CtrlK
BlogDocsLog inGet started
Tessl Logo

common-dast-tooling

Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on local/staging environments.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.github/skills/common/common-dast-tooling/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured overview with excellent progressive disclosure — commands are correctly deferred to a real, complete one-level-deep reference file. Its weaknesses are that the body itself contains no executable commands (actionability lives entirely in the reference) and that it is a tool catalog rather than a sequenced scanning workflow, with no validation checkpoints despite governing risky batch scanning operations.

Suggestions

Add a short sequenced workflow (identify target surface → confirm it is local/staging → run capped scan → triage report → apply the scoring table), with an explicit validation step that the target is not production before any scan starts.

Inline one or two copy-paste examples (e.g., a nuclei or ffuf invocation with the required cap flags) so the body is actionable without opening the reference.

Deduplicate the three links to references/implementation.md into the References section and drop the 'Priority: P1 (HIGH)' heading to tighten token use.

DimensionReasoningScore

Conciseness

The body is lean — one-line tool bullets ('Fast, template-based CVE/misconfiguration scanning'), guardrail rules ('Never run DAST tools against live production environments'), a scoring table, and anti-patterns, with no explanations of concepts Claude already knows. It is not 5 because of small redundancies: the link to references/implementation.md is repeated three times ('See [implementation guide](references/implementation.md)' twice plus the References section), and the 'Priority: P1 (HIGH)' heading adds little.

4 / 5

Actionability

The body gives concrete direction (specific tools, probe targets like '/metrics, /health, .git, /.env, /api-docs', headers like 'X-Forwarded-For'), but contains no executable commands itself — every command is deferred via 'See [implementation guide](references/implementation.md) for all commands', and tool bullets only describe rather than instruct. This matches the anchor 'Some concrete guidance but incomplete... missing key details' rather than 4, because a reader of the body alone could not execute a scan without opening the reference.

3 / 5

Workflow Clarity

The content is organized by tool category rather than as a sequenced process — there is no 'select target → run scan → triage findings → score' workflow and no validation checkpoints (e.g., verify the target is staging before scanning). The Always-Apply rules ('No Scanning Production... Use local or staging replicas only', 'Always set max-depth or max-duration') act as guardrails, which keeps this above 2, but DAST is a risky batch operation and the rubric caps workflow clarity at 3 without explicit validation steps, which is the binding constraint here.

3 / 5

Progressive Disclosure

The body is a well-organized overview (rules, tool catalog by platform, scoring table, anti-patterns) and all executable commands are appropriately split into references/implementation.md, which exists (verified in the bundle) and is referenced one level deep with clear signaling in three places. This matches the anchor 'Clear overview with well-signaled one-level-deep references; content appropriately split'.

5 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states what it does with concrete named tools across three target domains, and gives an explicit 'Use when' clause scoping it to local/staging dynamic scans. The only gap is that widely-used natural synonyms like 'DAST' and 'pentest' appear only in the metadata triggers rather than the description text.

Suggestions

Include the 'DAST' acronym and common synonyms like 'pentest' or 'vulnerability scanning' directly in the description text so users who type those terms trigger the skill.

Consider naming the mobile proxy tools (mitmproxy, Burp) in the description the way the web tools are named, for symmetry and better keyword coverage.

DimensionReasoningScore

Specificity

The description names multiple concrete capabilities across three named domains — 'backend APIs, frontend web apps, and mobile clients' — and enumerates specific tooling ('ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes'). This matches the anchor 'Lists multiple specific concrete actions; comprehensive coverage'; it is not score 4 because coverage of the domains and tools is comprehensive rather than having minor gaps.

5 / 5

Completeness

It explicitly answers what ('Standardize dynamic application security testing... Covers ZAP, Nuclei...') and when ('Use when advising on or running dynamic security scans on local/staging environments') with concrete trigger phrases. This is a clear match for the anchor 'Clearly and explicitly answers both what AND when'; not 4, because the 'when' clause is explicit and specific rather than generic.

5 / 5

Trigger Term Quality

Natural terms like 'dynamic security scans', 'security testing', and tool names (ZAP, sqlmap, ffuf) are present and would be said by users needing this skill. It falls short of 5 because common synonyms such as 'DAST' (the acronym users actually type), 'pentest', 'penetration testing', and 'vulnerability scan' are absent from the description itself (they only appear in the metadata triggers).

4 / 5

Distinctiveness Conflict Risk

The niche is clear — dynamic (not static) security scanning with named tools — and the 'Use when' clause scopes it to advising/running scans on local/staging environments, giving minimal conflict risk with other security or browser-automation skills. Not 4, because the dynamic-vs-static framing and specific tool names leave virtually no overlap ambiguity.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
HoangNguyen0403/agent-skills-standard
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.