CtrlK
BlogDocsLog inGet started
Tessl Logo

thick-client

Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/thick-client/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-sequenced overview with a real one-level-deep reference and a completion checklist, but its guidance stays at the checklist/tool-naming level rather than providing executable commands.

Suggestions

Add one or two concrete, copy-paste-ready commands per workflow phase (e.g. a Frida invocation for cert pinning, a Sysinternals command for port/process enumeration) to lift actionability from checklist prompts to executable guidance.

Optionally show an example command for DLL hijack probing or asar unpacking so the tool table's named tools have a runnable entry point.

DimensionReasoningScore

Conciseness

The body is lean checklist-and-table form ('□ 明文配置、硬编码密钥、调试开关', a compact tool table) with no explanation of concepts Claude already knows, so every token earns its place and it assumes competence.

3 / 3

Actionability

Concrete inspection targets and named tools appear ('Burp', 'dnSpy', 'asar', 'Frida'), but guidance is checklist prompts and tool names rather than executable, copy-paste-ready commands, matching 'some concrete guidance but incomplete'.

2 / 3

Workflow Clarity

A clearly sequenced four-phase workflow (建边界 → 本地攻击面 → 网络面 → 逆向验证) plus a '任务完成自检' completion checklist provide the explicit sequence and validation checkpoint the anchor-3 example expects.

3 / 3

Progressive Disclosure

The body is an overview that signals one real one-level-deep reference ('references/thick-client-checklist.md', verified present) under a '## 参考' section, with content appropriately split between SKILL.md and the bundle file.

3 / 3

Total

11

/

12

Passed

Description

75%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive with an explicit 'Use for' trigger that answers both what and when, though it lists attack surfaces rather than distinct action verbs and omits common user-facing keyword variants.

Suggestions

Lead with concrete action verbs (e.g. 'enumerate, intercept, and bypass') so the description lists multiple specific actions rather than one verb plus a list of surfaces.

Add natural keyword variants users actually say ('desktop app', 'Electron/Qt/.NET client', 'client-server') alongside the jargon terms to improve trigger coverage.

DimensionReasoningScore

Specificity

Names the domain ('authorized security testing of desktop thick clients') and concrete surfaces ('local storage, update channels, IPC, traffic, and client-side trust boundaries'), but surfaces are nouns rather than the multiple distinct action verbs the anchor-3 example requires, so it sits at anchor 2 not 3.

2 / 3

Completeness

The 'Use for authorized security testing of desktop thick clients...' clause provides explicit trigger guidance (the rubric only caps at 2 when such a clause is missing) and states what the skill does, so both what and when are clearly answered.

3 / 3

Trigger Term Quality

'desktop thick clients' is a term a user would naturally say, but 'IPC' and 'client-side trust boundaries' are jargon and common variations (e.g. 'desktop app', 'Electron', 'client-server') are absent, matching 'some relevant keywords but missing common variations' rather than full coverage.

2 / 3

Distinctiveness Conflict Risk

'desktop thick clients' anchored on local storage/IPC/update channels is a clear niche distinct from web or API security skills, making unintended triggering unlikely.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.