CtrlK
BlogDocsLog inGet started
Tessl Logo

security-pen-testing

Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.

68

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured skill body with executable commands and clean progressive disclosure to real reference files. The main gap is the absence of explicit validation/verification checkpoints in the multi-day pen-test workflows, which the rubric caps at 3 for destructive/batch operations.

Suggestions

Add explicit validation checkpoints to the pen-test workflows — e.g., 'Verify authorization scope before each testing phase' and 'Confirm scan output is complete before triaging', with a fix-and-retry loop on scan failures.

Trim restated common knowledge (CFAA explanation, OWASP category definitions Claude already knows) to tighten the token budget further.

Add a verify/rerun step in the dependency triage workflow (step 5 'Verify' exists, but mirror that pattern with explicit commands in the CI/CD gate and secret-scan workflows).

DimensionReasoningScore

Conciseness

Largely efficient with tables and terse command blocks assuming Claude's competence, but a few sections restate well-known context (e.g., explaining what CFAA/authorization means, restating OWASP categories Claude already knows) that could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready, executable commands throughout ('python scripts/vulnerability_scanner.py --target web --scope full', 'trufflehog git file://. --only-verified --json') plus a concrete findings JSON schema covering the common cases.

5 / 5

Workflow Clarity

Workflows are clearly sequenced (Day 1/2/3, numbered steps), but destructive/offensive operations and batch scans lack explicit validation checkpoints — e.g., no 'verify scan completed / confirm authorization before each phase' feedback loop, so the destructive-cap cap of 3 applies.

3 / 5

Progressive Disclosure

Well-organized overview with clearly signaled one-level-deep references to real bundle files (references/owasp_top_10_checklist.md, references/attack_patterns.md, references/responsible_disclosure.md) plus working scripts; no nested-reference chains, easy navigation.

5 / 5

Total

17

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that explicitly states both the triggering conditions and the concrete capabilities, with natural user-facing language. Minor room to add common synonyms (pentest, ethical hacking) and sharpen the 'audits' trigger against overlapping skills.

DimensionReasoningScore

Specificity

Lists multiple concrete action categories — 'static analysis, dependency scanning, secret detection, API security testing, and pen test report generation' — giving comprehensive coverage of what the skill does rather than vague abstractions.

5 / 5

Completeness

Explicitly answers both: 'Use when the user asks to perform...' (when) and 'Covers static analysis, dependency scanning...' (what), with concrete trigger phrases for both.

5 / 5

Trigger Term Quality

Strong natural trigger phrases ('security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments') that users would actually say, but missing common synonyms like 'pentest', 'ethical hacking', or 'red team'.

4 / 5

Distinctiveness Conflict Risk

Carves a clear offensive-security niche via 'offensive security assessments', but the broad term 'security audits' has minor overlap risk with defensive/CI-gate security skills it elsewhere distinguishes itself from.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing, 1 deeper-than-1-level, 3 suspicious

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.