CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-commands

This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "scan web vulnerabilities with nikto", "enumerate networks", or needs essential penetration testing command references.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/pentest-commands/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent executable command catalog — every entry is copy-paste ready with realistic flags and targets. Weaknesses are structural: it masquerades as a workflow without any sequence or authorization/scope validation checkpoints (capped accordingly), and it is a monolithic single-file dump rather than an overview with per-tool reference files.

Suggestions

Add explicit validation checkpoints before risky operations: verify written authorization and target scope before any exploit or brute-force step, per the destructive-operations guideline.

Split the per-tool catalogs (nmap, metasploit, nikto, sqlmap, hydra, john, aircrack-ng, tshark) into references/ files and keep SKILL.md as a concise index with one-level-deep links.

Remove the duplicated nmap commands in 'Quick Reference' (or fold them into the Nmap section) and drop or merge the filler Prerequisites/Outputs lists.

Label the 'Password Hash Types' table correctly (the Mode numbers are hashcat modes, not john formats) or move it to a john/hashcat reference.

DimensionReasoningScore

Conciseness

The body is almost entirely executable commands with one-line comments and no padding or explanations of concepts Claude already knows — efficient for a command reference. Not a 5 because the 'Quick Reference' section re-repeats nmap scans already covered above, and the generic 'Inputs/Prerequisites' and 'Outputs/Deliverables' sections add little actionable value.

4 / 5

Actionability

Every entry is a complete, copy-paste-ready command with real flags and placeholder targets (e.g., "nmap --script smb-vuln-ms17-010 192.168.1.1", "hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.1"), covering the common cases per tool. This matches the fully-executable, common-cases-covered anchor.

5 / 5

Workflow Clarity

Despite the 'Core Workflow' heading, there is no sequenced workflow — just a parallel tool catalog — and no validation checkpoints anywhere (no verify-authorization-before-running step, no confirm-target-scope check before exploitation or brute force). The rubric caps destructive/batch-operation skills without validation at 3, and the 'Always have written authorization' bullet is a constraint list, not an enforced checkpoint, so it cannot exceed 3.

3 / 5

Progressive Disclosure

The per-tool sections are clearly headed and navigable, but all ~430 lines live monolithically in SKILL.md with no references/ files at all — content that clearly belongs in separate per-tool references is inlined. This is the anchor-3 profile (structure present, content that should be separate is inline); not 2 because section headers make it navigable, not 4 because no material is split out.

3 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A trigger-rich description with natural, concrete user phrasing and a clear pentest niche. Its main weakness is a thin 'what' — the skill's actual capability (providing command references across eight tools) is only implied by the trailing phrase rather than stated up front, and trigger coverage omits several tools the skill actually documents.

Suggestions

Lead with a concrete 'what' clause (e.g., "Provides command references for nmap, metasploit, nikto, sqlmap, hydra, john, aircrack-ng, and tshark") before the trigger list.

Add trigger terms for the remaining covered tools (sqlmap, aircrack-ng/wifi cracking, wireshark/tshark packet capture) and the common synonym "brute force".

State the output of using the skill (e.g., quick command lookup during authorized assessments) to sharpen the 'what'.

DimensionReasoningScore

Specificity

The description names the domain and concrete tools ("nmap", "metasploit", "hydra or john", "nikto") but never states what the skill itself does — the only 'what' is the vague tail phrase "needs essential penetration testing command references". It matches anchor 3 (names domain, concrete elements present, but not comprehensive on actions) rather than 4, which expects several specific actions of the skill listed.

3 / 5

Completeness

The 'when' is explicit and concrete ("when the user asks to..."), and a 'what' is present ("penetration testing command references"), so both halves exist. It sits between anchor 4 and 5: the 'what' is thin and tool-coverage implicit rather than clearly enumerated, keeping it below the explicit what+when of a 5.

4 / 5

Trigger Term Quality

Natural quoted phrases like "run pentest commands", "scan with nmap", "crack passwords with hydra or john" are exactly what a user would say. Not a 5 because common variations are missing: "brute force", "penetration testing", and the other covered tools (sqlmap, aircrack-ng, wireshark) never appear as triggers.

4 / 5

Distinctiveness Conflict Risk

A clear niche (pentest command reference) with distinct tool-name triggers (nmap, metasploit, hydra, john, nikto) makes wrong-skill triggering unlikely. It fits anchor 5's clear-niche/minimal-conflict profile; the neighboring anchor 4 reserves overlap risk that is not present here.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.