CtrlK
BlogDocsLog inGet started
Tessl Logo

ethical-hacking-methodology

This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", or "write penetration test reports". It provides comprehensive ethical hacking methodology and techniques.

54

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/ethical-hacking-methodology/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is genuinely strong on concrete commands — nmap, Metasploit, Hydra, sqlmap usage is copy-paste ready — but it is a monolithic textbook that spends much of its budget teaching concepts Claude already knows. Restructuring into an overview plus focused reference files, and trimming the educational filler, would raise it substantially.

Suggestions

Split reference material (port table, malware/attack glossary, Kali install guide, hacker-type taxonomy) into files under references/ and keep SKILL.md as a concise workflow overview with clearly signaled links.

Delete textbook explanations Claude already knows (white/grey/black hat definitions, what ransomware/viruses are, what port 22 is for) and spend those tokens on non-obvious procedural guidance instead.

Add validation checkpoints to the workflow (e.g. verify scan results before exploiting, confirm cleanup of backdoors/persistence after testing) and reconcile the 'five stages' claim with the ten-phase structure.

DimensionReasoningScore

Conciseness

Large spans restate textbook knowledge Claude already has: the white/grey/black hat taxonomy, malware glossary entries like 'Virus: Self-replicating, needs host file', a port table listing 22=SSH and 80=HTTP, the OWASP Top 10 as bare names, and a full Kali Linux install walkthrough. This is noticeably verbose with several padded sections (anchor 2) rather than only occasional over-explanation (anchor 3).

2 / 5

Actionability

The body is dense with concrete, executable commands ('nmap -sV target.com', 'hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://target.com', 'sqlmap -u "http://target.com/page.php?id=1" --dbs', full Metasploit session). Not 5 because a few spots are comment-only hints (e.g. '# XSS testing / # Manual: <script>alert(XSS)</script>') rather than complete runnable examples.

4 / 5

Workflow Clarity

The ten numbered phases give a real sequence, but there are no validation checkpoints or error-recovery feedback loops, and the Purpose section claims 'five stages' while the workflow lists ten phases. The rubric caps workflow clarity at 3 for destructive operations lacking validation, and the content sits at anchor 3 (sequence present, checkpoints missing) regardless.

3 / 5

Progressive Disclosure

A ~460-line monolithic SKILL.md with no bundle files at all; reference material that clearly belongs in separate files — the port reference table, malware/network attack glossary, Kali installation guide, and hacker-type taxonomy — is inlined. This matches anchor 2 ('content that clearly belongs in separate files is inlined') rather than 3, since there is no reference structure at all to signal.

2 / 5

Total

11

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit, well-phrased 'Use when' trigger list covering natural user phrasings for the ethical hacking domain. Its main weakness is the vague capability statement, which asserts 'comprehensive methodology and techniques' without naming the concrete stages it actually covers.

Suggestions

Replace 'It provides comprehensive ethical hacking methodology and techniques' with the concrete stages covered, e.g. 'Covers reconnaissance, scanning, vulnerability analysis, exploitation, and reporting for authorized penetration tests.'

Add common synonyms users say, such as 'pentest', 'pen test', or 'security assessment', to the trigger list.

DimensionReasoningScore

Specificity

The trigger list names concrete activities ('perform reconnaissance', 'conduct security scanning', 'exploit vulnerabilities'), but the capability statement itself is generic: 'It provides comprehensive ethical hacking methodology and techniques.' This fits anchor 3 (domain named with some concrete actions, not comprehensive) rather than 4, whose example lists several specific capability actions.

3 / 5

Completeness

Both halves are present: an explicit 'This skill should be used when...' clause with concrete trigger phrases, and a 'what' statement. Not 5 because the 'what' ('comprehensive ethical hacking methodology and techniques') is vague and does not enumerate concrete capabilities; above 4's lower neighbors because the 'when' is fully explicit.

4 / 5

Trigger Term Quality

Natural quoted phrases like 'learn ethical hacking', 'understand penetration testing lifecycle', and 'write penetration test reports' are phrases users would actually say. Not 5 because common synonyms such as 'pentest', 'pen test', or 'security audit' are missing; clearly above 3 since multiple natural terms are present.

4 / 5

Distinctiveness Conflict Risk

Ethical hacking / penetration testing is a clear niche with distinct trigger phrases ('exploit vulnerabilities', 'write penetration test reports'), so the risk of firing for an unrelated skill is minimal. It matches the anchor 5 example's profile of a niche domain with distinct triggers.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.