CtrlK
BlogDocsLog inGet started
Tessl Logo

ctf-sandbox-orchestrator

Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when the user presents challenge infrastructure, binaries, prompts, hosts, or identities that should be treated as sandbox-internal by default and Codex needs to choose, route, and load the right downstream analysis path with concise evidence.

69

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-structured orchestration overview with concrete actionability, a clearly sequenced workflow including verification checkpoints, and sound progressive disclosure through verified one-level references; the main weakness is a verbose inline child-skill list that overlaps the router-matrix reference.

Suggestions

Move or compress the ~40-item inline child-skill enumeration into references/router-matrix.md, keeping only the routing rule in SKILL.md, to remove duplication and tighten conciseness.

Reference the eighth bundle file (ctf-resources-digest.md) from the body or drop it, so every bundle file is discoverable through signaled navigation.

Make the verification checkpoint slightly more concrete (e.g. name the exact reset/reproduce action) to sharpen the already-good workflow clarity.

DimensionReasoningScore

Conciseness

The prose is terse and imperative with no concept-explanation fluff and assumes Claude's competence, but the ~40-item inline child-skill enumeration (lines 69-108) duplicates the router-matrix reference and could be tightened or offloaded, so not every token earns its place.

2 / 3

Actionability

Guidance is concrete and specific for an instruction-only orchestration skill: 'Map the entry surface first: active hosts, routes, processes, storage, artifacts, or binaries', a precise 'What To Record' list, and explicit per-domain reference routing.

3 / 3

Workflow Clarity

A clearly sequenced four-phase Workflow (Establish Sandbox Model, Trace One Minimal Path, Expand By Challenge Type, Verify And Report) with verification/reset checkpoints such as 'Re-run from a clean or reset baseline before calling a path solved' and a re-route feedback loop when the path changes.

3 / 3

Progressive Disclosure

The body is an overview that routes to seven clearly signaled one-level-deep references (e.g. 'Web, API...: read references/web-api.md'), all of which exist as real files, keeping the SKILL.md lean while pushing detail outward.

3 / 3

Total

11

/

12

Passed

Description

82%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong on trigger terms and completeness with an explicit 'Use first when...' clause, but its breadth across roughly thirteen domains dilutes distinctiveness and its actions are abstract orchestration verbs rather than concrete capabilities.

Suggestions

Trim the domain enumeration so the description signals a focused router niche rather than claiming coverage of every security domain, reducing overlap with child skills.

Replace abstract verbs ('choose, route, and load') with one or two concrete capabilities to raise specificity beyond domain-naming.

Consider an explicit scope qualifier (e.g. 'competition/CTF sandbox tasks only') to make the distinctiveness from general security tooling unambiguous.

DimensionReasoningScore

Specificity

Enumerates many domains and orchestration verbs ('choose, route, and load the right downstream analysis path with concise evidence'), but the named actions are abstract routing rather than concrete analysis actions, so it names the domain and some actions without being comprehensive.

2 / 3

Completeness

It clearly states what the skill does (master orchestrator that chooses/routes/loads downstream analysis paths) and provides an explicit 'Use first when the user presents...' trigger clause answering when to use it.

3 / 3

Trigger Term Quality

Natural CTF/security terms a user would actually say are well covered ('CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host'), plus concrete trigger scenarios ('challenge infrastructure, binaries, prompts, hosts, or identities').

3 / 3

Distinctiveness Conflict Risk

It is competition-scoped and framed as the default entrypoint, but its ~13-domain breadth ('CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity') overlaps heavily with the many child skills it lists rather than occupying a single clear niche.

2 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.