CtrlK
BlogDocsLog inGet started
Tessl Logo

smtp-penetration-testing

This skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP banners", "brute force email credentials", or "assess mail server security". It provides comprehensive techniques for testing SMTP server security.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with comprehensive executable commands across a well-ordered 10-phase workflow, but it is padded with duplicated reference/example material and lacks inter-phase validation checkpoints in a single monolithic file.

Suggestions

Remove the duplicated Quick Reference tables and Examples section (or move them to a separate reference file) since the same commands already appear in the phased workflow.

Add explicit validation checkpoints between phases — e.g., confirm enumeration found valid users before brute forcing, and verify open-relay test results before documenting — to lift workflow clarity.

Split the large reference material (response-code/command tables, Security Recommendations) into one-level-deep reference files to improve progressive disclosure and reduce the inline token load.

DimensionReasoningScore

Conciseness

The body is mostly lean command reference material, but the Quick Reference tables and Examples section duplicate commands already shown in the phases, and the "Required Knowledge" list states concepts Claude already knows. It is efficient but could be tightened.

2 / 3

Actionability

Every phase provides concrete, copy-paste-ready commands with real flags and expected server responses (nmap, smtp-user-enum, hydra, openssl, dig, Metasploit modules), matching the fully-executable anchor.

3 / 3

Workflow Clarity

The 10-phase sequence is clearly ordered, but batch/sensitive operations (user enumeration, brute force, sending relay-test emails) lack embedded validation checkpoints between phases, which caps workflow clarity at 2 per the rubric.

2 / 3

Progressive Disclosure

The skill is a ~500-line monolith with no bundle files; well-organized into sections, but content that could be split out (Quick Reference tables, Examples, Security Recommendations) is all inline rather than referenced one level deep.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, concise, and supplies both an explicit "when" trigger list and a clear statement of what the skill does. Trigger terms are natural and specific to the SMTP security-testing domain.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions via quoted triggers — "enumerate email users", "test for open mail relays", "grab SMTP banners", "brute force email credentials" — matching the anchor for several specific concrete actions.

3 / 3

Completeness

It explicitly answers both what ("provides comprehensive techniques for testing SMTP server security") and when ("This skill should be used when the user asks to...") with explicit triggers.

3 / 3

Trigger Term Quality

Natural phrases a user would actually say are quoted directly ("perform SMTP penetration testing", "grab SMTP banners", "brute force email credentials"), giving good coverage of common variations.

3 / 3

Distinctiveness Conflict Risk

The SMTP-penetration-testing niche is clearly scoped with distinct triggers, making it unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (501 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.