CtrlK
BlogDocsLog inGet started
Tessl Logo

smtp-penetration-testing

This skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP banners", "brute force email credentials", or "assess mail server security". It provides comprehensive techniques for testing SMTP server security.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/smtp-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable and well-sequenced: every phase gives executable commands with expected outputs, and error recovery is addressed via a troubleshooting table. The skill is dragged down by verbosity — re-explained SMTP basics, redundant multi-tool variants, and an Examples section that duplicates the core workflow — and by a complete absence of progressive disclosure, with everything inlined in one ~490-line file.

Suggestions

Remove or drastically shrink content Claude already knows: the SMTP architecture/ports primer (Phase 1), the basic SMTP command table, and the standard response-code table.

Split the Examples section, Quick Reference tables, and per-tool variant commands into references/ files (e.g., references/examples.md, references/quick-reference.md), leaving SKILL.md as a lean phased workflow that links to them.

Dedupe multi-tool variants — pick one primary tool per task (e.g., smtp-user-enum for enumeration, hydra for brute force) and move alternates to a single comparison table.

DimensionReasoningScore

Conciseness

The body re-teaches concepts Claude already knows (Phase 1's MTA/MDA/MUA architecture and port list, the HELO/EHLO/MAIL FROM command table, and standard 220/250/550 response codes), and the ~75-line Examples section repeats the core workflow phases nearly verbatim, plus three redundant tool variants per task — noticeably verbose with several padded sections.

2 / 5

Actionability

Commands throughout are copy-paste ready (nmap script invocations, smtp-user-enum with method flags, hydra with port/SSL options, openssl s_client, dig lookups) with expected outputs and interpretation guidance ('If accepted (250 OK), server is open relay', '250 OK = user exists'), and the examples cover the common assessment cases end to end.

5 / 5

Workflow Clarity

Ten clearly sequenced phases run from discovery through SPF/DKIM/DMARC analysis, and the troubleshooting table plus response-code decision points provide error recovery; however, there are no explicit validate-checkpoint steps (e.g., confirm relay finding before reporting, verify enumeration coverage), so it sits below the 'explicit validation steps with feedback loops' anchor.

4 / 5

Progressive Disclosure

There is good in-file structure with clearly labeled phases and tables, but the ~490-line body is monolithic — the quick-reference tables, per-tool variant commands, and full worked examples clearly belong in separate reference files, and no bundle files exist at all. Structure saves it from anchor 2, but the lack of any file splitting keeps it below anchor 4.

3 / 5

Total

14

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong trigger-focused description with excellent explicit 'when' guidance and natural quoted phrases in third-person voice. Its main weakness is the vague capability statement — 'comprehensive techniques' — which forces the reader to infer what the skill actually does from the trigger quotes.

Suggestions

Replace 'It provides comprehensive techniques for testing SMTP server security' with a concrete capability list, e.g., 'Banners grabbing, user enumeration (VRFY/EXPN/RCPT), open relay testing, credential brute force, and SPF/DKIM/DMARC analysis for SMTP servers.'

Add a few more natural trigger synonyms such as 'check for open relay', 'mail server security', or 'SMTP enumeration' to broaden when-clause coverage.

DimensionReasoningScore

Specificity

The capability statement 'It provides comprehensive techniques for testing SMTP server security' is generic; the concrete actions (open relay testing, banner grabbing, brute force, user enumeration) appear only inside quoted user-trigger phrases rather than as the skill's own capability list, matching the 'names domain and 1-2 concrete actions' anchor rather than the 'lists several specific actions' anchor.

3 / 5

Completeness

The 'when' is explicit and strong ('should be used when the user asks to...' with concrete trigger phrases), and a 'what' is present, but the what-clause ('comprehensive techniques') is vague, so it falls short of the anchor requiring both what and when to be concrete and explicit.

4 / 5

Trigger Term Quality

Six natural quoted phrases ('perform SMTP penetration testing', 'enumerate email users', 'test for open mail relays', 'grab SMTP banners', 'brute force email credentials', 'assess mail server security') with synonym coverage (SMTP / mail server), but a few common variations (e.g., 'mail server', 'SMTP enumeration', port-specific phrasing) are missing.

4 / 5

Distinctiveness Conflict Risk

SMTP penetration testing is a clear niche with distinct protocol-specific triggers (open mail relays, SMTP banners, email credential brute force) and minimal overlap risk with other skills; no neighboring anchor fits better.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (501 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.