CtrlK
BlogDocsLog inGet started
Tessl Logo

scanning-tools

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.

58

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/scanning-tools/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with copy-paste-ready commands across many tools, but it is a token-heavy monolithic reference that explains material Claude largely already knows and provides no progressive disclosure or external reference structure. Workflow sequencing exists but lacks the validation feedback loops expected for destructive scanning operations.

Suggestions

Move the tool-flag cheat sheets (Nmap options, common ports, per-command lists) into bundled reference files and keep SKILL.md as a concise overview with signaled links.

Add explicit validation/verification checkpoints (e.g., confirm authorization before scanning, validate findings before reporting) into the Phase 8 workflow, especially around destructive actions like deauth and exploitation.

Trim conceptual restatement of well-known tool behavior to reduce token cost; keep only guidance Claude would not already know.

DimensionReasoningScore

Conciseness

The ~590-line body is a dense reference manual restating tool flags and concepts Claude already knows (e.g., Nmap option tables, common port tables), with minimal added value per token.

1 / 3

Actionability

Provides extensive concrete, executable command examples (nmap, masscan, nikto, aircrack-ng, etc.) that are copy-paste ready with inline comments.

3 / 3

Workflow Clarity

Phase 8 lays out a sequenced methodology (Planning→Reporting), but validation/verification checkpoints are only loosely described under Analysis; destructive batch operations like deauth or exploitation lack explicit validate-before-proceed feedback loops.

2 / 3

Progressive Disclosure

The skill is monolithic — all content is inline in SKILL.md with no bundle files (references/scripts/assets absent) and no one-level-deep references, despite the volume warranting splitting into separate cheat-sheet files.

1 / 3

Total

7

/

12

Passed

Description

92%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it lists concrete capabilities, uses natural user-spoken trigger phrases, and explicitly covers both what the skill does and when to use it. Its only weakness is the very broad scope spanning many scanning domains, which raises mild conflict risk with more specialized skills.

Suggestions

Consider narrowing the description to a tighter niche, or acknowledge sub-domains, to reduce overlap with dedicated per-domain scanning skills.

Optionally tighten the trailing clause 'It provides comprehensive guidance...' which borders on vague fluff relative to the concrete trigger list.

DimensionReasoningScore

Specificity

Lists multiple concrete scanning actions across distinct categories (vulnerability scanning, port scanning, web app security, wireless, malware, cloud, compliance), naming specific deliverables and methodologies.

3 / 3

Completeness

Explicitly answers what it does ('provides comprehensive guidance on security scanning tools and methodologies') and when to use it via the quoted 'Use when' trigger clause.

3 / 3

Trigger Term Quality

Phrases like 'perform vulnerability scanning', 'scan networks for open ports', and 'check cloud security' are natural terms a user would actually say, with good coverage across the scanning domain.

3 / 3

Distinctiveness Conflict Risk

The security-scanning niche is fairly clear, but the breadth across network/web/wireless/cloud/compliance could overlap with separate dedicated skills for each scanning category.

2 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (590 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.