CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-relay-coercion-chain

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for forced-auth coercion, relay chains, target selection, NTLM or related acceptance paths, and coercion-to-privilege transitions. Use when the user asks to trace a coercion primitive, follow a relay path, analyze forced authentication, determine which service accepts relayed auth, or connect a coercion step to resulting privilege, enrollment, or code execution. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

71

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured investigative skill body that assumes expertise, gives concrete evidence-gathering guidance, sequences the workflow clearly, and properly offloads detail to one real reference file. Main gap is the absence of an explicit validation/retry loop in the workflow.

Suggestions

Add an explicit validation/retry checkpoint in the Workflow (e.g., 'If relay acceptance cannot be proven, re-isolate the candidate target before claiming downstream privilege') to push workflow clarity toward 5.

Optionally surface one concrete tool or command per coercion source category (e.g., a coerer invocation or capture command) to move actionability from strong guidance to executable.

Trim the opening paragraph that restates the `$ctf-sandbox-orchestrator` dependency already covered in the description to remove the minor conciseness redundancy.

DimensionReasoningScore

Conciseness

Lean checklist-style body that assumes Claude's competence, never explaining what NTLM/coercion/relay are, with every line earning its place; the only mild redundancy is restating the orchestrator dependency already in the description.

5 / 5

Actionability

Concrete, specific guidance with enumerated items to record and concrete examples of what to look for ('service, RPC, file path, printer path, WebDAV edge, or protocol trigger'); as an instruction-only investigative skill it has no literal commands, leaving minor gaps.

4 / 5

Workflow Clarity

Clear sequenced Quick Start (5 steps) and a 3-phase Workflow, with a reproduction checkpoint ('Reproduce the smallest coercion-to-acceptance path that proves the decisive edge'); lacks an explicit fix-retry feedback loop, keeping it just below 5.

4 / 5

Progressive Disclosure

Concise overview body with a single well-signaled, one-level-deep reference ('Load `references/relay-coercion-chain.md` for the coercion checklist, relay checklist, and evidence packaging'), the referenced file exists, and navigation is easy.

5 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-scoped description that clearly states what the skill does and when to use it, with concrete trigger phrases and explicit orchestrator dependency gating. Third-person voice is maintained throughout.

DimensionReasoningScore

Specificity

Lists several concrete investigative actions ('trace a coercion primitive', 'follow a relay path', 'determine which service accepts relayed auth', 'connect a coercion step to resulting privilege, enrollment, or code execution') with clear domain coverage, though the verbs are slightly more abstract than literal operations.

4 / 5

Completeness

Explicitly answers both 'what' ('CTF-sandbox workflow for forced-auth coercion, relay chains, target selection, NTLM or related acceptance paths, and coercion-to-privilege transitions') and 'when' with a concrete 'Use when...' clause listing trigger phrases.

5 / 5

Trigger Term Quality

Good keyword coverage with natural synonyms users would say ('forced-auth coercion', 'forced authentication', 'relay chains', 'relay path', 'relayed auth', 'NTLM'); a few common variations like specific primitive names are absent.

4 / 5

Distinctiveness Conflict Risk

Clear niche (forced-auth coercion relay chains) with distinct triggers and explicit downstream scoping ('Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here') minimizing conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.