CtrlK
BlogDocsLog inGet started
Tessl Logo

pentest-tools

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-gated pentest skill body with concrete commands and explicit authorization/completion checkpoints. Its main weaknesses are length/inline material that could be offloaded to references and several referenced bundle paths that do not actually exist.

Suggestions

Move the inline MCP registration JSON and the manual-install bootstrap block into a reference file, keeping only a one-line pointer in SKILL.md to tighten conciseness.

Resolve the dangling bundle references — either add the missing 'payloads/', 'templates/', 'src-hunter/', and 'scripts/append-evidence.ps1' or remove/relabel them so every referenced path exists.

Collapse the '快速扫描流程' into the standard flow (or mark it as a quick-reference pointer) to remove duplication.

DimensionReasoningScore

Conciseness

Mostly efficient command tables and workflows, but the ~280-line body keeps inline material that could live in references (full MCP registration JSON, the manual-install 引导 block, external-links list) and the '快速扫描流程' partly duplicates the standard flow — 'mostly efficient but could be tightened'.

2 / 3

Actionability

Dense with copy-paste-ready, executable commands — 'nmap -sV -sC -O target', 'nuclei -u target -t cves/', 'sqlmap -u "url?id=1" --batch --dbs', docker pull/run, pip install — matching 'fully executable code/commands; copy-paste ready'.

3 / 3

Workflow Clarity

Clear sequenced flows plus explicit validation gates — the ACTION REQUIRED block (verify auth.status=granted, scope.md, tool-index paths), '手动验证 → 确认可利用性', a failure latch ('未打穿也要写 observed Evidence + 失败门闩'), and a 'MUST 通过' completion checklist — satisfy 'explicit validation steps, feedback loops, checklists'.

3 / 3

Progressive Disclosure

Provided references are well-signaled one level deep with one-line descriptions in '本 skill 内参考文档' (and verified present), but several in-skill paths the body points to — 'payloads/', 'templates/', 'src-hunter/', '../scripts/append-evidence.ps1' — are absent from the bundle, weakening navigation.

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, third-person description that names concrete capabilities, exposes a rich set of natural trigger terms, and signals a distinct active-pentest niche. It answers both 'what' and 'when' without padding.

DimensionReasoningScore

Specificity

Lists multiple concrete scenarios/actions — '信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解' — plus the concrete mechanism '通过 MCP server 将 20+ 安全工具暴露给 AI agent', matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Clearly states what it does ('主动渗透测试工具链') and provides equivalent explicit trigger guidance via the '触发关键词' line, so the 'when' is explicit rather than missing or implied; not capped at 2 because a Use-when-equivalent clause is present.

3 / 3

Trigger Term Quality

A dedicated '触发关键词' line gives broad natural-term coverage users would actually say — '渗透测试、端口扫描、Nmap、Nuclei、SQL 注入、SQLMap、FFUF、Hashcat、ZAP、Burp' — matching the 'good coverage of natural terms' anchor.

3 / 3

Distinctiveness Conflict Risk

A clear active-pentest niche anchored to specific tool names (Nmap/Nuclei/SQLMap/Hashcat) is unlikely to trigger for adjacent skills; matches the 'clear niche with distinct triggers; unlikely to conflict' anchor.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.