CtrlK
BlogDocsLog inGet started
Tessl Logo

tech-stack-teardown

Reverse-engineer a company's sales and marketing tech stack from public signals. Detects CRMs, cold email tools, people databases, ad pixels, email delivery services, and outbound sending domains via DNS records, website source inspection, Apify technology profiling, blacklist checks, and public spam complaint searches. Works on single companies or batches. Outputs a structured markdown report per company.

60

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/competitive-intel/capabilities/tech-stack-teardown/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete commands and a bundled script, and its workflows are well-sequenced, but it is held back by inlined reference tables that belong in a separate file and a missing validation/verification step for batch runs.

Suggestions

Move the SPF/DKIM/TXT/HTML pattern lookup tables (the 'DNS Record Cheat Sheet' and 'Website Source Patterns' sections) into a references/PATTERNS.md file and link to it one level deep, keeping only a short overview in SKILL.md.

Add an explicit validation/verification step to the agent workflow for batch runs, e.g. confirm each domain produced a report and flag any that returned 'No tools detected' for a retry with the Apify profiler.

Trim the redundant intro paragraph and the 'What It Detects' overview table where they restate content already covered by the cheat-sheet tables.

DimensionReasoningScore

Conciseness

Mostly operational and useful, but the intro restates the frontmatter description and the 'What It Detects' table overlaps with the later 'DNS Record Cheat Sheet' lookup tables, so it could be tightened.

3 / 5

Actionability

Provides copy-paste-ready commands for every usage mode (single, batch, --no-apify, --output, --json) plus concrete manual fallbacks (dig/curl/grep) and a bundled script, fully covering the common cases.

5 / 5

Workflow Clarity

The 6-step script flow and 4-step agent flow are clearly sequenced with a cost-confirmation checkpoint for batches, but there is no validation/verification step; because the skill is batch-capable, the missing-feedback-loop cap applies.

3 / 5

Progressive Disclosure

Sections are well-organized and scripts/recon.py is a real, clearly-referenced bundle file, but the large SPF/DKIM/TXT/HTML pattern lookup tables are inlined in SKILL.md rather than split into a one-level-deep reference file, and the skill is ~310 lines so the small-skill exception does not apply.

3 / 5

Total

14

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-differentiated with concrete actions and natural trigger terms, but it omits any explicit 'Use when…' guidance, which caps its completeness. Adding a trigger clause would raise the strongest remaining weakness.

Suggestions

Append an explicit trigger clause, e.g. 'Use when a user asks what tools/tech stack a company uses, wants competitive intel on a company's sales/marketing infrastructure, or mentions CRMs, cold email tools, or ad pixels.'

Add common natural phrasings users say ('what's their sales stack', 'what CRM do they use') to broaden trigger-term coverage toward the top anchor.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — reverse-engineering the tech stack and detecting CRMs, cold email tools, people databases, ad pixels, email delivery services, and outbound sending domains via named signal sources (DNS, source inspection, Apify, blacklists, spam searches) — giving comprehensive coverage.

5 / 5

Completeness

The 'what' is clearly stated (reverse-engineer stack, detect tools, output a markdown report) but there is no 'Use when…' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Strong natural keyword coverage ('tech stack', 'CRMs', 'cold email tools', 'DNS records', 'blacklist', 'spam complaints') with some synonyms, but a few natural phrasings a user might say ('what tools does X use', 'sales stack') are not present.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (public-signal sales/marketing tech-stack recon) with distinct triggers (DNS/blacklist/profiling signals) and minimal overlap with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
gooseworks-ai/goose-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.