CtrlK
BlogDocsLog inGet started
Tessl Logo

recon-scope-triage

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise. Automated recon keyword-matches on the brand name, so for any target whose name is a common/dictionary word, the output is dominated by assets belonging to UNRELATED same-named companies (repos, cloud buckets, mobile apps, breach corpora, typosquats). Built from an authorized engagement where an ASM report's "Criticals" were overwhelmingly false positives and the combo/repos/mobile/bucket lists were polluted with unrelated same-named orgs. Use at the START of any engagement, immediately on receiving any ASM/recon/OSINT dataset, BEFORE testing anything.

79

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, actionable triage skill: it pairs a concrete verification table with an executable soft-404 control and a sequenced workflow that includes explicit quarantine checkpoints. It stays lean without explaining basics Claude already knows.

DimensionReasoningScore

Conciseness

Lean, table-driven body with an executable code block and short sections; it does not explain concepts Claude already knows, and the calibration section conveys domain-specific false-positive expectations rather than padding.

3 / 3

Actionability

Provides concrete executable guidance — the curl/junk-path soft-404 control with exact bash — plus specific per-source ownership signals (repo owner emails, reverse-DNS package, exact owned-domain match).

3 / 3

Workflow Clarity

The 5-step triage workflow is clearly sequenced with explicit validation checkpoints ('No signal → quarantine, don't test') and a soft-404 feedback loop (compare finding vs. control, discard if identical).

3 / 3

Progressive Disclosure

No bundle files exist, so the single self-contained file with well-organized labeled sections and no nested references is appropriately structured; related skills are surfaced as one-level chains.

3 / 3

Total

12

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete actions, lists the asset classes it handles, and provides an explicit 'Use when...' trigger. It is distinguishable from generic recon/triage skills and uses third person throughout.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise' — and enumerates specific asset classes (repos, cloud buckets, mobile apps, breach corpora, typosquats).

3 / 3

Completeness

Clearly answers both what (triage recon for ownership, separate real assets from collision noise) and when via an explicit trigger clause: 'Use at the START of any engagement, immediately on receiving any ASM/recon/OSINT dataset, BEFORE testing anything.'

3 / 3

Trigger Term Quality

Uses natural domain terms a user would actually say when needing this skill — 'ASM/recon', 'ASM report', 'recon export', 'breach combo', 'OSINT dataset', 'ownership'.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche — namespace-collision triage for dictionary-word brands — with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.