CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t07-output-exfil

AATMF T7 — Output Manipulation & Exfiltration. Covert channels in output, schema break, exfil via image gen, side-channel via timing.

53

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t07-output-exfil/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a concise, well-organized single-file technique catalog that assumes Claude's competence and needs no external references. Its weaknesses are actionability and workflow clarity: it describes attacker techniques more than it gives executable testing procedures, and the probing workflow lacks explicit validation checkpoints.

Suggestions

Add a concrete, executable test harness or step-by-step probing procedure (e.g., example commands for running the listed plugins and checking interactsh/Burp Collaborator callbacks) to move from descriptive catalog to actionable playbook.

Insert an explicit validation loop for the probe workflow — run probe → confirm detection signal fired → confirm OOB callback received → classify severity — with checkpoints before escalating, to lift workflow_clarity above 2.

Provide at least one fully worked example (complete injection prompt + expected model output + the detection signal it should trigger) so Claude can execute a technique end-to-end.

DimensionReasoningScore

Conciseness

The body is lean and bullet-driven ('First-letter encoding', 'Whitespace patterns', 'U+200B'), uses terse notation ('w/', '→', 'exfil'), and never over-explains concepts Claude already knows, so every token earns its place.

3 / 3

Actionability

Concrete elements exist (a probe-pattern YAML block, specific exfil URL examples, and detection signals), but the bulk is descriptive enumeration of attacker techniques rather than a complete executable test harness or step-by-step procedure Claude can run end-to-end.

2 / 3

Workflow Clarity

T7.006 lays out a clear Step 1/2/3 sequence and the probe→detect→severity flow is implied, but there are no explicit validation/verification checkpoints for the risky probing workflow, which caps workflow clarity at 2 per the scoring notes.

2 / 3

Progressive Disclosure

The skill is a single self-contained file with well-organized sections (Techniques, Probe pattern, Detection signals, Severity, Defender, Cross-references), no nested or broken references, and no bundle files needing navigation, so the well-structured single-file organization scores full marks.

3 / 3

Total

10

/

12

Passed

Description

50%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific to its security niche and lists concrete technique categories, but it lacks an explicit 'Use when...' trigger clause, leans on framework jargon, and reads as a topic label rather than action-led guidance. These factors hold every dimension at the mid-level anchor.

Suggestions

Add an explicit 'Use when...' trigger clause, e.g. 'Use when assessing output-side data exfiltration, covert channels in LLM output, or side-channel leakage via timing or image generation', to raise completeness above 2.

Replace framework jargon ('AATMF T7', 'schema break', 'exfil') with natural user-facing terms and their common variations ('data exfiltration', 'output leakage', 'structured-output injection') to improve trigger_term_quality.

Lead with concrete action verbs describing capabilities (e.g. 'Identifies, probes, and rates output-side exfiltration techniques...') to lift specificity and reduce overlap with sibling AATMF tactics.

DimensionReasoningScore

Specificity

The description names the domain ('Output Manipulation & Exfiltration') and several concrete technique areas ('Covert channels in output, schema break, exfil via image gen, side-channel via timing'), but these read as a noun-phrase topic enumeration rather than concrete action verbs Claude would take, so it sits at 'names domain and some actions' rather than a full action list.

2 / 3

Completeness

It clearly states what the skill covers but provides no explicit 'Use when...' trigger clause or equivalent guidance, which per the judging guidelines caps completeness at 2.

2 / 3

Trigger Term Quality

It includes some natural security terms ('exfiltration', 'covert channel', 'side-channel', 'image gen') but mixes them with framework jargon ('AATMF T7', 'schema break', 'exfil'), missing common user-facing variations that would broaden trigger coverage.

2 / 3

Distinctiveness Conflict Risk

The output-side exfil niche is reasonably distinct from generic skills, but the framework-internal 'AATMF T7' naming and topical overlap with sibling tactics (T10 confidentiality breach, T11 agentic exploit) mean it could still collide within its own skill family.

2 / 3

Total

8

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.