CtrlK
BlogDocsLog inGet started
Tessl Logo

scanning-tools

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.

53

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/scanning-tools/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable — dense, concrete, copy-paste-ready commands across all ten phases with a useful tool-selection guide — but it is a monolithic cheat sheet that spends most of its tokens on flag-level reference data Claude already knows. Splitting per-category tool references into bundle files and adding explicit validation checkpoints (authorization confirmed, findings verified before reporting) to the methodology would address the two structural weaknesses.

Suggestions

Move per-tool command catalogs (wireless, cloud, compliance, and the nmap/Nikto flag dumps) into references/ files (e.g. references/network.md, references/wireless.md, references/cloud-compliance.md) and keep SKILL.md to tool selection, the methodology, and a quick start.

Drop content Claude already knows — the Common Ports Reference table and the Burp module descriptions — or move them to a reference file.

Add explicit validation checkpoints to the Phase 8 methodology: confirm written authorization before scanning, verify findings (re-test/false-positive elimination) before reporting, and a validate→fix→retry loop for failed scans, linking it to the existing Troubleshooting section.

DimensionReasoningScore

Conciseness

Large portions are flag-by-flag dumps of material Claude already knows: nmap timing templates (-T0 through -T5) and output formats, a 'Common Ports Reference' table (FTP 21, SSH 22, HTTP 80), Burp module descriptions, and ClamAV switches. This is several padded sections of known reference data rather than a few spots to tighten, matching anchor 2 rather than 3.

2 / 5

Actionability

Nearly every section is copy-paste-ready commands ('nmap -sS 192.168.1.100', 'prowler aws --compliance cis_aws', 'sudo lynis audit system') with per-command comments. Not 5 because a few blocks are not executable as written: the Burp section is prose steps inside a code fence, and the nessuscli scan --create syntax does not match the tool's actual CLI.

4 / 5

Workflow Clarity

Phase 8 provides a real sequence (Planning → Discovery → Vulnerability Assessment → Analysis → Reporting) and verification appears ('Manual verification', 'Eliminate false positives'), but checkpoints are implicit rather than explicit gates, and there is no validate→fix→retry feedback loop. Because network scanning is a batch operation over live systems, the batch-operation cap holds this at 3; it does not reach 4 since validation is not an explicit step in the workflow.

3 / 5

Progressive Disclosure

No bundle files exist, and ~590 lines of per-tool reference material (wireless cracking, cloud auditing, OpenSCAP compliance) are inlined in SKILL.md where per-category reference files clearly belong. Score 3 rather than 2 because the sections are well-organized with clear headers, a tool-selection table, and a quick reference; not 4 because at this size the split into references/ is obviously warranted.

3 / 5

Total

12

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-constructed 'Use when…' clause with natural trigger phrases across all six scanning categories is the description's main strength, and it uses appropriate third-person voice. The weakness is the vague, buzzword-tinged 'what' half — 'provides comprehensive guidance on security scanning tools and methodologies' — which never states concretely what the skill does.

Suggestions

Replace 'It provides comprehensive guidance on security scanning tools and methodologies' with a concrete capability statement, e.g. 'Covers tool selection, configuration, and usage for network discovery (nmap, masscan), vulnerability assessment (Nessus, OpenVAS), web app testing (Burp, ZAP, Nikto), wireless, cloud, and compliance scanning.'

Add a few tool-name synonyms to the trigger list (e.g. 'run a port scan with nmap', 'nessus/openvas scan', 'compliance audit') so users who name tools directly also match.

DimensionReasoningScore

Specificity

The 'what' half — 'It provides comprehensive guidance on security scanning tools and methodologies' — is generic and uses the buzzword 'comprehensive', though the quoted trigger phrases ('scan networks for open ports', 'detect malware', 'check cloud security') do name concrete activities. This matches anchor 3 (domain plus some concrete actions, not a comprehensive capability list) rather than 4, whose examples enumerate specific actions the skill performs.

3 / 5

Completeness

Both halves are present: an explicit, well-formed when-clause ('should be used when the user asks to…') plus a what-statement. Not 5 because the what-statement ('provides comprehensive guidance on security scanning tools and methodologies') is vague, whereas the anchor-5 example concretely states what the skill does and when with concrete trigger phrases.

4 / 5

Trigger Term Quality

'perform vulnerability scanning', 'scan networks for open ports', 'assess web application security', 'scan wireless networks', 'detect malware', 'check cloud security', 'evaluate system compliance' are natural user phrasings covering all six sub-domains. Not 5 because tool names (nmap, nessus, burp) and common synonyms ('pentest', 'compliance audit', 'port scan') are absent.

4 / 5

Distinctiveness Conflict Risk

'Security scanning tools' is a clear niche with distinct quoted triggers and minimal conflict risk against unrelated skills. Not 5 because the description spans six sub-domains (web app testing, wireless, cloud, compliance) that could each plausibly be a separate skill, creating overlap risk with individual-tool or pentest skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (590 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.