CtrlK
BlogDocsLog inGet started
Tessl Logo

domain-intel

Passive recon of subdomains, SSL certs, WHOIS, and DNS.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./optional-skills/research/domain-intel/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable CLI wrapper: every command is copy-paste ready with real examples, and the comparison tables help pick the right tool. The main gaps are duplicated caveat text and the absence of any error-handling/retry guidance for the batch and network-dependent operations, which caps workflow clarity.

Suggestions

Add a short error-handling/retry section: what to do on crt.sh timeouts, blocked port 43, or empty WHOIS responses (e.g. retry, fall back to DoH-only signals, report partial results) so the bulk/batch workflow has validation checkpoints.

De-duplicate the TCP-43 and 'only active operation' caveats — state them once (Platform compatibility or Notes, not both).

Include one sample JSON output block (or a pointer to it in a reference file) so consumers of the structured output know its shape before running bulk analysis.

DimensionReasoningScore

Conciseness

The body is command-first with no concept explanations Claude already knows, and the SKILL_DIR convention is explained in one line — matching 'efficient; minor instances that could be trimmed'. Not 5 because of duplication: "WHOIS queries use TCP port 43 — may be blocked" appears in both Platform compatibility and Notes, and "SSL check is the only 'active' operation" is stated twice.

4 / 5

Actionability

Every command has a copy-paste-ready invocation with a concrete example domain (e.g. `python SKILL_DIR/scripts/domain_intel.py ssl example.com`, plus `bulk example.com github.com --checks ssl,dns`), and the table maps each command to its data source — fully executable and covering all common cases, matching the 5 anchor.

5 / 5

Workflow Clarity

Each single lookup is unambiguous, but the skill explicitly offers batch operations (`bulk` across multiple domains with parallel workers) and provides no validation, error-handling, or retry guidance — e.g. what to do when crt.sh times out or WHOIS port 43 is blocked. Per the rubric, missing validation in batch-operation workflows caps workflow clarity at 3, overriding the simple-skill exception.

3 / 5

Progressive Disclosure

The body is well-sectioned with headers and the single bundle file (scripts/domain_intel.py) exists and is referenced accurately in place; no nested or dead references. Not 5 because the ~90-line body inlines material (e.g. the full tool-selection table and usage caveats) that could sit in a one-level-deep reference, and there are no signposted reference docs for deeper detail like output-schema examples.

4 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, specific description that clearly names its domain and four concrete capability areas with distinct, natural trigger terms. Its main weakness is the missing 'Use when...' guidance, which caps completeness at 3 and leaves triggering to inference from the capability list.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user asks about subdomains, certificate expiry, domain registration/WHOIS, or DNS records, or wants to check whether a domain is available."

Mention the domain-availability check and bulk multi-domain mode in the description so those capabilities are discoverable at trigger time.

Use action verbs ("Enumerate subdomains via Certificate Transparency, inspect SSL certificates, query WHOIS...") to sharpen the what-it-does statement.

DimensionReasoningScore

Specificity

"Passive recon of subdomains, SSL certs, WHOIS, and DNS" enumerates four concrete capability areas with a named method ("passive recon"), matching the 'lists several specific actions; minor gaps in coverage' anchor. It falls short of 5 because capabilities are named as objects rather than actions (no verbs like 'enumerate', 'inspect', 'query') and coverage gaps exist (domain availability, bulk analysis).

4 / 5

Completeness

The 'what' is clear (passive recon across four enumerated areas), but there is no 'Use when...' clause or equivalent explicit trigger guidance — the guideline caps completeness at 3 for this. It is above 2 because the 'what' half is concrete and specific, not vague.

3 / 5

Trigger Term Quality

"subdomains", "SSL certs", "WHOIS", and "DNS" are natural phrases users would say when needing this skill, giving good keyword coverage. Not 5 because common variations are missing — "domain availability", "certificate transparency", "domain registration", and file-extension/verb synonyms of the kind the 5-anchor requires.

4 / 5

Distinctiveness Conflict Risk

"Passive recon" + the specific OSINT data sources carve out a clear niche unlikely to grab general research or file-processing skills, matching 'mostly distinct; minor overlap risk'. Not 5 because bare "DNS" and "recon" could collide with networking or broader security-recon skills.

4 / 5

Total

15

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
NousResearch/hermes-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.