CtrlK
BlogDocsLog inGet started
Tessl Logo

wordpress-penetration-testing

This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/wordpress-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced command reference for WordPress pentesting, with copy-paste-ready examples at every phase. Its weaknesses are token efficiency (duplicated path/flag tables and repeated command listings), no validation checkpoints in the destructive brute-force and exploitation phases, and a fully monolithic 480-line structure with no progressive disclosure into reference files.

Suggestions

Deduplicate the reference material: the 'Common WordPress Paths' table repeats the Phase 1 file listing and the WPScan flag table repeats the Phase 7 inline comments — keep each in one place only.

Add explicit validation/verification checkpoints to the risky workflows (e.g., confirm a credential works before launching wp_admin_shell_upload, verify webshell access with a harmless command like `id` before use, and stop brute-force on lockout signals), integrating the existing Troubleshooting guidance into the workflow steps.

Split the SKILL.md into an overview plus one-level-deep reference files (e.g., references/wpscan-flags.md for the Quick Reference tables, references/exploitation.md for Metasploit and manual webshell techniques, references/troubleshooting.md) to reduce the monolithic body.

DimensionReasoningScore

Conciseness

The body is mostly lean command examples rather than concept explanations, but contains clear duplication: WordPress paths are listed in Phase 1 and again verbatim in the 'Common WordPress Paths' table, WPScan enumeration flags are explained in Phase 7 comments and repeated in the Quick Reference table, and there is unsolicited padding like "WordPress powers approximately 35% of websites". Not a 2 because there is no explanation of concepts Claude already knows; not a 4 because the duplicated tables and repeated wpscan invocations could be meaningfully trimmed.

3 / 5

Actionability

Fully executable, copy-paste-ready commands throughout: curl probes, wpscan invocations with real flags, nmap scripts, Metasploit module configurations, and complete PHP webshell code. Specific examples cover the common cases for every phase of the workflow.

5 / 5

Workflow Clarity

Phases 1-10 are clearly sequenced (discovery → enumeration → exploitation), but the batch password-attack and destructive exploitation workflows include no validation or verification checkpoints — per the rubric guideline, missing validation for destructive/batch operations caps workflow clarity at 3. The Troubleshooting section offers some error-recovery guidance but it is disconnected from the workflow steps, so a 4 is not warranted.

3 / 5

Progressive Disclosure

Section structure is good with clear headers and a Quick Reference, but the ~480-line skill is entirely monolithic with no bundle files at all — reference material (enumeration flag tables, common paths, XML-RPC exploitation detail, troubleshooting) that clearly belongs in separate files is inlined. It is above a 2 because the structure is not minimal or buried, but below a 4 because nothing is offloaded and there are no references to split content into.

3 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an excellent, explicit trigger clause containing natural user phrasings and a clearly distinct niche. The main weakness is the vague, buzzword-heavy capability statement ('comprehensive WordPress security assessment methodologies') that under-specifies what the skill actually does compared to its well-crafted 'when' clause.

DimensionReasoningScore

Specificity

The description lists several concrete actions ("scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", "use WPScan"), though the capability statement "provides comprehensive WordPress security assessment methodologies" is generic buzzword phrasing. Not a 5 because the 'what' leans on 'comprehensive' over-claiming rather than enumerating capabilities directly; clearly above a 3 since more than 1-2 specific actions are named.

4 / 5

Completeness

Both halves are present: an explicit "This skill should be used when the user asks to..." trigger clause with concrete phrases, and a "what" statement. Not a 5 because the 'what' ("provides comprehensive WordPress security assessment methodologies") is vague and does not concretely state capabilities like the trigger clause does.

4 / 5

Trigger Term Quality

Quoted phrases like "pentest WordPress sites", "scan WordPress for vulnerabilities", and "use WPScan" are exactly what a user would naturally say, including the tool name. Not a 5 because common synonyms such as "WordPress security audit" or "harden WordPress" are absent; well above a 3 since both the natural phrasings and tool keyword are covered.

4 / 5

Distinctiveness Conflict Risk

The niche is unambiguous — WordPress penetration testing with named tooling (WPScan) — so it is clearly distinguishable from generic web-testing or other security skills with minimal conflict risk.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.