CtrlK
BlogDocsLog inGet started
Tessl Logo

ethical-hacking-methodology

This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", or "write penetration test reports". It provides comprehensive ethical hacking methodology and techniques.

56

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/ethical-hacking-methodology/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An actionable command reference undermined by verbosity and weak workflow structure: it teaches concepts Claude already knows and presents destructive operations without validation checkpoints or progressive file structure.

Suggestions

Remove or condense Phase 1 (hacker types) and Phase 8 (common attack types) — these are concepts Claude already knows and add token cost without actionable value.

Add explicit validation checkpoints to the destructive workflow phases (e.g., verify a finding is exploitable before persistence, confirm scope/authorization before exploitation, validate cleanup after testing).

Move reference material such as the common-port table, Kali setup walkthrough, and command quick-reference into separate files under references/ and link to them from SKILL.md, keeping the body a concise overview.

DimensionReasoningScore

Conciseness

Noticeably verbose: Phase 1 (hacker type classifications) and Phase 8 (malware/attack type definitions) explain concepts Claude already knows, and the Kali installation walkthrough is reference padding.

2 / 5

Actionability

Many concrete copy-paste commands across recon, scanning, and exploitation (nmap, nikto, gobuster, sqlmap, hydra, metasploit), with minor gaps in the schematic vulnerability-scanner commands (omp/nessuscli).

4 / 5

Workflow Clarity

Phases are loosely sequenced but lack validation checkpoints, and destructive operations (exploitation, persistence, privilege escalation, covering tracks) have no validation feedback loops, capping this at 3.

3 / 5

Progressive Disclosure

Good section headers and tables, but no bundle files exist and substantial reference material (port table, common attack types, Kali setup) is inlined rather than split into one-level-deep referenced files.

3 / 5

Total

12

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with explicit trigger guidance and a clear niche, weakened only by a generic what-statement and some missing common synonyms. It clearly answers both what and when.

DimensionReasoningScore

Specificity

Lists several concrete trigger-actions ("perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", "write penetration test reports"), though the closing "provides comprehensive ethical hacking methodology and techniques" is generic.

4 / 5

Completeness

Explicitly answers both what (provides ethical hacking methodology) and when (quoted trigger phrases), but the what-statement is generic which keeps it below a 5.

4 / 5

Trigger Term Quality

Good natural phrases users would say ("learn ethical hacking", "penetration testing lifecycle", "exploit vulnerabilities"), but missing common synonyms like "pentest", "red team", or "vulnerability assessment".

4 / 5

Distinctiveness Conflict Risk

Clear penetration-testing niche with distinct triggers and minimal conflict risk, with only minor overlap risk against general cybersecurity skills.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.