CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-checklist

This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing best practices", or needs a structured methodology for penetration testing engagements.

56

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-checklist/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sequenced, reasonably actionable phased checklist with concrete commands, credentials, and standards, but it is bloated by explanations of concepts Claude already knows and by a redundant Quick Reference section. At 335 lines it should be restructured as a lean overview with per-phase detail moved into one-level reference files.

Suggestions

Cut explanations of concepts Claude already knows (the black/gray/white box table, IDS/IPS/SIEM definitions, budget truisms like 'Cheap pentests often produce poor results') and keep only the checklist items and decision guidance.

Split per-phase detail into one-level reference files (e.g., references/scoping.md, references/monitoring.md, references/remediation.md) and keep SKILL.md as a concise overview with clearly signaled links.

Remove or compress the Quick Reference section, which duplicates the phase content, and replace it with a short pre/post engagement checklist that adds only new information.

DimensionReasoningScore

Conciseness

The checklist items themselves are the skill's value and are efficiently phrased, but several sections explain concepts Claude already knows — the black/gray/white box table, IDS/IPS/SIEM terminology, 'Cheap pentests often produce poor results', and trivial 'tail -f' commands. Not a 2 because the core content is genuinely useful; not a 4 because the known-concept padding recurs and the Quick Reference section largely duplicates the phase content.

3 / 5

Actionability

Concrete, executable guidance is present: 'nmap -sV --script vuln TARGET', 'nikto -h http://TARGET', 'tcpdump -i eth0 -w capture.pcap', specific credentials (OSCP, GPEN, CREST), standards (PTES, OWASP, NIST), and cloud provider policy URLs. Not a 5 because many checklist items remain abstract directives ('Seek recommendations - Ask trusted sources') and the monitoring commands are shallow.

4 / 5

Workflow Clarity

A clear five-phase sequence (Scope Definition → Environment Preparation → Expertise Selection → Monitoring → Remediation) with pre/post checklists and verification steps ('Verify backup integrity', 'Verify cleanup complete', 'Plan verification testing'). Not a 5 because there are no explicit error-recovery feedback loops — nothing says what to do when a checkpoint fails.

4 / 5

Progressive Disclosure

The skill is a single monolithic 335-line SKILL.md with no bundle files; content that clearly belongs in one-level reference files (per-phase detail, monitoring tooling, report format guidance) is inlined. Internal section structure is good, which keeps it above 2, but at this length the body should be an overview pointing to reference files, which keeps it below 4.

3 / 5

Total

14

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description excels at trigger coverage with explicit, natural 'use when' phrases, but it is one-sided: it says when to invoke the skill without clearly stating what the skill contains or does. Adding a concrete capability statement (e.g., 'provides a phased checklist covering scoping, environment preparation, tester selection, monitoring, and remediation') would round it out.

Suggestions

State explicitly what the skill provides before the trigger clause, e.g., 'Provides a phased penetration-testing checklist covering scope definition, environment preparation, expertise selection, monitoring, and remediation.'

Broaden trigger synonyms to include 'pen test', 'security audit', and 'ethical hacking' alongside the existing 'pentest' / 'penetration test' / 'penetration testing' variants.

Trim 'follow security testing best practices', which is generic enough to overlap with general security-review skills, in favor of more planning-specific triggers.

DimensionReasoningScore

Specificity

The description names the domain and a couple of concrete actions ('create a security assessment checklist', 'define pentest scope') but never states what the skill itself provides — there is no phrase like 'provides a phased checklist covering scoping, preparation, monitoring, and remediation'. It is not a 2 (more than generic domain-naming) and not a 4 (no list of the skill's concrete capabilities).

3 / 5

Completeness

The 'when' is fully explicit ('This skill should be used when the user asks to...'), but the 'what' is only weakly implied by 'needs a structured methodology for penetration testing engagements' — the description never explicitly says the skill is a checklist or methodology or what it covers. Anchor 4 requires a solid 'what' alongside the 'when', which is absent.

3 / 5

Trigger Term Quality

Strong natural trigger phrases users would actually say: 'plan a penetration test', 'prepare for penetration testing', 'define pentest scope', 'follow security testing best practices', with pentest/penetration-test synonym variation. Falls short of 5 because common variants like 'pen test', 'ethical hacking', or 'security audit' are missing.

4 / 5

Distinctiveness Conflict Risk

The triggers target a clear niche (planning penetration testing engagements) and are unlikely to fire for unrelated skills. Only minor overlap risk with broader security-assessment or code-security-review skills keeps it below 5.

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.