CtrlK
BlogDocsLog inGet started
Tessl Logo

firmware-analyst

Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is highly actionable with executable commands across a well-sequenced firmware analysis workflow, but it lacks validation checkpoints for destructive operations and keeps all reference material inlined in a single long file rather than splitting it into progressively disclosed bundle files.

Suggestions

Add explicit validation/verification steps between phases (e.g., confirm extraction output size and entropy before filesystem analysis, re-verify a flashed or modified image) to lift workflow clarity above the destructive-operation cap of 3.

Split the large reference tables (Tool Proficiency, Common Vulnerability Classes, Reporting Template) into separate files under references/ and link to them from SKILL.md to improve progressive disclosure.

Trim or consolidate the tool-proficiency and vulnerability-class lists to only entries not already known to Claude, improving token efficiency.

DimensionReasoningScore

Conciseness

The body is mostly lean command/code reference with little concept over-explanation, but the tool-proficiency tables and vulnerability-class descriptions are reference-heavy padding that could be trimmed; not 5 because not every token earns its place, not 3 because it is largely efficient rather than noticeably verbose.

4 / 5

Actionability

Provides copy-paste-ready, executable commands across all phases (binwalk -eM, dd if=/dev/mtd0, chroot with qemu-static, Firmadyne scripts) covering the common cases; not 4 because the guidance is fully executable rather than having minor gaps.

5 / 5

Workflow Clarity

The four phases are clearly sequenced and a checklist exists, but destructive/batch operations (dd from /dev/mtd0, chip-off, flashing) lack explicit validation checkpoints and feedback loops; per the rubric cap, a destructive workflow without validation cannot score above 3. Not 2 because the sequence is coherent, not 4 because validation gates are missing.

3 / 5

Progressive Disclosure

Content is reasonably sectioned by headers but is a monolithic ~308-line file with no bundle files and no external references; tool lists, vulnerability classes, and the reporting template are inlined content that could live in separate files. Not 4 because no file split or signaled references are used despite the length, not 2 because section structure exists.

3 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and explicitly answers both what the skill does and when to use it, with comprehensive domain coverage and natural trigger terms. Minor keyword synonym/extension gaps keep trigger quality just below the top anchor.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('firmware extraction, analysis, and vulnerability research') across several device domains (routers, IoT, automotive, industrial controllers), matching the comprehensive-coverage anchor; not 4 because coverage and action count are broad rather than having minor gaps.

5 / 5

Completeness

Explicitly states what it does (extraction, analysis, vulnerability research) and when to use it ('Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research'), matching the anchor for clearly answering both with concrete trigger phrases; not 4 because 'when' is explicit and specific rather than weakly implied.

5 / 5

Trigger Term Quality

Includes natural triggers ('firmware security audits, IoT penetration testing, embedded systems research') but omits common synonyms and file extensions (e.g., 'reverse engineering firmware', '.bin', 'extract firmware'); not 5 because keyword coverage is not fully comprehensive.

4 / 5

Distinctiveness Conflict Risk

Targets a clear niche ('embedded systems, IoT security, and hardware reverse engineering') with distinct triggers and minimal overlap with other skills; not 4 because the niche and triggers are distinct rather than having minor overlap risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.