CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-forensic-timeline

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for DFIR chronology, cross-artifact correlation, persistence chains, and incident timeline reconstruction. Use when the user asks to build a forensic timeline, correlate EVTX, PCAP, registry, disk, memory, mailbox, or browser artifacts, explain the order of attacker actions, or pinpoint the stage where the decisive artifact appears. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized, concise, and uses progressive disclosure with a verified one-level reference, with a clear multi-step workflow. Its main gap is actionability: it stays at the process-guidance level without a concrete worked example or output template.

Suggestions

Add one short worked example of a decisive timeline segment (e.g., a 3-4 row ordered table tying a logon ID to a process and a network session) to make the guidance copy-paste ready.

Show the concrete output format you expect for the 'compact timeline table or ordered list' mentioned in 'What To Preserve' so the final answer shape is unambiguous.

Optionally include one specific correlation command or parser invocation (e.g., an evtx parsing snippet) to lift actionability from process description to executable instruction.

DimensionReasoningScore

Conciseness

The body is lean (~45 lines), assumes Claude's competence, and does not re-explain concepts like what EVTX or PCAP are; every section earns its place. Minor repetition of the orchestrator-gating message is the only slack, but not enough to drop a level.

3 / 3

Actionability

Gives concrete lists of artifact types and correlation identifiers, but provides no executable commands/code and no worked example of a decisive timeline segment or output format, fitting the 'some concrete guidance but incomplete' anchor rather than 'copy-paste ready'.

2 / 3

Workflow Clarity

A clear numbered Quick Start plus a three-phase Workflow with explicit confirmed-vs-inferred separation and 'call out missing validation steps separately' guidance; not 2 because validation reasoning is explicit rather than merely implied.

3 / 3

Progressive Disclosure

A concise overview that signals one real one-level-deep reference (references/forensic-timeline.md, verified present) with clear navigation; not below because the reference does not nest further and content is appropriately split.

3 / 3

Total

11

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities, gives explicit and varied trigger terms, answers both 'what' and 'when', and is clearly scoped to avoid skill conflicts. No meaningful weaknesses to address.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'DFIR chronology, cross-artifact correlation, persistence chains, and incident timeline reconstruction' — matching the 'multiple specific concrete actions' anchor; not the level below because it goes well beyond naming a single domain.

3 / 3

Completeness

Explicitly answers 'what' (DFIR chronology, correlation, persistence chains, timeline reconstruction) and 'when' via a clear 'Use when...' clause with multiple triggers; not 2 because the 'when' is explicit rather than implied.

3 / 3

Trigger Term Quality

Covers natural terms a user would say — 'build a forensic timeline, correlate EVTX, PCAP, registry, disk, memory, mailbox, or browser artifacts, explain the order of attacker actions' — with broad variation; not below because it is not limited to a single jargon phrase.

3 / 3

Distinctiveness Conflict Risk

A clear niche (CTF forensic-timeline reconstruction) with distinct triggers and an explicit scope guard ('Use only after `$ctf-sandbox-orchestrator`'), making wrong-skill triggering unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.