CtrlK
BlogDocsLog inGet started
Tessl Logo

web-subdomain-takeover

Subdomain takeover via dangling DNS/CNAME — GitHub Pages, Heroku, Azure, Fastly, Shopify, Netlify, Surge, Tumblr, Beanstalk, Zendesk, etc.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/recon/web-recon/subdomain-takeover/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a lean, highly actionable recon workflow with executable commands end-to-end and a strong decision-gate validation structure; its only weaknesses are minor conciseness trim opportunities and the absence of a true error-recovery feedback loop and bundle-file disclosure.

DimensionReasoningScore

Conciseness

The body is dense and operational — compact command blocks, a high-value provider fingerprint table, and impact context that earns its place — matching 'Efficient; minor instances of over-explanation that could be trimmed'; it is not 5 because breadth sections (defender detection signatures, the full chains table) add material that could be tightened.

4 / 5

Actionability

Enumeration, CNAME extraction, single/mass detection (subjack/subzy/nuclei), and the PoC marker page with a verification curl are all copy-paste ready with real flags, matching 'Fully executable; copy-paste ready code or commands'; per-provider claim steps are deferred to the upstream can-i-take-over-xyz reference with explicit justification.

5 / 5

Workflow Clarity

A clear 1–8 numbered sequence is backed by validation checkpoints — the decision-gate table (section 8), the manual sanity check on hits, and the PoC verify curl — so the destructive/batch cap at 3 does not apply; it is not 5 because there is no explicit validate→fix→retry error-recovery feedback loop.

4 / 5

Progressive Disclosure

Eight well-headed numbered sections plus a clear Cross-references block make navigation easy, and references (upstream can-i-take-over-xyz, sister skills) are one level deep and clearly signaled; it is not 5 because the skill is a single monolithic file with no bundle split, and some breadth content (provider table, chains, defender signatures) is inlined.

4 / 5

Total

17

/

20

Passed

Description

60%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly distinct and uses strong, natural trigger terms with good synonym coverage, but it is a noun phrase that omits concrete actions and lacks an explicit 'Use when…' clause, capping completeness and specificity.

Suggestions

Lead with concrete action verbs (e.g. 'Detects and claims orphaned subdomain tenants via dangling DNS/CNAME') to raise specificity.

Add an explicit 'Use when…' clause naming trigger phrases (e.g. 'Use when investigating dangling CNAMEs, NXDOMAIN providers, or orphaned subdomains in bug-bounty recon') to lift completeness past 3.

Surface a couple of metadata-only trigger terms (NXDOMAIN, orphaned subdomain, subjack/subzy) into the description itself for fuller keyword coverage.

DimensionReasoningScore

Specificity

The phrase 'Subdomain takeover via dangling DNS/CNAME' names the domain richly (with a long concrete provider list) but is a noun phrase with no action verbs, matching 'Names the domain but actions are minimal or generic'; it is not score 1 because the domain is concretely specified, and not score 3 because no discrete actions (e.g. 'detects', 'claims') are stated.

2 / 5

Completeness

The 'what' is clear (the subdomain-takeover subject and providers), but there is no 'Use when…' clause or equivalent explicit trigger guidance, which per the rubric caps completeness at 3; it is not 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

Natural terms users say are well covered with synonyms — 'subdomain takeover', 'dangling DNS', 'dangling CNAME' — plus concrete provider names (GitHub Pages, Heroku, Azure, etc.), matching 'Good keyword coverage; a few natural terms missing'; terms like 'NXDOMAIN', 'orphaned subdomain', and tool names appear only in metadata, keeping it below 5.

4 / 5

Distinctiveness Conflict Risk

'Subdomain takeover via dangling DNS/CNAME' with a specific provider list is a clear niche with distinct triggers and minimal conflict risk against general web-recon or other exploit skills.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.