CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t11-agentic-exploit

AATMF T11 — Agentic & Orchestrator Exploitation. MCP tool poisoning, agent-to-agent prompt injection, tool-result spoofing, orchestrator state confusion.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t11-agentic-exploit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-sectioned reference taxonomy of agentic/orchestrator attack techniques with concrete probe patterns, detection signals, and defender mitigations. It is weakest in executable workflow guidance, lacking an explicit sequenced testing procedure with validation checkpoints.

Suggestions

Add an explicit ordered testing procedure with validation steps (e.g., 1. spin up malicious MCP server, 2. register with target agent, 3. confirm injection observed, 4. validate via audit log) to raise workflow clarity.

Make the probe pattern more directly executable by including a minimal runnable malicious-MCP-server snippet or a concrete command rather than only the YAML plugin config.

DimensionReasoningScore

Conciseness

Telegraphic bullet structure ("Attacker who controls an MCP server: Description... Implementation...") with minimal padding assumes domain competence and every section earns its place, matching the lean/efficient anchor; it does not pad with concepts Claude already knows.

3 / 3

Actionability

Provides some concrete guidance — a copy-pasteable YAML probe pattern, detection-signal and defender-mitigation lists — but the bulk describes attack concepts rather than giving fully executable instruction, matching "some concrete guidance but incomplete" rather than fully copy-paste-ready code.

2 / 3

Workflow Clarity

Sections are organized but there is no explicit multi-step testing workflow with validation checkpoints; the probe guidance is a config snippet plus a vague "build a malicious test MCP server + register it → observe behavior" instruction, matching the score-2 anchor and falling short of explicit validate-then-proceed checkpoints.

2 / 3

Progressive Disclosure

A well-organized single-file reference with clear section headers and no nested/deep references; no bundle files exist (references/scripts/assets absent) so the self-contained, well-sectioned structure is appropriate, matching the well-organized-with-clear-navigation anchor.

3 / 3

Total

10

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and clearly niched within the AATMF T11 category, enumerating concrete attack techniques. Its main weakness is the absence of an explicit "Use when..." trigger clause and trigger terms that lean technical rather than natural.

Suggestions

Append a "Use when..." clause naming natural user phrasings (e.g., "Use when testing agent/MCP security, tool-poisoning, or prompt-injection in multi-agent systems") to raise completeness and trigger-term quality.

Add common/natural trigger variations alongside the technical jargon (e.g., "MCP server attacks", "AI agent injection") so users would naturally say these terms.

DimensionReasoningScore

Specificity

Lists multiple concrete attack actions — "MCP tool poisoning", "agent-to-agent prompt injection", "tool-result spoofing", "orchestrator state confusion" — matching the anchor that enumerates several specific actions, and clearly above the score-2 anchor which only names a domain plus some actions.

3 / 3

Completeness

Clearly states what the skill covers but has no "Use when..." clause or equivalent explicit trigger guidance, so per the rubric cap it lands at "has what, but when is missing or only implied" rather than the score-3 anchor that answers both what and when.

2 / 3

Trigger Term Quality

Contains domain-relevant keywords ("MCP tool poisoning", "agent-to-agent prompt injection") but they skew toward technical jargon and omit common phrasings a user might naturally say, so it matches "some relevant keywords but missing common variations" rather than full natural-term coverage.

2 / 3

Distinctiveness Conflict Risk

The scoped designation "AATMF T11 — Agentic & Orchestrator Exploitation" carves a clear niche with distinct triggers unlikely to conflict with other skills, matching the score-3 anchor and clearly above the score-2 "could still overlap" anchor.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.