CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-tools

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

66%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, actionable pentest toolkit with concrete commands and a gated workflow, but it is on the verbose side and references several paths (payloads/, templates/, src-hunter/, precedent-pentest.md, scope-contract.md) that do not exist in the provided bundle, weakening progressive disclosure and conciseness.

Suggestions

Remove or move out of SKILL.md the duplicated manual-install template and full MCP docker blocks — they belong in references/ — to tighten conciseness.

Inline at least one explicit validation/verification checkpoint per workflow phase (e.g., 'confirm finding is reproducible before recording as Evidence') rather than delegating all gating to references/pentest-loop.md, to push workflow clarity to 5.

Fix broken references: either add the missing payloads/, templates/, src-hunter/ directories and the ../field-journal, ../ops, ../tool-index, ../scripts paths, or remove those citations so navigation matches the actual bundle.

DimensionReasoningScore

Conciseness

The body is mostly efficient (tables of tools with one-line commands) but contains padded sections — the full MCP installation blocks, manual-install guidance template, and external-resource lists restate info Claude largely already knows or that lives in referenced files, which could be trimmed.

3 / 5

Actionability

Concrete executable commands abound (nmap -sV -sC, sqlmap --batch --dbs, ffuf -u target/FUZZ -w, hashcat -m 0) and MCP registration JSON is copy-paste ready; minor gaps are placeholders like '通过 API 或 MCP 调用' and Metasploit needing separate install.

4 / 5

Workflow Clarity

A clear 5-step standard pentest flow plus a 4-step quick-scan flow is present, with authorization/scope gating (ACTION REQUIRED: confirm scope.md auth.status=granted) and a completion self-check; it falls short of 5 because validation/verify-checkpoints within each phase are largely delegated to references rather than inline, and the pentest-loop.md framework is referenced rather than embedded.

4 / 5

Progressive Disclosure

References are one-level-deep and mostly real (pentest-loop.md, recon-pipeline.md, client-side-lab-playbook.md, burpsuite-mcp-guide.md all exist in references/), but several referenced paths do not exist in the bundle (payloads/, templates/, src-hunter/, ../field-journal/precedent-pentest.md, ../ops/scope-contract.md, ../tool-index.md, ../scripts/append-evidence.ps1, automation-loop-pattern.md is referenced as a file but the '本 skill 内参考文档' lists it), and structure mixes inline tool matrices with external pointers, leaving navigation partly unclear.

3 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill does and when to use it, with an explicit trigger-keyword line covering natural user phrasings and tool names. It is concise, third-person, and well-targeted to its niche.

DimensionReasoningScore

Specificity

Lists many concrete actions — '信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解' — and names 20+ specific tools (Nmap, Nuclei, SQLMap, FFUF, Hashcat, ZAP, Burp), giving comprehensive coverage of the domain.

5 / 5

Completeness

Clearly answers 'what' ('主动渗透测试工具链…通过 MCP server 将 20+ 安全工具暴露给 AI agent') and 'when' (explicit 触发关键词 / trigger-keywords clause naming the scenarios), matching the anchor that requires concrete trigger phrases for both.

5 / 5

Trigger Term Quality

The explicit '触发关键词' line provides comprehensive natural-language terms users would actually say (渗透测试、端口扫描、Nmap、SQL 注入、目录爆破、密码破解、子域名) plus concrete tool names as synonyms.

5 / 5

Distinctiveness Conflict Risk

The active-offensive-pentest niche (port scanning, exploitation, injection, hash cracking via named tools) is distinct from reverse-engineering or browser-automation skills, with minimal conflict risk given the specific trigger terms.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.