CtrlK
BlogDocsLog inGet started
Tessl Logo

common-dast-tooling

Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on local/staging environments.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.github/skills/common/common-dast-tooling/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured DAST standard that uses progressive disclosure effectively via the implementation reference. Its main weakness is the absence of a sequenced scan workflow with validation checkpoints, which is important for batch/destructive scanning operations.

Suggestions

Add a short ordered scan workflow (scope target -> authenticate -> run passive then active scans -> triage findings -> confirm before reporting) with explicit validation/checkpoint steps, since DAST scanning is a batch operation that should be capped above 3 only with validation.

Include a few key inline executable command snippets for the highest-value tools rather than deferring all commands to the reference, to improve actionability of the body itself.

Replace the standalone '## Priority: P1 (HIGH)' line with inline labeling or fold the scoring-impact table into the reference to trim non-essential tokens.

DimensionReasoningScore

Conciseness

Largely lean bullet lists that assume Claude's knowledge (e.g. 'Nuclei: Fast, template-based CVE/misconfiguration scanning'), with only minor non-essential tokens like the standalone 'Priority: P1 (HIGH)' header and the scoring-impact table.

4 / 5

Actionability

The body lists tools and targets but defers nearly all executable commands to references/implementation.md; the inline curl-probing paths are concrete, yet most sections give descriptive rather than copy-paste-ready guidance.

3 / 5

Workflow Clarity

Content is organized as a reference (rules -> tools by surface -> scoring -> anti-patterns) rather than a sequenced scan workflow, and there are no validation checkpoints; since active DAST scanning is a batch/destructive operation, the missing validation caps this at 3.

3 / 5

Progressive Disclosure

The body acts as an overview and clearly signals a real one-level-deep reference ('See [implementation guide](references/implementation.md)') that exists and holds the detailed commands, though the same file is referenced twice and some inline material could be delegated.

4 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-constructed description that answers both 'what' and 'when' explicitly with concrete trigger phrasing and a distinct DAST niche. Minor gains are possible by adding a few more user-natural synonyms (e.g. 'pentest', 'vulnerability scan').

DimensionReasoningScore

Specificity

Names the DAST domain plus several concrete actions ('Standardize dynamic application security testing', 'advising on or running dynamic security scans') and enumerates specific tools, but the core verbs are limited so it sits just below comprehensive.

4 / 5

Completeness

Explicitly states what it does (standardize DAST across backend/frontend/mobile covering named tools) and when to use it ('Use when advising on or running dynamic security scans on local/staging environments') with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Strong natural coverage ('DAST', 'dynamic security scans', 'local/staging') plus named tools users would say, though a few common phrasings like 'pentest' or 'vulnerability scan' are absent from the description itself.

4 / 5

Distinctiveness Conflict Risk

A clearly scoped DAST niche with distinct tool-name triggers (ZAP, Nuclei, sqlmap, ffuf) makes overlap with unrelated skills minimal.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
HoangNguyen0403/agent-skills-standard
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.