CtrlK
BlogDocsLog inGet started
Tessl Logo

digital-forensics

Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/digital-forensics/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-structured forensics workflow with executable Volatility commands, preservation-first validation, and a properly split one-level reference file. The main gaps are checklist-style (non-executable) guidance in the host and network phases and the absence of explicit error-recovery feedback loops.

Suggestions

Add executable commands for the host-artifact and network phases (e.g. tshark and EvtxECmd/PECmd invocations) alongside the checklists.

Add an explicit feedback loop for evidence integrity, e.g. 'If SHA256 of the working copy differs from the acquisition hash, stop and re-image.'

Trim the 路由上下文 routing metadata (上游/下游, MASTER R25) or move it to the reference file, since it does not advance the forensics task.

DimensionReasoningScore

Conciseness

The body is dense and checklist-driven with no concept padding and assumes Claude knows the tools, but the 路由上下文 routing metadata and slight overlap between 适用场景 and 工作流 are tokens that do not directly advance the forensics task.

4 / 5

Actionability

The memory section gives copy-paste Volatility 3 commands ('vol -f mem.dmp windows.pslist', etc.) and host/network sections give concrete artifact lists, but network and host-artifact guidance is checklist-style rather than full executable commands.

4 / 5

Workflow Clarity

A clear four-phase sequence (保全→内存→主机伪影→网络) opens with hash/read-only preservation as a validation checkpoint and ends with a completion self-check, but it lacks explicit error-recovery feedback loops (e.g. hash-mismatch handling).

4 / 5

Progressive Disclosure

Well-organized into clear sections with a well-signaled one-level-deep reference (references/forensics-triage.md, verified to exist) holding the detailed triage ordering and output template, keeping the body as an overview with easy navigation.

5 / 5

Total

17

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and distinct, cleanly scoping an authorized forensics niche with multiple concrete capability areas. Its main weakness is that 'what' and 'when' are fused into one sentence and it omits common synonyms and file extensions that would sharpen triggering.

Suggestions

Split into a capability clause and an explicit trigger clause, e.g. 'Use when the user mentions memory dumps, .pcap files, disk/E01 timelines, or IR evidence preservation.'

Add natural synonyms and file extensions (.pcap, .E01, Volatility, Plaso) to improve trigger-term coverage.

Keep the 'authorized' qualifier but pair it with a concrete trigger example so the when-condition is unambiguous.

DimensionReasoningScore

Specificity

Lists several concrete capability areas ('memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation') but they are domain-level tasks rather than fine-grained actions, leaving minor coverage gaps.

4 / 5

Completeness

Answers both 'what' (the listed forensics tasks) and 'when' ('Use for authorized digital forensics...') in a single merged clause, but the 'when' is a general context rather than a rich enumerated trigger phrase set.

4 / 5

Trigger Term Quality

Includes natural terms a forensics user would say ('digital forensics', 'memory dumps', 'PCAP investigation', 'IR evidence preservation'), but misses common synonyms and file extensions such as .pcap, E01, or Volatility.

4 / 5

Distinctiveness Conflict Risk

Targets a clear niche ('authorized digital forensics') with forensics-specific triggers (evidence preservation, PCAP, disk timelines) and an explicit authorization qualifier, giving minimal conflict risk with adjacent IR skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.