CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-hunting

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/threat-hunting/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured threat-hunting playbook that respects token budget and lays out a clear workflow with safety gating. Its main weakness is actionability — the query and rule-authoring steps stay at the checklist/pseudocode level rather than providing executable SIEM queries or a complete Sigma example.

Suggestions

Replace the abstract '查询与堆叠' checklist with at least one concrete, copy-pasteable SIEM query (e.g. an ELK/Splunk SPL snippet) for the canonical anomalous-parent-process hypothesis.

Inline a minimal complete Sigma rule skeleton with field mappings instead of a comment pointing to malware-analysis, so detection authoring is self-contained.

Add an explicit validate→fix→retry feedback loop for rule tuning (false-positive triage → adjust logic → replay historical logs) to lift workflow clarity toward 5.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it never explains what Sigma/YARA/SIEM are and uses compact checklists — but carries some structural/navigation overhead (适用场景, 路由上下文) that could be trimmed, placing it at 4 rather than the maximally lean 5.

4 / 5

Actionability

It gives concrete data-source hints (Sysmon 1/3/10, Windows Security 4624/4648) but the query section is an abstract checklist ('基线/异常/关联') with no executable SIEM query, and the Sigma skeleton is only a comment pointer to another skill, matching the 'some concrete guidance but incomplete' anchor.

3 / 5

Workflow Clarity

A clear 4-step sequence (建假说 → 查询 → 规则化 → 验证) with a closing self-check checklist and lab-gated validation steps; not a 5 because validation feedback loops are implicit rather than fully spelled out.

4 / 5

Progressive Disclosure

Well-organized sections with a clearly signaled, one-level-deep reference to references/hunting-loop.md (a real file) plus cross-skill routing pointers; minor organization gaps keep it at 4 rather than 5.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, third-person description that clearly states what the skill covers and when to use it, with strong trigger terms and a distinct security-detection niche. It stops short of the top anchor on every dimension due to minor coverage and overlap gaps rather than any real weakness.

DimensionReasoningScore

Specificity

Names the domain and several concrete activities — 'detection engineering with Sigma/YARA', 'SIEM query design', 'incident detection validation' — with only minor coverage gaps, fitting the 'lists several specific actions' anchor rather than the fully comprehensive 5.

4 / 5

Completeness

Explicit 'Use for…' trigger answers 'when' and the activity list answers 'what'; both are present but the 'when' could be more specific about scenarios, matching the 4 anchor.

4 / 5

Trigger Term Quality

Natural user-facing terms ('blue-team threat hunting', 'Sigma/YARA', 'SIEM') are present with good coverage, though a few common synonyms/extensions are missing, so it sits at 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

The Sigma/YARA/SIEM detection niche is distinct and unlikely to mis-trigger, but it shares detection-engineering surface area with related malware-analysis/forensics skills, so it is 'mostly distinct' at 4 rather than 5.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.