CtrlK
BlogDocsLog inGet started
Tessl Logo

active-recon

Active target probing — port scanning, service detection, vulnerability scanning, banner grabbing, web directory fuzzing, SSL/TLS analysis.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/active-recon/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable commands and a clear workflow, but it is a long monolithic reference that duplicates content and lacks validation gates and external detail files.

Suggestions

Remove the "Quick Reference" block or fold it into section 2 to eliminate command duplication and reduce tokens.

Add explicit validation checkpoints in the section 12 workflow (e.g., "Verify open ports before running -sV / NSE").

Move large reference blocks (service-specific enumeration, vulnerability scanning) into separate reference files linked one level deep.

DimensionReasoningScore

Conciseness

The body is mostly tight command references, but the "Quick Reference — Common Scan Patterns" duplicates commands detailed again in section 2, and ~400 lines of inline reference could be trimmed; it is not level 3 because of that redundancy and length.

2 / 3

Actionability

It provides numerous executable, copy-paste-ready commands (nmap, ffuf, nuclei, testssl.sh) with concrete flags and output options, fully matching the executable-guidance anchor.

3 / 3

Workflow Clarity

Section 12 gives a clear 11-step sequence and sections 13–14 add error handling and pitfalls, but there are no explicit validation checkpoints between phases (e.g., confirm open ports before service enumeration), so it sits at 2 rather than 3.

2 / 3

Progressive Disclosure

Content is well-organized into 14 numbered sections, but everything lives inline in a single ~400-line file with no one-level-deep reference files for sizable subsections (service enumeration, vuln scanning); it is above level 1 due to the clear sectioning but below 3 because no detail is split out.

2 / 3

Total

9

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and rich with natural trigger terms, but it omits an explicit "Use when" clause, which limits its completeness score.

Suggestions

Append an explicit trigger clause, e.g. "Use when performing active scans, port/service detection, or vulnerability scanning against targets confirmed in scope."

Consider adding commonly-said tool names (nmap, nuclei, ffuf, testssl) to strengthen natural trigger-term coverage.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions — "port scanning, service detection, vulnerability scanning, banner grabbing, web directory fuzzing, SSL/TLS analysis" — matching the anchor for listing several specific concrete actions.

3 / 3

Completeness

It clearly states what the skill does but lacks any explicit "Use when..." trigger clause; per the rubric a missing explicit trigger guidance caps completeness at 2, and it is not the level below because the "what" is concretely answered.

2 / 3

Trigger Term Quality

Phrases like "port scanning", "service detection", "vulnerability scanning", "banner grabbing", and "SSL/TLS analysis" are natural terms a user would say when requesting active recon, giving good coverage rather than jargon.

3 / 3

Distinctiveness Conflict Risk

"Active target probing" with these specific techniques carves a clear niche distinct from passive recon or web-recon, making unintended triggering unlikely.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.