CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-mailbox-abuse

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for enterprise mail abuse, OAuth consent, inbox or forwarding rules, transport rules, shared mailbox access, phishing chains, and token-to-mailbox side effects. Use when the user asks to trace mailbox rules, OAuth consent grants, forwarding or delegate abuse, shared mailbox access, message-trace evidence, or explain how mail artifacts turn into persistence, exfiltration, or privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured investigative skill body: concise, actionable, with a clear sequenced workflow, a prove-it verification step, and a single clearly-signaled reference file that exists in the bundle.

DimensionReasoningScore

Conciseness

Lean and efficient with no padding or explanation of concepts Claude already knows; every line is investigative guidance that earns its place, matching the 'lean and efficient; assumes Claude's competence' anchor.

3 / 3

Actionability

Although there is no code (appropriate for an instruction-only analytical skill), the guidance is concrete and specific — 'Correlate consent logs, sign-ins, message traces, inbox rules...' and 'Compress the path to the smallest sequence: lure or grant -> token or delegate edge -> mailbox or transport mutation -> resulting mail effect' — meeting the actionable standard without being penalized for absent code.

3 / 3

Workflow Clarity

A clear three-step sequence (Map -> Prove -> Reduce) with an explicit verification checkpoint in Quick Start step 5 ('Reproduce the smallest mail effect that proves persistence, exfiltration, or privilege'); for a simple analytical skill this satisfies the 'clear sequence with explicit validation steps' anchor.

3 / 3

Progressive Disclosure

Under 50 lines and well-organized into clear sections, with a single one-level-deep, clearly signaled reference to references/mailbox-abuse.md (verified to exist) — meeting the 'well-organized sections' allowance for short skills.

3 / 3

Total

12

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-scoped description that explicitly states capabilities, provides natural trigger terms, answers both what and when, and clearly distinguishes itself from sibling skills via explicit downstream-only routing.

DimensionReasoningScore

Specificity

Names multiple concrete surfaces and actions — 'OAuth consent, inbox or forwarding rules, transport rules, shared mailbox access, phishing chains' and verbs 'trace'/'explain how mail artifacts turn into persistence, exfiltration, or privilege' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers both what (the CTF-sandbox mail-abuse workflow and its surfaces) and when, via an explicit 'Use when the user asks to trace...' trigger clause, satisfying the 'clearly answers both what AND when' anchor.

3 / 3

Trigger Term Quality

Includes natural phrasings a user would say — 'trace mailbox rules, OAuth consent grants, forwarding or delegate abuse, shared mailbox access, message-trace evidence' — giving good coverage of common variations rather than just a single keyword.

3 / 3

Distinctiveness Conflict Risk

The niche is sharply bounded — 'Internal downstream skill for ctf-sandbox-orchestrator' and 'Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here' — making it unlikely to trigger for the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.