CtrlK
BlogDocsLog inGet started
Tessl Logo

shodan-reconnaissance

This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP ranges with Shodan," or "discover IoT devices and open ports." It provides comprehensive guidance for using Shodan's search engine, CLI, and API for penetration testing reconnaissance.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/shodan-reconnaissance/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a highly actionable, executable reference with a clear stepwise workflow and a useful troubleshooting matrix, but it duplicates queries across sections and inlines ~200 lines of filter/ example material that should be split into reference files. Splitting references and de-duplicating the example queries would materially improve token efficiency.

Suggestions

Move the 'Search Filters Reference' and 'Examples' sections into references/ (e.g., references/filters.md and references/examples.md), keeping only the most common queries inline in the Quick Reference tables.

De-duplicate queries that appear in both the Quick Reference tables and the Examples section (org recon, webcams/modbus, SSL certs) by cross-referencing instead of repeating.

Add an explicit validation checkpoint in the on-demand scanning workflow — check 'shodan scan status SCAN_ID' and confirm completion before running 'shodan download'.

DimensionReasoningScore

Conciseness

The body is dense reference material (commands, filters, tables) rather than padded conceptual explanation, but there is notable duplication: the same queries appear in 'Common Search Queries', 'Useful Filter Combinations', and again in the Examples section (e.g., 'org:"Target Company"' and webcam/modbus queries repeat). This matches anchor 3 — mostly efficient but could be tightened — rather than 4, where duplication would be absent.

3 / 5

Actionability

Nearly everything is copy-paste executable: real CLI invocations with sample outputs ('shodan host 1.1.1.1', 'shodan download --limit 5000 results.json.gz "nginx"'), curl API calls, and a complete runnable Python automation script with error handling. This matches anchor 5 and exceeds anchor 4 because the examples cover the common cases end-to-end with concrete arguments rather than placeholders-only.

5 / 5

Workflow Clarity

An explicit 8-step core workflow sequences setup → host recon → search → filters → scanning → stats → monitoring → API, and the Troubleshooting table provides issue→cause→fix recovery loops. It falls short of anchor 5 because validation checkpoints are implicit rather than enforced — e.g., it never instructs verifying scan completion or credit balance before downloading results, and batch operations like 'download --limit -1' lack explicit verification steps.

4 / 5

Progressive Disclosure

Section structure with headers and quick-reference tables is good, but the skill is a ~495-line monolith with no references/ files at all: the ~150-line filter reference and the examples clearly belong in separate reference files per progressive-disclosure practice. This matches anchor 3 (content that should be separate is inline) rather than 2, because internal organization and navigation within the single file is solid.

3 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit and well-phrased trigger clause with natural, quotable user phrases and is highly distinctive. Its main weakness is the 'what' half, which relies on 'comprehensive guidance' buzzword phrasing rather than concretely listing what the skill does.

Suggestions

Replace 'provides comprehensive guidance' with 3-4 concrete capabilities, e.g., 'Search Shodan for exposed devices and services, run filtered queries, submit on-demand scans, and export host/vulnerability data for penetration testing reconnaissance.'

Add one or two common trigger variations such as 'run a Shodan query' or 'look up a host on Shodan' to broaden natural keyword coverage.

DimensionReasoningScore

Specificity

The what-clause 'provides comprehensive guidance for using Shodan's search engine, CLI, and API for penetration testing reconnaissance' names the domain and tooling but uses the buzzword 'comprehensive guidance' rather than listing concrete actions; the concrete actions only appear in the trigger phrases. This sits at anchor 3 (names domain and limited concrete actions) rather than 4, which requires several specific actions enumerated as capabilities.

3 / 5

Completeness

Both what and when are present, and the 'when' is explicit with concrete trigger phrases ('This skill should be used when the user asks to...'). It does not reach anchor 5 because the 'what' half leans on the vague 'comprehensive guidance' phrasing instead of concretely enumerating capabilities, matching anchor 4's 'when could be more explicit or specific' relaxation applied to the what-side.

4 / 5

Trigger Term Quality

Natural user phrases like 'search for exposed devices on the internet', 'find vulnerable services using Shodan', and 'discover IoT devices and open ports' are quoted verbatim as user asks, giving good keyword coverage. It falls short of anchor 5 because common variations such as 'run a Shodan query', 'look up a host on Shodan', or 'check Shodan for CVEs' are absent.

4 / 5

Distinctiveness Conflict Risk

Every trigger is Shodan-branded ('perform Shodan reconnaissance', 'scan IP ranges with Shodan') and the niche — internet-wide exposure search for pentest recon — is clearly distinct from general scanning or OSINT skills, giving minimal conflict risk. This clearly matches anchor 5 and not anchor 4, which would require some overlap with closely related skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (504 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.