CtrlK
BlogDocsLog inGet started
Tessl Logo

attack-surface-recon

侦察/攻击面测绘:被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei,DNS地域/CDN/Nginx catch-all/宝塔/UniApp指纹。开局第一动作,认知写入项目黑板。Use when starting recon, asset mapping, fingerprinting, or CDN/DNS bypass discovery.

71

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally lean and actionable recon runbook with concrete commands and valuable non-obvious operational discriminators throughout. Its main defects are the two reference pointers to nonexistent files and the absence of markdown-level structure and explicit validation checkpoints for what is a batch-oriented scanning workflow.

Suggestions

Create references/nginx-404-differential-fingerprinting.md and references/uniapp-dcloud-apk-reversing.md (or remove the '详见' pointers) — both referenced paths are missing from the bundle, breaking navigation.

Move the 🚨 technique sections out of the single fenced code block into markdown sections (or separate reference files) so the passive-first and active-pipeline runbook reads as an overview with one-level-deep detail.

Add explicit validation checkpoints to the active pipeline (e.g., verify catch-all/wildcard-DNS conditions before launching ffuf or subdomain enumeration, and confirm findings from nuclei against httpx output) to give the batch scanning workflow a validate-then-proceed loop.

DimensionReasoningScore

Conciseness

A telegraphic runbook where every line is either an executable command or a hard-won operational fact (e.g., '502≠不存在: 502=后端响应被CDN过滤, 404=路径真不存在'); there is no padding and no explanation of concepts Claude already knows.

5 / 5

Actionability

Commands are copy-paste ready with flags and output plumbing ('subfinder -d {domain} -silent | tee subs.txt', 'nmap -sCV -iL <(head -20 alive_subs.txt)'), and the trap sections give concrete discriminators (502/404/403 differential, '真实nginx 404(146B)') that cover the common cases.

5 / 5

Workflow Clarity

The sequence is clear (passive-first '全部执行', then '主动流水线(逐步执行)', then the component-vuln-intel handoff) with embedded verification discriminators (random-path catch-all check, wildcard-DNS random-subdomain check). It falls short of 5 because for a batch scanning/brute-force workflow the validation logic lives inside technique notes rather than explicit checkpoints, and ordering is implied by layout inside a single code block rather than enumerated steps.

4 / 5

Progressive Disclosure

The body is a single fenced code block with no markdown sections, and its two clearly-signaled references ('详见references/nginx-404-differential-fingerprinting.md', 'references/uniapp-dcloud-apk-reversing.md') point to files that do not exist in the bundle, leaving navigation broken. This fits the 'some structure but references defective / content that should be separate is inline' anchor rather than the 'minor organization gaps' level, since missing referenced files are more than a minor gap.

3 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, tool-enumerating description with an explicit bilingual 'what' and a clean English 'Use when' trigger clause. The only weakness is trigger-term coverage, which misses several natural English synonyms for the recon domain.

DimensionReasoningScore

Specificity

The description lists concrete tool chains for each phase ('被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei') plus specific technique targets (DNS地域/CDN/Nginx catch-all/宝塔/UniApp指纹), matching the comprehensive-coverage anchor rather than the 'minor gaps' level.

5 / 5

Completeness

Both parts are explicit: the 'what' enumerates passive/active recon tools and fingerprinting techniques, and the 'when' gives concrete trigger phrases ('Use when starting recon, asset mapping, fingerprinting, or CDN/DNS bypass discovery').

5 / 5

Trigger Term Quality

The 'Use when' clause provides good natural triggers ('recon, asset mapping, fingerprinting, or CDN/DNS bypass discovery'), but common variations a user would say ('OSINT', 'subdomain enumeration', 'port scanning', 'attack surface') are missing, and the mostly-Chinese body keywords won't match English user phrasing.

4 / 5

Distinctiveness Conflict Risk

Offensive recon/attack-surface mapping is a clear niche with distinct triggers, unlikely to fire for adjacent skills (the referenced component-vuln-intel is a separate, later-stage trigger).

5 / 5

Total

19

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

referenced_paths_exist

Referenced path issues: 4 missing, 1 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.