CtrlK
BlogDocsLog inGet started
Tessl Logo

wordpress-penetration-testing

This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/wordpress-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A comprehensive, highly actionable WordPress pentesting skill with strong executable examples and clear phase sequencing. Its main weaknesses are length/verbosity, the absence of validation checkpoints in destructive workflows, and a monolithic structure that should be split into referenced files.

Suggestions

Add explicit validation checkpoints to the destructive phases (e.g., confirm authorized scope and verify exploit success before proceeding) so brute-force, shell-upload, and exploitation workflows include a validate-then-act feedback loop.

Split the document into a lean overview in SKILL.md with one-level-deep references (e.g., enumeration.md, exploitation.md, quick-reference.md, troubleshooting.md) to improve progressive disclosure and reduce token load.

Trim redundant content such as the Quick Reference tables that duplicate inline commands, and remove the unsolicited market-share framing ("WordPress powers approximately 35% of websites") that does not aid execution.

DimensionReasoningScore

Conciseness

The body is mostly efficient command/code, but it runs ~480 lines with padded framing ("WordPress powers approximately 35% of websites, making it a critical target") and duplicate Quick Reference tables that restate inline commands, so it could be tightened.

3 / 5

Actionability

Abundant copy-paste-ready, executable bash/PHP/XML-RPC examples covering discovery, enumeration, brute-force, and exploitation, matching the anchor for fully executable guidance across common cases.

5 / 5

Workflow Clarity

The ten phases are well sequenced, but destructive/batch operations (brute-force, shell upload, exploitation) lack explicit validate-then-proceed checkpoints or feedback loops, which the rubric caps at 3 for such operations.

3 / 5

Progressive Disclosure

The file has good section headers and a logical structure, but it is a monolithic ~480-line document with content (quick-reference tables, troubleshooting, advanced techniques) that clearly belongs in separate, one-level-deep reference files, and no external references are signaled.

3 / 5

Total

14

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, trigger-rich description written in third person that clearly conveys both purpose and invocation conditions with comprehensive natural-language keywords. The only minor weakness is a somewhat generic capability summary, but the enumerated actions compensate for it.

DimensionReasoningScore

Specificity

Lists several concrete actions via the trigger phrases ("pentest WordPress sites", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", "use WPScan") and names WPScan, but the capability statement ("comprehensive WordPress security assessment methodologies") is slightly generic, leaving minor gaps versus full enumeration.

4 / 5

Completeness

Explicitly answers both "what" ("comprehensive WordPress security assessment methodologies") and "when" with concrete trigger phrases, satisfying the highest anchor.

5 / 5

Trigger Term Quality

Comprehensive natural-language triggers including synonyms and the canonical tool name ("pentest", "scan", "enumerate", "exploit", "WPScan"), matching the anchor that expects coverage of natural terms and tool names.

5 / 5

Distinctiveness Conflict Risk

A clear WordPress-specific penetration-testing niche with distinct triggers (WPScan, WordPress enumeration) and minimal overlap risk with unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.