CtrlK
BlogDocsLog inGet started
Tessl Logo

js-reverse

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

62%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured operational skill with a clear five-stage workflow and feedback loops, but it loses points for redundancy across the jshookmcp sections and a referenced bootstrap script that is absent from the bundle.

Suggestions

Resolve the dangling reference: either add scripts/bootstrap-reverse.ps1 or remove/replace the powershell bootstrap command in the '按需自举' section so no referenced path 404s.

De-duplicate the jshookmcp positioning — it is explained in '当前环境默认工具映射', 'jshookmcp 的定位', '路由上下文', and '按需自举'; consolidate into one place.

Condense the 15-line tool-name mapping table (e.g. note the single 'js-reverse_' prefix rule once) to reduce token weight, and surface key tool arguments inline or confirm tool-defaults.md covers them.

DimensionReasoningScore

Conciseness

Mostly operational without explaining basics Claude knows, but the 15-line tool-name mapping table and jshookmcp positioning repeated across four sections ('默认工具映射', 'jshookmcp 的定位', '路由上下文', '按需自举') could be tightened; not a 3 due to this redundancy, not a 1 because it is not padded with conceptual explanation.

2 / 3

Actionability

Gives concrete tool names per workflow stage and a bootstrap command, but the one copy-paste script 'scripts/bootstrap-reverse.ps1' does not exist in the bundle and exact tool arguments are deferred to references; not a 3 because guidance is not fully copy-paste ready, not a 1 because specific tool calls are named.

2 / 3

Workflow Clarity

The five-stage workflow (Observe→Capture→Rebuild→Patch→DeepDive) is clearly sequenced with per-stage goals/rules/outputs, plus a patch→retest feedback loop, a fallback path on failure, and a completion checklist; not a 2 because explicit validation checkpoints are present.

3 / 3

Progressive Disclosure

The 12 references/ files are one-level-deep and clearly signaled with descriptions, but 'scripts/bootstrap-reverse.ps1' is referenced in the bootstrap section and the scripts/ directory is absent — a dangling internal path that breaks easy navigation; not a 3 because a referenced bundle file is missing, not a 1 because the reference set is otherwise well split and organized.

2 / 3

Total

9

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with an explicit use-when trigger, concrete enumerated actions, and a well-bounded niche. Voice is impersonal (no first/second person), so no voice penalty applies.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — '签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出' — matching the 'lists multiple specific concrete actions' anchor; not a 2 because the actions are specific and enumerated rather than just naming a domain.

3 / 3

Completeness

Answers both what (the five reverse-engineering actions) and when via the explicit trigger '在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用'; the 'Use when...' equivalent is present, so it is not capped at 2.

3 / 3

Trigger Term Quality

Covers natural domain terms a reverse-engineering user would say — '前端 JavaScript 逆向', '签名链路', '补环境', '取证', '运行时采样' — alongside tool names; not a 2 because the natural-language domain coverage is broad, not just jargon.

3 / 3

Distinctiveness Conflict Risk

Clear niche (frontend JS reverse) bound to specific tooling (js-reverse_*, jshookmcp) with distinct triggers, making overlap with generic reverse-engineering skills unlikely; not a 2 because the scope is sharply bounded.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.