CtrlK
BlogDocsLog inGet started
Tessl Logo

homelab-network-auditor

Audit homelab network topology, scan for open ports and exposed services, review firewall rules, and generate network security reports.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/homelab-network-auditor/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-organized instruction-only skill body with a clear sequenced workflow and good safety gating. Its main gap is actionability: tool names are given but no concrete commands, flag mappings, or report templates to make execution copy-paste ready.

Suggestions

Add concrete executable commands, e.g. `nmap -sn 192.168.1.0/24` for discovery and `nmap -sV --top-ports 100 <hosts>` for service scanning.

Include a report template or field list for step 6 so generated reports are consistent and complete.

Add an explicit validation checkpoint before reporting (e.g., re-verify unexpected external exposures before flagging them as critical).

DimensionReasoningScore

Conciseness

The ~46-line body is lean with no concept explanations or padding — it assumes Claude knows what nmap and ARP scans are ("nmap or equivalent") and every section (Invocation, Workflow, Safety, MCP, References, Companions) earns its tokens. It matches anchor 5 rather than 4 because there are no over-explanations to trim.

5 / 5

Actionability

Steps name concrete tools ("ping sweep or ARP scan", "nmap or equivalent") but provide no executable commands, no report structure/template, and no specifics on how to compare firewall rules. This matches anchor 3 — some concrete guidance but incomplete with missing key details — rather than anchor 4, which expects concrete commands.

3 / 5

Workflow Clarity

The 8-step workflow is clearly sequenced with checkpoints in step 1 ("confirm scope is limited to owned infrastructure") and the Safety section ("Confirm scope with user before any scan begins"). It falls short of anchor 5 because there is no post-scan validation of findings (e.g., verifying an unexpected exposure is real before reporting it).

4 / 5

Progressive Disclosure

The skill is under 50 lines with no bundle files needed (references/ and scripts/ are empty), and the body is organized into well-labeled sections with only one-level-deep external links. Per the rubric guideline, this scores 5 for a short skill requiring no external references.

5 / 5

Total

17

/

20

Passed

Description

71%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, third-person description with strong concrete verbs and good natural keywords. Its main weakness is the complete absence of "when to use" trigger guidance, which both caps completeness and slightly blurs distinctiveness against related skills.

Suggestions

Append a trigger clause such as "Use when the user asks to scan the homelab network, check open ports, audit firewall rules, or review exposed services."

Add common synonyms users might say (e.g. "port scan", "vulnerability", "nmap") to broaden natural trigger coverage.

Clarify the boundary vs. general security-review skills by scoping explicitly to owned homelab infrastructure in the description.

DimensionReasoningScore

Specificity

Lists four concrete actions — "audit homelab network topology", "scan for open ports and exposed services", "review firewall rules", "generate network security reports" — giving comprehensive coverage of the skill's domain. It exceeds anchor 4 because no capability area is noticeably missing.

5 / 5

Completeness

The "what" is clearly and concretely stated, but there is no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guideline. It is not anchor 2 because the "what" is specific rather than vague.

3 / 5

Trigger Term Quality

Natural phrases like "open ports", "firewall rules", "exposed services", and "network security report" are present and would be said by users. Not anchor 5 because common variations such as "port scan", "vulnerability", or "nmap" are absent; not anchor 3 because keyword coverage is solid rather than partial.

4 / 5

Distinctiveness Conflict Risk

The "homelab" qualifier plus port/firewall auditing actions form a mostly distinct niche with only minor overlap risk against general security-audit or sibling homelab skills. Not anchor 5 because the lack of explicit trigger phrases leaves some ambiguity versus closely related skills.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
pvnkmnk/AgenticSelfHostSkills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.