CtrlK
BlogDocsLog inGet started
Tessl Logo

security-arsenal

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.

66

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, executable security arsenal with decent embedded workflows, but it fails progressive disclosure badly: it is an oversized monolith that references non-existent bundle files. Conciseness also suffers from inlined reference bulk.

Suggestions

Split the WAF bypass tables, payload catalogs, and Framework 1-Day section into separate files under references/ (e.g. references/waf-bypass.md, references/framework-1day.md) and have SKILL.md point to them one level deep, so the overview stays lean.

Either create the cited tools/ scripts (bypass_403.sh, waf_response_analyzer.py, waf_encoder.py, multipart_mutator.py) under scripts/ or remove/replace the broken references with inline guidance, so navigation is not misleading.

Trim explanatory prose that restates how WAF tokenizers/parsers work and consolidate the repeated "> Submittable / N/A" notes into a single submission-rules section to reduce token overhead.

DimensionReasoningScore

Conciseness

Most of the file is lean payload/tables, but the ~1660-line monolith inlines large reference datasets and includes prose explanations of WAF tokenizer behavior and framework context that could be tightened; the sheer inlined volume is a token-budget concern for a SKILL.md overview.

3 / 5

Actionability

Copy-paste-ready payloads, concrete curl/hashcat/sqlmap commands, and per-engine RCE examples cover the common cases with fully executable guidance throughout.

5 / 5

Workflow Clarity

The Bypass Decision Tree, numbered HTTP-smuggling detection steps, and per-finding "Submittable / N/A" verdict boxes provide clear sequences with validation checkpoints (e.g. the 5-minute kill rule, verdict system for batch probes); minor gaps keep it below 5.

4 / 5

Progressive Disclosure

A 1668-line monolithic wall of text with no references/scripts/assets bundle, yet the body cites tools/bypass_403.sh, tools/waf_encoder.py, tools/multipart_mutator.py, and web2-vuln-classes — files that do not exist — so navigation is broken and content that belongs in separate reference files is inlined.

2 / 5

Total

14

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, comprehensive, and clearly states both capability and trigger conditions with strong natural-language keywords. Its only flaw is second-person voice ("you need"), which the rubric penalizes on specificity.

DimensionReasoningScore

Specificity

Lists multiple concrete artifacts ("Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table") giving comprehensive coverage; reduced from 5 because the second-person "Use when you need" / "Also use when" phrasing triggers the voice penalty.

4 / 5

Completeness

Explicitly answers both what (payloads, bypass tables, wordlists, submission tables) and when ("Use when you need specific payloads for..." and "Also use when asked about what NOT to submit") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including abbreviations and synonyms users actually say: "XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass" plus "what NOT to submit".

5 / 5

Distinctiveness Conflict Risk

Clear niche (offensive security payload arsenal plus bug-bounty submission rules) with distinct, specific triggers and minimal overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (1669 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
shuvonsec/claude-bug-bounty
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.