CtrlK
BlogDocsLog inGet started
Tessl Logo

web2-recon

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomain enum, or attack surface mapping.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and well sequenced with strong feedback/verification loops, making it a strong operational runbook. Its main weakness is token efficiency and progressive disclosure: it is long, has some duplicated sections, and inlines large reference material that could live in separate files.

Suggestions

De-duplicate repeated guidance — SecretFinder/LinkFinder invocation and stack fingerprinting each appear twice — and consolidate into a single section.

Move the large swagger/openapi path wordlist into a separate file (e.g. references/swagger-paths.txt) and reference it, reducing SKILL.md token weight.

Tighten the longer prose blocks (e.g., 'Operator Notes' intro and target-scoring narrative) to lean, imperative bullets that assume Claude's competence.

DimensionReasoningScore

Conciseness

The body is densely useful but quite long (~700 lines) with some repeated guidance (e.g., SecretFinder invocation appears twice, stack fingerprinting explained in two places) that could be tightened for token efficiency.

3 / 5

Actionability

It is packed with copy-paste-ready, executable bash commands and concrete wordlists covering each pipeline phase, with specific flags and example outputs.

5 / 5

Workflow Clarity

The standard pipeline is a clearly numbered step sequence (Step 0–6) with validation/verification touches (live-host counts, the 5-minute kill-signal feedback loop, go/no-go scoring before time investment), and fallback procedures with smoke-tests.

5 / 5

Progressive Disclosure

Content is well sectioned but essentially monolithic in SKILL.md; it references a few external docs (`docs/verification/recon-hackerone-vdp.md`) and sibling skills, but no bundle files exist and large reference material (e.g., the full swagger wordlist) is inlined rather than split out.

3 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it lists comprehensive concrete capabilities and pairs them with an explicit, natural-language 'Use when...' trigger clause. It is specific, distinct, and complete. Minor headroom remains only in broadening natural trigger-term synonyms.

DimensionReasoningScore

Specificity

The description enumerates many concrete actions across the pipeline (subdomain enumeration via subfinder/Chaos/assetfinder, live host discovery via dnsx/httpx, URL crawling, directory fuzzing, JS analysis, continuous monitoring) giving comprehensive coverage of specific capabilities.

5 / 5

Completeness

It explicitly answers 'what' (the named enumeration/discovery/analysis capabilities) and 'when' ('Use when starting recon on any web2 target or when asked about asset discovery, subdomain enum, or attack surface mapping') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural trigger terms ('recon', 'asset discovery', 'subdomain enum', 'attack surface mapping', 'web2 target') are present and user-likely, but common synonyms/file extensions are not exhaustively covered.

4 / 5

Distinctiveness Conflict Risk

The web2-recon niche with its specific toolchain and trigger phrases is clearly distinct from adjacent skills and unlikely to fire for unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (699 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

13

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.