct triggers unlikely to fire for unrelated skills, matching the clear-niche anchor.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.