CtrlK
BlogDocsLog inGet started
Tessl Logo

ssh-penetration-testing

This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tunneling", or "audit SSH security". It provides comprehensive SSH penetration testing methodologies and techniques.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/ssh-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable — every phase is executable copy-paste commands — but it is a padded 480-line monolith that restates well-known SSH knowledge with redundant tool variants, and its batch/destructive operations lack validation checkpoints. Splitting reference material into bundle files and trimming to non-obvious content would address both weaknesses.

Suggestions

Trim redundant tool variants (keep 2-3 representative Hydra/Medusa invocations) and drop the "Required Knowledge" and port-forwarding-syntax explanations that restate what Claude already knows; target the non-obvious content (ssh-audit interpretation, CVE-specific techniques, evasion flags).

Add validation checkpoints to the workflow: verify found credentials with a single confirmed login before post-exploitation, and confirm written authorization as an explicit Phase 0 gate before any active attacks.

Move the full Paramiko script, the Metasploit module catalog, and the quick-reference tables into references/ files (e.g. references/scripts.md, references/metasploit.md) linked from SKILL.md, keeping the body as a lean overview.

DimensionReasoningScore

Conciseness

The ~480-line body restates knowledge Claude already has: a "Required Knowledge" section listing "SSH protocol fundamentals / Public/private key authentication / Port forwarding concepts", seven near-duplicate Hydra variants, four Medusa variants, and full explanations of standard ssh -L/-R/-D syntax. Not 1 because the content is accurate and organized, but the padding and redundancy are extensive.

2 / 5

Actionability

Every phase gives copy-paste-ready commands (nmap NSE invocations with script-args, hydra/medusa syntax including port and timing flags, a complete runnable Paramiko script) covering the common cases. Fully executable with no pseudocode.

5 / 5

Workflow Clarity

Phases 1-10 are clearly sequenced, but the workflow involves batch and destructive operations (brute-force runs, appending a key to ~/.ssh/authorized_keys for persistence) with no validation or verification checkpoints — e.g. verifying credentials before post-exploitation or confirming authorization before attacks. Per the rubric cap, destructive/batch workflows without validation cannot score above 3.

3 / 5

Progressive Disclosure

Section headers and quick-reference tables provide reasonable structure, but it is a monolithic single file with zero external references; the full Paramiko script and the Metasploit module catalog are inlined where they belong in separate reference files. Not 2 because the internal structure is genuinely well-organized, not 4 because nothing is split out.

3 / 5

Total

13

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has strong, natural trigger phrases and a clearly distinct SSH-pentest niche, but its capability statement relies on generic filler ("comprehensive methodologies and techniques") instead of concretely stating what it does. The enumerated trigger actions do most of the descriptive work.

Suggestions

Replace "It provides comprehensive SSH penetration testing methodologies and techniques" with a concrete enumeration, e.g. "Covers SSH service discovery, configuration auditing with ssh-audit, credential attacks with Hydra/Medusa, known-CVE exploitation, and port-forwarding/pivoting techniques."

Add common synonyms to the trigger list such as "SSH port forwarding", "SSH pivoting", or "check SSH hardening" to improve natural-term coverage.

DimensionReasoningScore

Specificity

Quotes six concrete actions ("pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tunneling", "audit SSH security"), but the capability statement itself ("comprehensive SSH penetration testing methodologies and techniques") is generic. Not 5 because the 'what' is padded rather than concrete; not 3 because the enumerated actions give broad, specific coverage.

4 / 5

Completeness

The 'when' is explicit with quoted trigger phrases, but the 'what' ("provides comprehensive SSH penetration testing methodologies and techniques") is vague. Not 5 because anchor 5 requires both halves to be concrete; not 4→3 because the enumerated action list substantially answers 'what' beyond a weak implication.

4 / 5

Trigger Term Quality

Natural phrases a user would say ("brute force SSH credentials", "perform SSH tunneling", "audit SSH security") are present and well-phrased. Not 5 because common synonyms like "port forwarding", "SSH hardening review", or "password spraying" are missing.

4 / 5

Distinctiveness Conflict Risk

Every trigger contains "SSH" and names the exact activity, carving a clear niche with minimal overlap risk against general networking or pentest skills. Matches the anchor-5 example's pattern of distinct, file/protocol-specific triggers.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.