CtrlK
BlogDocsLog inGet started
Tessl Logo

linux-privilege-escalation

This skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for root access", "enumerate Linux systems for privilege escalation", or "gain root access from low-privilege shell". It provides comprehensive techniques for identifying and exploiting privilege escalation paths on Linux systems.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/linux-privilege-escalation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers a well-sequenced, fully executable privesc playbook with concrete payloads for every major vector. Its weaknesses are efficiency and structure: it re-lists basic enumeration commands Claude already knows, duplicates material in a quick-reference section, keeps everything in one long file instead of splitting references, and lacks validation checkpoints around its destructive steps.

Suggestions

Add explicit validation checkpoints between phases of the destructive steps (e.g., verify a kernel exploit on a test snapshot before running it, confirm a writable cron script's permissions and cron daemon status before injecting a payload) so the workflow doesn't rely on the post-hoc Troubleshooting table.

Cut Phase 1's basic-command listings down to the handful of privesc-relevant commands (sudo -l, SUID find, getcap, crontab, exports) and drop the Quick Reference table that duplicates them, or move both into a reference file.

Split the monolithic body: move the kernel-exploit table, reverse-shell one-liners, worked examples, and troubleshooting table into one-level-deep reference files (e.g., references/kernel-exploits.md, references/payloads.md) and keep SKILL.md as the phased overview.

DimensionReasoningScore

Conciseness

The body avoids concept explanations, but Phase 1 spends ~80 lines listing trivial commands Claude already knows (hostname, whoami, id, env, ps aux, ifconfig, cat /etc/issue), and the Quick Reference table plus reverse-shell one-liners repeat or extend material already covered. Mostly efficient with clear trim opportunities, matching anchor 3 rather than anchor 4's 'minor instances'.

3 / 5

Actionability

Every phase is copy-paste executable: complete enumeration commands, an LD_PRELOAD C source with its exact gcc invocation, concrete GTFOBins-style sudo/SUID payloads, a writable-cron hijack, PATH hijack, and an NFS SUID-shell recipe. This matches anchor 5 — executable, specific examples covering the common cases.

5 / 5

Workflow Clarity

The nine phases are clearly sequenced, but destructive operations (kernel exploits that 'may crash the system', overwriting cron scripts, writing to /etc/shadow) have no inline validation checkpoints — only a post-hoc Troubleshooting table and a guardrail sentence. The rubric's cap for destructive workflows without validation applies, holding this at anchor 3 rather than 4.

3 / 5

Progressive Disclosure

Section headers and a quick-reference summary give real structure, but ~500 lines are inlined in one monolithic SKILL.md with no bundle files — the kernel-exploit table, reverse-shell one-liners, worked examples, and troubleshooting table are prime candidates for one-level-deep reference files. This fits anchor 3 ('content that should be separate is inline') better than anchor 2, since navigation via headers is present and clear.

3 / 5

Total

14

/

20

Passed

Description

81%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit, natural-sounding trigger list and a clearly bounded Linux-privesc niche. The main weakness is that the capability ('what') sentence is generic and leans on "comprehensive" rather than naming its own techniques, which it currently borrows only from the trigger phrases.

DimensionReasoningScore

Specificity

The 'what' clause is generic ("provides comprehensive techniques for identifying and exploiting privilege escalation paths") and never names concrete techniques itself; the specific vectors (sudo, SUID, cron) appear only inside the trigger phrases. This matches anchor 3 — domain named with some concrete actions but not a comprehensive standalone capability list — and not anchor 4 because no distinct action list is given outside the triggers.

3 / 5

Completeness

Both are present: an explicit 'when' ("when the user asks to...") and a 'what' ("provides... techniques for identifying and exploiting privilege escalation paths"). Not anchor 5 because the 'what' relies on the vague word "comprehensive" rather than enumerating concrete capabilities, while the 'when' is stronger than anchor 4's example.

4 / 5

Trigger Term Quality

Trigger coverage is comprehensive and natural, including synonyms users actually say: "escalate privileges on Linux", "privesc vectors", "sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for root access", "gain root access from low-privilege shell". Matches anchor 5's comprehensive-synonyms pattern.

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche — Linux privilege escalation specifically — with distinct triggers (privesc, sudo, SUID, cron, root) that would not fire for unrelated skills, matching anchor 5. It is more distinct than anchor 4's 'minor overlap with closely related skills', since the scope is pinned to one OS and one activity.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (505 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.