CtrlK
BlogDocsLog inGet started
Tessl Logo

enterprise-vpn-attack

External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, default credentials, configuration-disclosure paths, pre-auth RCE/SSRF/path-traversal exploits where applicable. Built from authorized-engagement Cisco ASA testing plus 2024-2026 enterprise VPN CVE landscape. Use whenever the target's perimeter exposes any SSL VPN appliance or remote-access gateway — these are the most common initial-access points in 2024-2026 actor TTPs.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable attack matrix with strong executable coverage and good structural organization, appropriately cautious about destructive operations. It loses points only on conciseness trim and the absence of a formal validation feedback loop and external reference split for the large CVE tables.

Suggestions

Move the per-vendor CVE tables into a one-level-deep reference file (e.g. references/VPN_CVE_MATRIX.md) and keep SKILL.md as an overview that links to it, improving progressive disclosure for the bulk content.

Add an explicit validate→retry feedback loop to the probe sequence (e.g. after nuclei triage, confirm each candidate CVE with a second independent technique before declaring it exploitable) to lift workflow clarity.

Trim the few narrative/justification lines (e.g. 'Most enterprise VPNs now use SAML for SSO. Check SP metadata:') down to imperative commands to tighten conciseness.

DimensionReasoningScore

Conciseness

The body is mostly lean curl commands, tables, and tight prose that assumes Claude's competence without explaining what a VPN or SAML is, but a few narrative lines ('Built from authorized-engagement Cisco ASA testing plus 2024-2026 enterprise VPN CVE landscape' is in the frontmatter, and inline rationales like 'Most enterprise VPNs now use SAML for SSO') could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready, executable curl/nuclei commands with exact paths, cookies, and crafted headers (e.g. the CVE-2023-4966 Host-header leak, CVE-2024-3400 cookie injection), covering the common cases across all vendors.

5 / 5

Workflow Clarity

The 'Common probe sequence (5-minute fingerprint)' gives a clear ordered workflow and the 'Anti-patterns'/'Operational discipline' sections act as checklists with verification guidance ('test 3+ CVEs per vendor', 'Don't trust the version banner alone'), but there is no explicit validate→fix→retry feedback loop for error recovery.

4 / 5

Progressive Disclosure

Well-organized into clearly headed sections (When to use, Vendor identification, CVE matrix, SAML, Default credentials, Probe sequence) with no nested references and easy navigation, but everything is inlined into one ~350-line file with no one-level-deep reference files for the bulky CVE matrix.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality, third-person description that crisply states capabilities and trigger conditions with concrete vendor and product keywords. The only mild blemish is the slightly marketing-toned closing claim about 'most common initial-access points in 2024-2026 actor TTPs', but it does not undermine specificity or trigger quality.

DimensionReasoningScore

Specificity

Lists multiple concrete action categories ('version fingerprinting, CVE matrix, AAA backend identification, default credentials, configuration-disclosure paths, pre-auth RCE/SSRF/path-traversal exploits') alongside a comprehensive vendor list, matching the comprehensive-coverage anchor.

5 / 5

Completeness

Explicitly answers both 'what' (an attack matrix covering fingerprinting, CVEs, AAA, creds, and RCE/path-traversal) and 'when' ('Use whenever the target's perimeter exposes any SSL VPN appliance or remote-access gateway') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Covers the natural terms users actually say — vendor/product names ('Cisco ASA/AnyConnect', 'Fortinet FortiGate', 'Citrix NetScaler', 'Palo Alto GlobalProtect', 'Pulse Secure / Ivanti') plus 'SSL VPN', 'remote-access appliance', and 'remote-access gateway', giving comprehensive synonym and product-name coverage.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (SSL VPN / remote-access perimeter appliances) with distinct, vendor-specific triggers and explicit out-of-scope boundaries ('DO NOT use for' IPsec/L2TP/OpenVPN, client-side bugs, lateral movement), minimizing conflict with peer skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.