CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-cloud-metadata-path

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for cloud metadata services, instance identity, workload identity, link-local credential paths, role assumption, and metadata-to-privilege trust edges. Use when the user asks to inspect metadata-service access, instance credentials, pod or workload identity, link-local token paths, SSRF-to-metadata escalation, or explain how metadata-derived credentials turn into accepted cloud or control-plane privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is lean, well-structured, and appropriately offloads detail to a real one-level reference file. Its main weakness is workflow_clarity: a verification-critical CTF privilege-proof process without an explicit validation/feedback-loop checkpoint.

Suggestions

Add an explicit validation checkpoint in the workflow (e.g., step verifying the issued credential was actually accepted by a downstream API before declaring the chain proven) with a fix-and-retry loop.

Include one compact worked example or concrete command (e.g., a representative link-local curl with required headers) to lift actionability from mostly-executable to fully concrete.

Make the 'switch back to control-plane skill' routing note an explicit conditional checkpoint rather than a passive hint, so the handoff boundary is unambiguous.

DimensionReasoningScore

Conciseness

Lean instruction-only body with no padding and no explanation of concepts Claude already knows; every line is task-relevant and earns its place.

5 / 5

Actionability

Concrete, specific checklist guidance (headers, hop limits, role name, audience, issuer) is actionable for an instruction-only skill, though it lacks executable commands or worked examples that would push it to fully concrete.

4 / 5

Workflow Clarity

A clear sequence (Quick Start 1–5, Workflow 1–3) is present, but proving metadata-to-privilege acceptance is verification-critical and the steps lack an explicit validate/verify checkpoint with a fix-and-retry feedback loop, so the destructive/batch cap applies.

3 / 5

Progressive Disclosure

Clear overview under 50 lines with a single one-level-deep, well-signaled reference (references/cloud-metadata-path.md, verified to exist) and organized sections, fitting the simple-skill exception.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, comprehensive, and well-scoped to a clear niche with explicit 'what' and 'when' guidance plus natural trigger terms. It is a strong, low-conflict description for a downstream specialization skill.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — 'cloud metadata services, instance identity, workload identity, link-local credential paths, role assumption, and metadata-to-privilege trust edges' — giving comprehensive coverage of the niche domain rather than vague language.

5 / 5

Completeness

Explicitly answers both 'what' (the metadata-to-privilege workflow) and 'when' ('Use when the user asks to inspect...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural trigger phrases a CTF user would say are present with synonyms and variations: 'metadata-service access, instance credentials, pod or workload identity, link-local token paths, SSRF-to-metadata escalation'.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (metadata-derived identity to accepted privilege within a CTF sandbox chain) and explicitly distinguishes from sibling skill, minimizing conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.