CtrlK
BlogDocsLog inGet started
Tessl Logo

web-api-enumeration

REST API discovery, GraphQL detection, parameter fuzzing.

59

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/web-recon/api-enumeration/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is concise, well-structured, and provides concrete executable commands for API enumeration and parameter fuzzing. Its main weakness is the absence of validation/verification steps for the batch fuzzing operations, which caps workflow clarity.

Suggestions

Add a verification step after fuzzing, e.g., manually confirm likely-positive results to filter ffuf false positives before reporting endpoints or parameters.

Replace the '<default_size>' placeholder with guidance on how to obtain the baseline response size (e.g., 'run once without -fs to capture the default size first') so commands are fully copy-paste ready.

Trim the narrative intro sentence to a single purpose statement to push conciseness toward score 5.

DimensionReasoningScore

Conciseness

The body is mostly efficient with concrete ffuf/curl commands and minimal padding; the narrative intro 'This sub-skill covers everything between the directory tree is mapped and I know what to fuzz' is a minor instance of over-explanation that could be trimmed, keeping it just below lean (score 5).

4 / 5

Actionability

Commands are real and executable (ffuf with -mc filters, curl introspection queries), but placeholders like '<default_size>' require the reader to determine the value, a minor gap versus copy-paste-ready score 5.

4 / 5

Workflow Clarity

Sections give a rough sequence (enumerate endpoints, then discover parameters) but lack validation checkpoints, and because ffuf fuzzing is a batch operation the rubric caps workflow_clarity at 3; it is above 2 because a real sequence is present.

3 / 5

Progressive Disclosure

This is a focused, single-purpose skill with no bundle files and a well-organized two-section structure with clear headers, so the simple-skill exception applies and progressive disclosure scores 5 on organization alone.

5 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and uses natural trigger terms for a well-defined API-enumeration niche, but it omits any explicit 'Use when...' guidance, which caps its completeness. Adding trigger conditions would lift it from good to comprehensive.

Suggestions

Append an explicit 'Use when...' clause listing concrete triggers (e.g., 'Use when enumerating API endpoints, finding Swagger/OpenAPI docs, detecting GraphQL, or fuzzing parameters').

Add common synonyms users say — 'endpoints', 'swagger', 'openapi', 'introspection' — to broaden trigger coverage toward score 5.

Consider mentioning file extensions or artifact types (e.g., swagger.json, openapi.yaml) to sharpen distinctiveness from general web fuzzing skills.

DimensionReasoningScore

Specificity

Names the domain (REST/GraphQL) and lists three concrete actions — 'REST API discovery, GraphQL detection, parameter fuzzing' — with only minor coverage gaps, matching the 'several specific actions' anchor rather than the 1-2 actions of score 3.

4 / 5

Completeness

It clearly states what the skill does but contains no 'Use when...' clause or explicit trigger guidance, so per the rubric completeness caps at 3; it is not a 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

'REST API', 'GraphQL', and 'parameter fuzzing' are natural terms a user would say, with good but not exhaustive coverage; missing common synonyms like 'endpoints', 'swagger', or 'openapi' keeps it just below comprehensive (score 5).

4 / 5

Distinctiveness Conflict Risk

The API-enumeration niche is mostly distinct with clear triggers, but 'parameter fuzzing' and general web recon overlap with broader fuzzing skills, leaving minor conflict risk rather than minimal.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.