Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T…
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .claude/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add openocta/openocta_skills --skill djbh-assessment -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .agents/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add openocta/openocta_skills --skill djbh-assessment -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .cursor/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add openocta/openocta_skills --skill djbh-assessment -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .gemini/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add openocta/openocta_skills --skill djbh-assessment -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .github/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add openocta/openocta_skills --skill djbh-assessment -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "djbh-assessment" agent skill from https://github.com/openocta/openocta_skills/tree/main/%E7%AD%89%E4%BF%9D%E6%B5%8B%E8%AF%84skill into .opencode/skills/djbh-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "djbh-assessment", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
djbh-assessment
GitHub stars
167
Token cost
~6.3k tokens
SKILL.md length
440 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT
At a glance
Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T…
Works in 6 steps: 环境: Kali… → 授权: 必须取得客户书面授权书,明确测评范围和允许的操作 → 流程: 严格按六阶段执行——定级确认→差距分析→现场测评→整改建议→复测→报告 → …
Tasks that involve Penetration testing
SKILL.md covers 等保级别速查, 等保2.0安全域全景图, 一、测评全流程(六阶段) and 阶段0:系统定级与备案, plus 6 more sections
Calls curl, python3 and rsync
What it does
Djbh Assessment is an agent skill from openocta/openocta_skills. Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T 22239-2019.
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing. It works with Linux. The repository describes itself as: 本仓库用于汇集第三方贡献的 OpenOcta 技能(Skill)资源,便于分享、版本管理与分发。 The licence is MIT.
When your agent uses it
Tasks that involve Penetration testing
Example prompts
“/djbh-assessment”
Workflow steps
6 steps, taken from the first numbered list in SKILL.md.
1环境: Kali Linux,确保工具已安装(nmap/masscan/sqlmap/hydra/testssl/nikto/nuclei等)
2授权: 必须取得客户书面授权书,明确测评范围和允许的操作
3流程: 严格按六阶段执行——定级确认→差距分析→现场测评→整改建议→复测→报告
4等级区分: 二级侧重网络+计算环境+区域边界;三级在此基础上增加安全管理中心
5三种方法: 每项指标必须通过"访谈+核查+测试"三维交叉验证
6记录留痕: 所有测试操作截图、命令输出均需存档作为测评证据
What it can do on your machine
Read from SKILL.md and the folder at commit 6ac4479. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
curl
python3
rsync
openssl
wget
jq
ssh
redis-cli
bash
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use curl, rsync, wget and ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Djbh Assessment loads about 6.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 440 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~56
When it runs· the whole SKILL.md, loaded when a task matches
~6.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NoteMentions a .env fileSKILL.md:470
# .env泄露
NoteMentions a .env fileSKILL.md:471
curl -s http://<目标IP>/.env
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/djbh-assessment/SKILL.md (or your agent's skills folder).
name
djbh-assessment
description
Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T 22239-2019.
Djbh Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Djbh Assessment compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Djbh Assessment this skillopenocta/openocta_skills
Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.
Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T…. Djbh Assessment is an agent skill from openocta/openocta_skills.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T 22239-2019.
When should I use Djbh Assessment?
Djbh Assessment fits situations like: tasks that involve Penetration testing.
How do I install Djbh Assessment in Claude Code?
Run `npx skills add openocta/openocta_skills --skill djbh-assessment -a claude-code`. Or copy the skill folder (等保测评skill in openocta/openocta_skills) into .claude/skills/djbh-assessment in your project. Claude Code loads it when a task matches its description.
How do I install Djbh Assessment in Codex?
Run `npx skills add openocta/openocta_skills --skill djbh-assessment -a codex`. Or copy the skill folder (等保测评skill in openocta/openocta_skills) into .agents/skills/djbh-assessment in your project. Codex loads it when a task matches its description.
Can I use Djbh Assessment in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openocta/openocta_skills --skill djbh-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/djbh-assessment, .gemini/skills/djbh-assessment, .github/skills/djbh-assessment and .opencode/skills/djbh-assessment in your project.
What does Djbh Assessment need to run?
Going by SKILL.md and its folder, Djbh Assessment needs the command-line tools its instructions call (curl, python3, rsync, openssl, wget and jq).
Does Djbh Assessment access the network?
SKILL.md contains no URLs. Its commands use curl, wget and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Djbh Assessment safe to install?
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Djbh Assessment use?
Djbh Assessment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Djbh Assessment use?
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Djbh Assessment?
Skills that share tags, products or a category with Djbh Assessment: Detecting T1548 Abuse Elevation Control Mechanism (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Network Scanner (ptn1411/skill, 219 stars), Code Audit (3stoneBrother/code-audit, 892 stars) and Fix Strix Security Findings (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Djbh Assessment?
openocta (a GitHub user) maintains it in openocta/openocta_skills, which has 167 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 22, 2026.
Source: openocta/openocta_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.