CtrlK
BlogDocsLog inGet started
Tessl Logo

passive-recon

Passive intelligence gathering without touching the target — DNS, WHOIS, subdomain enumeration, Certificate Transparency, technology fingerprinting, ASN mapping.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/passive-recon/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a dense, highly actionable passive-recon knowledge base with copy-paste commands, a clear sequenced workflow, validation via wildcard filtering and a decision-gate checklist, and well-signaled one-level-deep bundle references. Its only weaknesses are mild verbosity from Quick-Reference duplication and the lack of an explicit validate-retry loop in the main workflow.

DimensionReasoningScore

Conciseness

The body is mostly commands and tight analysis bullets that earn their tokens, but the Quick Reference duplicates commands restated in later sections and a few lines restate basics Claude knows (e.g. "CT logs are a public, immutable record"), leaving minor trim opportunities that keep it below anchor 5.

4 / 5

Actionability

It provides copy-paste-ready, executable commands throughout (whois, dig, subfinder, amass, crt.sh curl, httpx pipelines) plus a full workflow block, an error-handling table with specific fixes, and a wildcard-detection script, fully covering the common cases.

5 / 5

Workflow Clarity

A numbered 9-step recon sequence, a decision-gate checklist, wildcard/false-positive validation, and an error-handling table give clear sequencing with most checkpoints present; it stops short of anchor 5 because the main workflow lacks an explicit validate→fix→retry feedback loop for its batch operations.

4 / 5

Progressive Disclosure

The body is well-sectioned and the Bundled Resources block clearly signals one-level-deep resources (references/dns-techniques.md and scripts/parse_subdomains.py) with usage; minor duplication between the body and the reference file and a dense inlined overview keep it just below anchor 5.

4 / 5

Total

17

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped, naming six concrete passive-recon techniques and clearly distinguishing passive from active/OSINT work. Its main weakness is the absence of an explicit "Use when..." trigger clause inside the description field, which limits completeness.

Suggestions

Append an explicit trigger clause to the description, e.g. "Use when the user asks for passive recon, WHOIS/DNS lookups, subdomain enumeration, certificate transparency, or ASN/tech fingerprinting without touching the target."

Add a couple of natural-language synonyms users actually say ("find subdomains", "DNS lookup", "passive footprinting") to broaden trigger-term match quality.

Reframe one or two capability nouns as verb phrases (e.g. "enumerate subdomains", "map ASNs") to push specificity toward the comprehensive anchor.

DimensionReasoningScore

Specificity

The description enumerates six concrete capability areas ("DNS, WHOIS, subdomain enumeration, Certificate Transparency, technology fingerprinting, ASN mapping"), giving broad coverage, though they are noun phrases rather than verb-actions, keeping it just below the comprehensive anchor 5.

4 / 5

Completeness

It clearly states what the skill does (passive intelligence gathering across six techniques) but lacks an explicit "Use when..." clause in the description itself; per the rubric, a missing explicit trigger clause caps completeness at 3 even though metadata.when_to_use carries triggers elsewhere in the frontmatter.

3 / 5

Trigger Term Quality

It surfaces natural terms a user would say ("DNS", "WHOIS", "subdomain", "passive intelligence gathering") with good coverage, but leans technical ("Certificate Transparency", "ASN mapping") and omits a few common synonyms like "find subdomains" or "DNS lookup".

4 / 5

Distinctiveness Conflict Risk

The "passive" framing plus the specific technique list carves a clear niche distinct from active recon, and the skill explicitly boundaries itself against an `osint` skill, leaving only minor overlap risk with general recon skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.