CtrlK
BlogDocsLog inGet started
Tessl Logo

thick-client

Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/thick-client/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean thick-client testing playbook with concrete tools, a clear phased workflow, and a real checklist reference. It stops short of copy-paste-ready commands and explicit validation feedback loops.

Suggestions

Add one concrete example command or Frida/Burp snippet in the network or reverse-engineering phase to move actionability from tool-naming toward copy-paste-ready.

Add an explicit validate->fix->retry checkpoint (e.g., re-run a proxy capture and confirm findings before reporting) to strengthen the workflow feedback loop.

Promote the sibling-skill references (../dotnet-reverse/, ../ida-reverse/, etc.) into a clearly signaled 'Related skills' subsection so they read as one-level-deep navigation rather than inline links.

DimensionReasoningScore

Conciseness

Lean checklists, short tables, and terse phase descriptions that assume Claude's competence; the routing-context and self-check blocks add a few tokens that could be trimmed, so not a 5.

4 / 5

Actionability

Concrete tool names (Burp, mitmproxy, dnSpy, IDA, Ghidra, Process Monitor), specific paths (%APPDATA%, Keychain), and named techniques (DLL hijack, cert pinning, asar); instruction-only but actionable, with minor gaps since no exact commands are given.

4 / 5

Workflow Clarity

Clear phased sequence (boundaries -> local -> network -> reverse) plus NOW/NEXT/ACT ordering and a completion self-check that acts as a verification checkpoint; not a 5 because there is no explicit validate->fix->retry feedback loop.

4 / 5

Progressive Disclosure

Overview body points to one real one-level-deep reference (references/thick-client-checklist.md, verified present) that is clearly signaled; sibling-skill links are inline/buried in the 参考 section rather than promoted into clear navigation, keeping it below 5.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-triggered description that clearly carves out the thick-client security-testing niche. The main gap is that the "when" is stated at the domain level rather than via concrete user-facing trigger phrases.

Suggestions

Add concrete user-facing trigger phrases (e.g., 'Use when the user mentions thick-client pentest, desktop/binary app security, DLL hijacking, or client-side trust boundaries') to lift completeness and trigger term quality.

Name a few explicit actions (e.g., 'map trust boundaries, intercept update traffic, bypass client-side checks') rather than only listing surfaces.

DimensionReasoningScore

Specificity

Names the domain ("authorized security testing of desktop thick clients") plus several concrete surfaces ("local storage, update channels, IPC, traffic, and client-side trust boundaries"); not a 5 because the actions are implied rather than enumerated and a few attack surfaces are absent.

4 / 5

Completeness

The "Use for ..." clause answers both what and when in one phrase, but the when is domain-level rather than tied to concrete user trigger phrases, so it is not a 5.

4 / 5

Trigger Term Quality

Includes natural terms users would say ("security testing", "thick clients", "desktop", "IPC", "update channels"); a few common synonyms (e.g., "pentest", "binary", ".exe") are missing, keeping it below 5.

4 / 5

Distinctiveness Conflict Risk

"desktop thick clients" with the listed surfaces is a clear niche with distinct triggers and minimal overlap risk with adjacent web/mobile skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.