CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-dpapi-credential-chain

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for DPAPI masterkeys, vault blobs, browser credential stores, protected secrets, domain backup keys, and secret-to-acceptance replay chains. Use when the user asks to inspect DPAPI blobs or masterkeys, recover browser or vault credentials, trace DPAPI context or backup-key use, or explain how protected Windows secrets become accepted access or privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean instruction-only workflow skill that offloads detail to one real reference and assumes Claude's competence. Its main gap is the absence of explicit validation/replay-confirmation feedback loops in the workflow and a slightly coarse reference pointer.

Suggestions

Add an explicit validation checkpoint in step 2, e.g. 'Only proceed to step 3 once plaintext replay is confirmed accepted by the target service, not merely decrypted.'

Split the single reference pointer into labeled sub-links (e.g. blob checklist, masterkey checklist, evidence packaging) so the reader can navigate directly to the needed list.

Add one or two concrete acceptance-test commands or checks (e.g. confirming the recovered credential yields a session/token) to lift actionability from actionable instruction toward executable verification.

DimensionReasoningScore

Conciseness

The body is lean: it assumes Claude knows DPAPI internals and lists only the operationally decisive items (SID, protector scope, store names, acceptance edge) with no concept tutorials or padding. Not below 5 because every section earns its place; the 'Reply in Simplified Chinese' note is a terse operational constraint, not fluff.

5 / 5

Actionability

Gives concrete, specific guidance — 'Record SID, user or machine context, masterkey path, vault or browser store, and target replay point' and a crisp protected-artifact->masterkey->plaintext->replay->capability chain — but contains no executable commands or code, which is appropriate for an instruction-only skill yet leaves minor gaps. Not 5 because there are no copy-paste artifacts; not 3 because the per-step instructions name exact fields and stores to capture.

4 / 5

Workflow Clarity

Quick Start plus a 3-step Workflow gives a clear sequence (map context -> prove unwrap and acceptance -> reduce to decisive chain) with a reduction step and a hand-back condition. Not 5 because validation checkpoints are implicit rather than explicit feedback loops (e.g. 'confirm plaintext is accepted before reducing'); not 3 because the sequence and the 'distinguish decryption from accepted access' checkpoint are clearly present.

4 / 5

Progressive Disclosure

The body is an overview with a clearly signaled one-level reference — 'Load references/dpapi-credential-chain.md for the blob checklist, masterkey checklist, and evidence packaging' — and the referenced file exists and matches that description. Not 5 because the link is a plain path rather than a labeled per-topic breakdown (e.g. separate pointers to the blob checklist vs masterkey checklist), so navigation could be slightly more granular.

4 / 5

Total

17

/

20

Passed

Description

90%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, comprehensive, and clearly answers both what and when, with strong trigger phrases and an explicit routing boundary that sharply limits conflict risk. It is slightly long and could drop a few synonyms for extensions, but the substance is excellent.

DimensionReasoningScore

Specificity

Lists multiple concrete targets and actions — 'inspect DPAPI blobs or masterkeys, recover browser or vault credentials, trace DPAPI context or backup-key use, or explain how protected Windows secrets become accepted access or privilege' — covering the domain comprehensively. Not below 5 because coverage spans masterkeys, vault blobs, browser stores, backup keys, and replay chains with named operations.

5 / 5

Completeness

Explicitly answers 'what' ('CTF-sandbox workflow for DPAPI masterkeys, vault blobs, browser credential stores, protected secrets, domain backup keys, and secret-to-acceptance replay chains') and 'when' with a concrete 'Use when the user asks to...' trigger clause plus a routing precondition. Not below 5 because both what and when are present and concrete.

5 / 5

Trigger Term Quality

Includes natural user-facing phrases like 'inspect DPAPI blobs or masterkeys', 'recover browser or vault credentials', and 'backup-key use', but is missing common synonyms and concrete file extensions (e.g. .json login data, cookies file names) a user might mention. Not 5 because synonym/extension coverage is incomplete; not 3 because several genuine natural-language trigger phrases are present.

4 / 5

Distinctiveness Conflict Risk

The DPAPI-specific niche, explicit routing dependency on '$ctf-sandbox-orchestrator', and the hand-back note make it clearly distinct from sibling skills with minimal overlap risk. Not below 5 because the trigger phrases and boundary ('Use only after...') carve out a precise, non-overlapping niche.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.