CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t13-supply-chain

AATMF T13 — AI Supply Chain & Artifact Trust. Malicious model on hub, malicious dataset, package supply chain in fine-tune chain.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t13-supply-chain/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-structured, token-efficient catalog of AI supply-chain techniques with clear sections and mitigations. Its weakness is actionability and workflow clarity: it describes attacks more than it instructs how to execute or verify probes.

Suggestions

Convert the 'Probe pattern' bullets into a numbered, sequenced workflow with explicit validation checkpoints (e.g., verify hash -> run safetensors-only check -> audit dependencies -> re-verify).

Add concrete, copy-paste-ready commands or code snippets for the highest-value probes (e.g., a hash-verification command for HuggingFace, a safetensors-only loading snippet).

Provide a short actionable procedure per technique family rather than purely descriptive summaries.

DimensionReasoningScore

Conciseness

The body is lean and terse, using compact notation ('w/', '=', arrows) and bullet lists without explaining concepts Claude already knows; every section earns its place.

3 / 3

Actionability

Mostly a descriptive attack catalog; it offers some concrete commands ('npm audit', 'pip-audit', 'revision="<commit-sha>"') but no complete, executable procedures for probing or exploiting each technique.

2 / 3

Workflow Clarity

The 'Probe pattern' section is a checklist rather than a sequenced workflow, and it lacks explicit validation checkpoints or feedback loops for batch/destructive audit operations.

2 / 3

Progressive Disclosure

A self-contained, well-organized document with clear sections and a single one-level cross-reference that is clearly signaled; no nested references or bundle files to navigate.

3 / 3

Total

10

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description establishes a specific, distinguishable niche around AI supply-chain attacks but reads more as a topic enumeration than an action-oriented trigger. It is missing explicit 'use when' guidance, which limits its completeness.

Suggestions

Add an explicit 'Use when...' clause with natural trigger terms (e.g., 'Use when investigating malicious models on HuggingFace/Ollama, poisoned datasets, or MCP package supply-chain attacks').

Lead with action verbs ('Audits', 'Probes', 'Detects') instead of noun phrases to better convey concrete capabilities.

Drop or de-emphasize internal taxonomy jargon ('AATMF T13', 'Artifact Trust') in favor of terms a user would naturally say.

DimensionReasoningScore

Specificity

Names concrete artifacts and threats ('Malicious model on hub, malicious dataset, package supply chain in fine-tune chain') but uses no action verbs, so it lists specifics rather than concrete actions.

2 / 3

Completeness

Clearly states what the skill covers (supply-chain attack vectors) but lacks any 'Use when...' trigger clause, capping completeness at 2 per the guidelines.

2 / 3

Trigger Term Quality

Includes relevant terms like 'supply chain', 'malicious model', and 'fine-tune', but mixes in taxonomy jargon ('AATMF T13', 'Artifact Trust') and omits common variations a user would naturally say.

2 / 3

Distinctiveness Conflict Risk

Targets a clear niche (AI supply-chain and artifact trust) with distinct triggers, making it unlikely to fire for the wrong skill.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.