CtrlK
BlogDocsLog inGet started
Tessl Logo

web-cms-scanning

CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/web-recon/cms-scanning/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is token-efficient and well-structured with executable commands, but workflow guidance is thin: there is no sequencing or output-validation advice beyond the entry trigger, and the Joomla/Drupal coverage is sparse.

Suggestions

Add brief next-step guidance on interpreting scan output (e.g., what to do with enumerated users or detected plugin versions) to raise workflow clarity above the missing-checkpoints anchor.

Expand the Joomla and Drupal sections beyond a single version-detection command to match the depth of the WordPress examples.

DimensionReasoningScore

Conciseness

The body is lean: a single orienting sentence then directly executable commands, with no padding or explanation of what a CMS is, so every token earns its place.

5 / 5

Actionability

Commands are concrete and mostly copy-paste ready (wpscan with enumerate flags, curl one-liners), but the Joomla and Drupal sections each provide only a single thin check, leaving minor gaps in coverage.

4 / 5

Workflow Clarity

An entry condition is given ("Once tech fingerprinting... confirms a CMS, switch...") but there is no sequencing of follow-up steps and no guidance on interpreting output or validating findings, matching the checkpoints-missing anchor.

3 / 5

Progressive Disclosure

The body is under 50 lines, needs no external references, and is organized into clear per-CMS section headers, which per the simple-skill guideline earns a 5 with well-organized sections.

5 / 5

Total

17

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive, naming concrete CMS targets and a tool, but it lacks an explicit 'when to use' trigger clause, which caps its completeness. Trigger-term coverage is strong though not exhaustive.

Suggestions

Append a 'Use when...' clause to the description stating when Claude should reach for this skill (e.g., 'Use when a CMS is confirmed and version/plugin/user enumeration is needed').

Add a few natural trigger synonyms to the description such as 'CMS detection' or 'plugin/theme enumeration' to improve keyword coverage.

DimensionReasoningScore

Specificity

"CMS-specific scans" names the domain and "version detection" is one concrete action, but coverage of plugins/themes/user-enum is only implied, matching the 1-2 concrete actions anchor rather than the comprehensive 5.

3 / 5

Completeness

A clear "what" is present but there is no "Use when..." trigger clause in the description, which per the judging guidelines caps completeness at 3 even though when_to_use exists in metadata.

3 / 5

Trigger Term Quality

Natural terms users would say are present ("WordPress", "wpscan", "Joomla", "Drupal", "CMS-specific scans"), but common variations like "CMS detection" or "plugin enumeration" are absent, so it sits just below the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

The named platforms and tool (WordPress, wpscan, Joomla, Drupal) carve a clear CMS-scanning niche with distinct triggers and minimal overlap with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.