CtrlK
BlogDocsLog inGet started
Tessl Logo

web-discovery

Web app discovery — directory/file fuzzing, vhost discovery, JavaScript endpoint extraction.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/web-recon/discovery/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-organized recon command catalog with strong executable examples and good validation in the alias-probe workflow, with only minor conciseness and progressive-disclosure refinements needed.

Suggestions

Tighten the "Why this is in recon, not exploit" and "Anti-pattern" prose to one line each to improve conciseness.

Add a brief results-triage checkpoint to the directory-fuzzing section (e.g. how to validate and dedupe hits before reporting).

Consider splitting the JavaScript analysis or alias-probe details into a reference file to introduce clear one-level-deep progressive disclosure.

DimensionReasoningScore

Conciseness

The body is a lean command catalog that assumes familiarity with ffuf/curl/grep, but prose sections like "Why this is in recon, not exploit" and the "Anti-pattern" paragraph could be trimmed, fitting the efficient-but-slightly-over anchor 4.

4 / 5

Actionability

It provides fully executable, copy-paste-ready ffuf/curl/grep one-liners and for-loops covering basic fuzzing, extensions, filtering, recursion, throttling, vhosts, alias probing, JS extraction, and source maps, matching the comprehensive anchor 5.

5 / 5

Workflow Clarity

Each section is clearly sequenced and the alias probe includes explicit validation (homepage-size baseline plus a control-file confirmation), but the directory-fuzzing sections lack an explicit results-triage checkpoint, leaving minor validation gaps at anchor 4.

4 / 5

Progressive Disclosure

Content is organized into four numbered, clearly headed sections with no nested references, but it is a single-file monolith over 50 lines with no bundle files to disclose, so it stops short of the well-signaled multi-file anchor 5.

4 / 5

Total

17

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinct, naming three concrete recon activities with some natural trigger terms, but it omits any explicit "Use when..." guidance, which caps its completeness and leaves trigger coverage incomplete.

Suggestions

Add an explicit trigger clause, e.g. "Use when performing web recon: directory/file fuzzing, vhost discovery, or JavaScript endpoint extraction."

Include natural synonyms users say (e.g. "recon", "enumeration", "directory bruteforce") alongside the existing technical terms.

Rephrase actions as verbs (e.g. "Fuzz directories and files, discover virtual hosts, extract endpoints from JavaScript") to lift specificity toward anchor 5.

DimensionReasoningScore

Specificity

Lists three concrete action categories ("directory/file fuzzing, vhost discovery, JavaScript endpoint extraction") but uses noun-phrases rather than verb-driven actions and covers only one JS sub-action, leaving minor gaps versus the comprehensive anchor 5.

4 / 5

Completeness

The description gives a clear "what" but includes no "Use when..." clause or equivalent trigger guidance, which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

"directory/file fuzzing" and "vhost discovery" are natural user phrases, but "JavaScript endpoint extraction" is more technical and common synonyms like recon/enumeration are absent, matching the good-but-incomplete anchor 4.

4 / 5

Distinctiveness Conflict Risk

It targets a clear niche (web app discovery via directory fuzzing, vhosts, and JS) but carries minor overlap risk with closely related recon or subdomain-enumeration skills, fitting anchor 4.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.