CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-jwt-claim-confusion

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for JWT, JWS, and JWE validation paths, header parsing, key selection, claim acceptance, audience and issuer checks, role derivation, and token-to-identity confusion bugs. Use when the user asks to inspect JWT headers or claims, key lookup, `kid` handling, `alg` confusion, audience or issuer validation, role claims, or explain how a token becomes accepted identity or privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-organized analysis skill: dense overview in the body with checklists deferred to one real reference file, a clear multi-step workflow, and a proof-oriented closing step. The only weakness is that intermediate validation checkpoints are implicit rather than called out.

Suggestions

Add an explicit mid-flow checkpoint, e.g. after mapping header/key selection, 'Confirm parser success is distinguished from authorization success before proceeding to claim-to-privilege analysis.'

Surface the reference earlier with a one-line pointer at the top of the Workflow section so the checklist is discoverable before step 1 rather than only at the end.

Tighten the slight overlap between Quick Start steps 1-2 and Workflow sections 1-2 by making Quick Start purely the high-level spine and reserving field-level detail for the Workflow.

DimensionReasoningScore

Conciseness

Lean instruction-only body that assumes Claude's competence — no textbook explanation of JWT concepts, compact bullets, and every section (Quick Start, Workflow, Preserve) earns its place.

5 / 5

Actionability

Concrete, specific guidance for an analysis task (exact header fields to record, exact claim-to-privilege mappings to trace, an explicit token->acceptance compression format), but it is procedural direction rather than copy-paste commands, leaving minor gaps.

4 / 5

Workflow Clarity

A clear sequenced process (Quick Start 1-5 feeding into Workflow 1-3) with a terminal proof step ('Reproduce the smallest token-to-acceptance flow that proves the decisive confusion'), though intermediate validation checkpoints are implicit rather than explicit.

4 / 5

Progressive Disclosure

Body is a concise overview that points to a single, well-signaled one-level-deep reference (references/jwt-claim-confusion.md, verified present) holding the checklists and evidence packaging — easy to navigate, content appropriately split.

5 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, well-structured description that conveys concrete capabilities, natural trigger terms, explicit use-conditions, and a clear routing boundary — all in third person with no padding.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — JWT/JWS/JWE validation paths, header parsing, key selection, claim acceptance, audience/issuer checks, role derivation, and token-to-identity confusion bugs — giving comprehensive coverage rather than generic phrasing.

5 / 5

Completeness

Explicitly states both what the skill does (the validation-path workflow) and when to use it, with concrete 'Use when the user asks to...' trigger phrases and a routing precondition.

5 / 5

Trigger Term Quality

Covers natural domain terms a CTF user would say (JWT headers, claims, key lookup, `kid` handling, `alg` confusion, audience/issuer validation, role claims) plus synonyms/forms (JWT, JWS, JWE).

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (JWT claim-confusion analysis within a CTF sandbox) with distinct triggers and an explicit 'Use only after $ctf-sandbox-orchestrator' guard that minimizes conflict with sibling skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.