CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-linux-credential-pivot

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Linux credential artifacts, service tokens, SSH material, cloud and container secrets, socket-level trust, and host-to-host pivot chains. Use when the user asks to trace Linux auth artifacts, accepted token or key replay, socket or service-account trust edges, sudo or capability abuse, or explain lateral movement across Linux challenge nodes. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-organized methodology skill with good progressive disclosure to a single real reference. Its weaknesses are actionability and workflow clarity: it tells Claude what to look for and record but rarely how to prove acceptance or verify a replay, and the workflow lacks explicit validation checkpoints.

Suggestions

Add concrete, executable techniques under 'Prove Replay And Pivot' (e.g., `ssh -i <key> ... -o BatchMode=yes`, `kubectl --kubeconfig=... auth can-i --list`, `curl --unix-socket ...`) so the guidance is copy-paste ready rather than goal-only.

Insert an explicit verification checkpoint into the workflow, e.g., after 'Prove Replay And Pivot', require confirming the replay produced a new session/privilege before compressing to the decisive chain, with a fix-and-retry loop on failure.

Optionally add a one-line example artifact-to-accepted-access chain in 'Reduce To Decisive Linux Pivot Chain' so the compressed output format is unambiguous.

DimensionReasoningScore

Conciseness

The body is a lean set of bullets and short sections that assumes Claude's competence — it never explains what SSH, kubeconfigs, or capabilities are — so every token earns its place, matching the level-3 'lean and efficient' anchor.

3 / 3

Actionability

It gives concrete artifact checklists ('Record SSH keys, agent sockets, kubeconfigs, cloud tokens…') but instructs rather than methods — 'Show where key, token, socket, or secret is accepted' and 'Prove Replay And Pivot' describe the goal without executable commands or techniques, fitting the level-2 'some concrete guidance but incomplete' anchor.

2 / 3

Workflow Clarity

The three-step sequence (Map → Prove → Reduce) is clearly ordered, but there are no explicit validation/verification checkpoints or replay-verify feedback loops, and the rubric caps such workflows at level-2 when validation gaps are present.

2 / 3

Progressive Disclosure

The body is a concise overview that cleanly offloads detail to a single, clearly-signaled one-level-deep reference ('Load `references/linux-credential-pivot.md` for artifact checklists, replay matrix, and evidence packaging'), and that referenced file exists, matching the level-3 anchor.

3 / 3

Total

10

/

12

Passed

Description

90%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-structured, third-person description with strong trigger-term coverage, explicit use-when guidance, and clear downstream routing. Its main weakness is specificity: it catalogues the domain's artifact types comprehensively but presents the capability as one composite 'workflow' rather than discrete concrete actions.

Suggestions

Convert the composite 'CTF-sandbox workflow for…' framing into a short list of discrete verbs (e.g., 'Recover Linux credential artifacts, prove accepted replay paths, and reconstruct host-to-host pivot chains') to lift specificity toward the level-3 anchor.

Front-load one or two of the most decisive actions before the artifact-type list so the concrete capability is visible in the first sentence.

DimensionReasoningScore

Specificity

The description enumerates concrete domain categories ('Linux credential artifacts, service tokens, SSH material, cloud and container secrets, socket-level trust, and host-to-host pivot chains') but frames the capability as a single abstract 'CTF-sandbox workflow for…' rather than listing multiple discrete actions, matching the 'names domain and some actions, but not comprehensive' anchor rather than the level-3 'lists multiple specific concrete actions' example.

2 / 3

Completeness

It clearly answers 'what' (the CTF-sandbox credential/pivot workflow) and 'when' via an explicit 'Use when the user asks to trace…' clause, satisfying the level-3 'clearly answers both what AND when with explicit triggers' anchor.

3 / 3

Trigger Term Quality

Trigger terms are natural for the security/CTF audience and well covered: 'trace Linux auth artifacts, accepted token or key replay, socket or service-account trust edges, sudo or capability abuse, or explain lateral movement across Linux challenge nodes' — these are phrases a user would plausibly say, matching the level-3 'good coverage of natural terms users would say' anchor.

3 / 3

Distinctiveness Conflict Risk

The explicit 'Internal downstream skill for ctf-sandbox-orchestrator' and 'Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here' carve out a distinct niche with explicit routing, making it unlikely to trigger for the wrong skill.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.