CtrlK
BlogDocsLog inGet started
Tessl Logo

common-dast-tooling

Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on local/staging environments.

69

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, token-efficient overview that progressively discloses executable commands into a real reference file. Its main gaps are the absence of an explicit sequenced scanning workflow with validation checkpoints and the lack of any executable commands in the body itself.

Suggestions

Add a short ordered scanning workflow (e.g. 1. scope/recon on local/staging, 2. run authenticated scans with max-depth/max-duration, 3. triage findings against the Scoring Impact table, 4. verify/reproduce before reporting) with explicit validation checkpoints, since these are batch/risky operations.

Include at least one or two copy-paste executable command examples inline in the body (e.g. a representative nuclei or zap-cli invocation) rather than deferring all commands to implementation.md.

Clarify or remove the 'Priority: P1 (HIGH)' header, which is not explained in the body and adds noise without context.

DimensionReasoningScore

Conciseness

A lean tool catalog with one-line role descriptions, safety rules, a compact scoring table, and anti-patterns; it avoids explaining concepts Claude already knows and nearly every line earns its place. The unexplained 'Priority: P1 (HIGH)' header is the only mild noise, not enough to drop below the lean/efficient anchor.

3 / 3

Actionability

The body gives concrete specifics (exact endpoints like '/metrics', '/.env', '/api-docs', headers like 'X-Forwarded-For', JWT variants) but no executable copy-paste commands — those are deferred to references/implementation.md, so guidance is concrete but incomplete in the body itself.

2 / 3

Workflow Clarity

Content is organized by tool category with safety guardrails ('Always-Apply Rules'), but there is no sequenced scan workflow (recon -> scan -> triage -> verify) and no explicit validation/verification checkpoints for these batch/risky scanning operations, capping it at 2.

2 / 3

Progressive Disclosure

Clear overview body pointing to a real one-level-deep reference (references/implementation.md, verified present) signaled both inline and in a References section, with content appropriately split between overview and command detail.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that covers a concrete capability set, surfaces natural trigger terms, and explicitly states both what it does and when to use it. It is concise without vagueness or over-claiming.

DimensionReasoningScore

Specificity

Names the domain (DAST for backend APIs, frontend web apps, mobile clients) and lists multiple concrete tools and surfaces (ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, AI-driven curl probes), matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly states what it does ('Standardize dynamic application security testing...') and when to use it ('Use when advising on or running dynamic security scans on local/staging environments'), satisfying both the what and the when with an explicit trigger.

3 / 3

Trigger Term Quality

Includes natural terms a user would say when needing this skill — 'DAST', 'dynamic security scans', 'ZAP', 'Nuclei', 'Nikto', 'sqlmap', 'ffuf' — giving good coverage rather than jargon-only phrasing.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (dynamic security testing tooling) with distinct, specific triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
HoangNguyen0403/agent-skills-standard
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.