CtrlK
BlogDocsLog inGet started
Tessl Logo

ethical-hacking-methodology

This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", or "write penetration test reports". It provides comprehensive ethical hacking methodology and techniques.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/ethical-hacking-methodology/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is rich in executable commands and well-sequenced phases, but it is bloated with textbook security concepts Claude already knows and lacks any progressive disclosure into reference files. Risky phases also miss explicit validation checkpoints.

Suggestions

Move the hacker-type taxonomy, malware glossary, common-port table, and Kali install walkthrough into reference files (e.g. references/glossary.md, references/setup.md) and keep SKILL.md as a lean overview that links to them, cutting token bloat.

Add explicit validation/authorization checkpoints before destructive phases (e.g. 'Confirm written authorization and scope before exploitation; verify the exploit succeeded before moving to persistence'), with a validate→fix→retry loop.

Trim general-knowledge explanations (what a virus/worm is, what phishing is) that Claude already knows, leaving only the methodology, commands, and reporting specifics.

DimensionReasoningScore

Conciseness

The ~460-line body re-teaches general security knowledge Claude already knows — White/Black/Grey hat taxonomy, a malware-type glossary (Virus/Worm/Trojan/Ransomware), a common-port reference table, and a full Kali install walkthrough — which pad the token budget, matching the score-1 anchor of explaining known concepts.

1 / 3

Actionability

Dense copy-paste-ready commands with real flags and syntax (nmap, theHarvester, gobuster, msfconsole, hydra, sqlmap, nikto) plus a concrete report structure, matching the fully-executable anchor.

3 / 3

Workflow Clarity

Phases are clearly sequenced (1–10) but destructive/batch operations (exploitation, persistence, brute force) lack explicit validation or authorization-check checkpoints, which the rubric says caps this dimension at 2.

2 / 3

Progressive Disclosure

It is a single monolithic file with no bundle files and no external references, and large reference material (port table, Kali setup, command cheat sheet) that could be split out is inline, matching the anchor-2 example of inline content that belongs in a separate file.

2 / 3

Total

8

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it pairs an explicit 'Use when...' trigger clause with a clear statement of what the skill provides and a set of natural user phrasings. Its only weakness is that the capability framing uses broad phase verbs rather than a list of concrete actions.

DimensionReasoningScore

Specificity

Quotes name the domain and major phase actions ("perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", "write penetration test reports") but list broad phase verbs rather than multiple concrete capability actions, matching anchor 2.

2 / 3

Completeness

Explicitly answers both what ("provides comprehensive ethical hacking methodology and techniques") and when ("should be used when the user asks to...") with an explicit trigger clause, matching the top anchor.

3 / 3

Trigger Term Quality

Six natural quoted triggers ("learn ethical hacking", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", "write penetration test reports") cover the kinds of phrasings a user would actually say, matching the good-coverage anchor.

3 / 3

Distinctiveness Conflict Risk

The triggers are specific to the ethical hacking / penetration testing niche and unlikely to fire for unrelated skills, matching the clear-niche anchor.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.