CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-ssrf-metadata-pivot

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for SSRF reachability, internal route probing, metadata-service access, credential pivoting, and token-to-accepted-privilege chains. Use when the user asks to trace SSRF sources, internal hosts, metadata endpoints, link-local tokens, service-account credentials, or explain how a server-side fetch edge turns into accepted access. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, token-efficient instructional skill body: concise, concrete, with a clear sequence of analytical steps and a single properly signaled reference file. It assumes Claude's competence and avoids redundant concept explanations.

DimensionReasoningScore

Conciseness

A lean ~40-line body with no padding or explanation of concepts Claude already knows; every section (Quick Start, Workflow, Preserve) earns its place and assumes competence.

3 / 3

Actionability

For an instruction-only skill the guidance is concrete and specific — e.g. 'Record source primitive: URL parameter, webhook, image fetcher, importer, proxy endpoint, or backend callback' and 'Record token fields, role scope, service account, expiration' give exact things to capture rather than abstract direction.

3 / 3

Workflow Clarity

A clearly sequenced 5-step Quick Start and a 3-phase Workflow with embedded correctness checks ('Distinguish read-only reachability from credential-bearing access', 'Reproduce the smallest SSRF-to-accepted-access path'); no destructive/batch operation is involved so the missing validate-then-retry loop does not cap the score.

3 / 3

Progressive Disclosure

Under 50 lines with a single, clearly signaled one-level-deep reference ('Load references/ssrf-metadata-pivot.md'), which exists in the bundle; the body is an overview, the detail lives in the reference.

3 / 3

Total

12

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, third-person description that states concrete capabilities, gives explicit 'Use when' triggers, and is clearly scoped as a downstream specialization. It avoids verbosity and over-claims while covering the natural terms a CTF user would invoke.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'SSRF reachability, internal route probing, metadata-service access, credential pivoting, and token-to-accepted-privilege chains' — a comprehensive enumeration of specific capabilities rather than vague language.

3 / 3

Completeness

Explicitly answers both: what it does (the workflow capabilities) and when to use it via the 'Use when the user asks to trace...' trigger clause.

3 / 3

Trigger Term Quality

Natural CTF user phrasing is well covered — 'trace SSRF sources, internal hosts, metadata endpoints, link-local tokens, service-account credentials' — these are the terms a user would actually say in this domain.

3 / 3

Distinctiveness Conflict Risk

A clear niche (CTF sandbox SSRF metadata pivot) with distinct triggers and an explicit 'Use only after $ctf-sandbox-orchestrator' guard, making collision with other skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.