CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-agent-cloud

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

58

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./CTF-Sandbox-Orchestrator/competition-agent-cloud/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and token-efficient, with clear routing to a real reference file and sibling skills. It is held back by a lack of executable detail and missing validation checkpoints for exploit reproduction, which the rubric treats as a capping condition for workflow clarity.

Suggestions

Add at least one concrete, executable example (e.g., a command or snippet to compare a manifest against a live mount, or to capture a prompt-to-tool trace) to lift actionability.

Insert an explicit validation checkpoint in the workflow, e.g., 'Confirm the reproduced side effect occurs with minimal context before recording it as the exploit chain.'

Expand references/agent-cloud.md or add a second reference so the one-level-deep material matches the breadth of sub-domains the body enumerates.

DimensionReasoningScore

Conciseness

Lean, list-driven body that assumes Claude's competence and avoids explaining basic concepts; a few generic phrases ('Distinguish checked-in intent from live runtime truth') could be trimmed but every section earns its place.

4 / 5

Actionability

Guidance is concrete in intent (map a minimal control chain, split build/deploy/runtime, reconcile manifests with live mounts) but offers no executable commands, code, or specific tool invocations, leaving it as directional rather than copy-paste-ready.

3 / 5

Workflow Clarity

A numbered Quick Start sequence and two-step workflow are present, but there are no explicit validation/verification checkpoints for reproducing an exploit or confirming a misconfiguration; the destructive/verification-sensitive nature of CTF exploit reproduction caps this at 3.

3 / 5

Progressive Disclosure

The body is a concise overview that cleanly signals one one-level-deep reference (references/agent-cloud.md, which exists) and lists sibling-skill routes under 'Read This Reference'; the single reference is thin relative to the breadth, keeping it just below 5.

4 / 5

Total

14

/

20

Passed

Description

71%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and trigger-rich for a CTF-sandbox specialization niche, clearly stating what and when. It loses points because the multi-domain scope overlaps sibling skills and the trigger is gated behind a prerequisite orchestrator skill rather than standing alone.

Suggestions

Narrow the primary trigger so it does not overlap with the sibling specialization skills it defers to (prompt-injection, supply-chain, etc.); either commit to the umbrella framing or trim the listed sub-domains.

Make the standalone 'Use when...' trigger explicit without requiring the reader to already know about $ctf-sandbox-orchestrator, so the description is self-contained for routing.

DimensionReasoningScore

Specificity

Names a concrete niche (CTF-sandbox workflow for AI-agent, prompt-injection, MCP/toolchain, cloud, container, CI/CD, supply-chain) with several specific analysis actions like 'analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift'; minor gaps in named concrete actions cap it below 5.

4 / 5

Completeness

Clearly states what it does (specialized CTF-sandbox analysis workflow) and when to use it ('Use when the user asks to analyze...'), but the 'when' is gated on a prerequisite skill ('Use only after $ctf-sandbox-orchestrator'), making the standalone trigger slightly less explicit than the 5 anchor.

4 / 5

Trigger Term Quality

Strong coverage of natural trigger phrases ('prompt-to-tool flows', 'retrieval poisoning', 'mounted secrets', 'deployment drift', 'runtime-vs-manifest mismatches', 'registry provenance', 'CI-produced artifacts') a user might actually say; missing a few common synonyms/extensions.

4 / 5

Distinctiveness Conflict Risk

The CTF-sandbox niche is fairly specific, but the description bundles many sub-domains (prompt-injection, cloud, container, CI/CD, supply-chain) that overlap with sibling specialization skills it defers to, creating moderate overlap risk despite clear routing.

3 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.