CtrlK
BlogDocsLog inGet started
Tessl Logo

red-team-tools

This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/red-team-tools/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, command-heavy reference that is genuinely actionable for recon and bug bounty work, held back by missing validation steps in the batch-scan workflow and a complete absence of progressive disclosure — everything lives in one monolithic file. Redundancy in the Examples section and undefined input files are the remaining rough edges.

Suggestions

Add an explicit validation step to the workflow (e.g., step 11: verify findings before reporting — rerun nuclei with -severity medium,high and manually confirm each result), moving it out of the Troubleshooting table.

Split the automated recon script into scripts/recon.sh and move the tool table / API endpoint list into a references file, keeping SKILL.md as the workflow overview.

Define or provision the undefined inputs (`resolvers.txt`, `api_wordlist.txt`, ParamSpider installation) and cut the Examples section, which duplicates pipelines already shown in sections 2-8.

DimensionReasoningScore

Conciseness

Dense, command-first sections with terse comments and no explanations of concepts Claude already knows; the only notable padding is the Examples section, which repeats pipelines from sections 2-8, plus a few filler comments like "Wappalyzer (if available)".

4 / 5

Actionability

Mostly executable guidance — full commands with flags, output files, and wordlist paths — but minor gaps remain: `resolvers.txt`, `api_wordlist.txt`, and `paramspider.py` are referenced without being provisioned or installed.

4 / 5

Workflow Clarity

A clear 1-10 sequence (acquisitions, subdomains, live hosts, fingerprinting, content, analysis, XSS, scanning, API, automation) exists, but batch scanning workflows lack validation checkpoints — "manually verify findings" appears only in Troubleshooting/Constraints, not as an explicit workflow step, which caps this dimension at 3.

3 / 5

Progressive Disclosure

Good section headers organize the body, but there is no bundle structure at all — the full automated recon script belongs in scripts/ and the tool/endpoint reference in a separate file — so content that should be separate is inlined in one 300-line file.

3 / 5

Total

14

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with explicit, natural trigger phrases and a distinct security niche. Its main weakness is the vague capability statement — it never concretely says what the skill does beyond "techniques and tool configurations".

DimensionReasoningScore

Specificity

Lists several concrete actions ("perform bug bounty hunting", "hunt for XSS vulnerabilities", "enumerate subdomains", "automate reconnaissance"), but the capability clause "security researcher techniques and tool configurations from top bug bounty hunters" is generic, so coverage has minor gaps rather than being comprehensive.

4 / 5

Completeness

Both parts are present: an explicit, well-formed "when" ("This skill should be used when the user asks to...") and a "what", but the what ("needs security researcher techniques and tool configurations") is vague and could be more specific, matching the anchor where one of the two could be improved.

4 / 5

Trigger Term Quality

Good keyword coverage with natural user phrases ("bug bounty hunting", "reconnaissance", "XSS vulnerabilities", "subdomains"), but common synonyms like "pentest", "security assessment", or "OSINT" are missing, so it falls just short of comprehensive.

4 / 5

Distinctiveness Conflict Risk

The bug bounty / red team recon niche is mostly distinct with specific triggers, but broad terms like "reconnaissance" and "security researcher techniques" create minor overlap risk with general pentest or security skills.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.