CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t14-infra-warfare

AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t14-infra-warfare/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

87%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise and actionable, with an executable probe pattern and concrete defender guidance. Its main gap is the absence of an explicit validate-then-proceed workflow with checkpoints for the probe/monitor cycle.

Suggestions

Add a short sequenced probe workflow with a validation checkpoint, e.g. run spike test -> confirm cost/latency signal -> escalate batch size -> re-measure, capping at a defined budget.

Add an explicit budget/safety cap before running the probe command so destructive load-testing cannot run away.

Consider noting when to stop and document findings (a feedback loop) after the monitor step.

DimensionReasoningScore

Conciseness

The body is dense and lean — terse technique bullets, a compact probe snippet, a severity table, and targeted defender controls — with no padding or explanation of concepts Claude already knows.

3 / 3

Actionability

It provides an executable copy-paste `hey` probe command, specific monitoring metrics (cost/min, p99 latency, 429/503 rate), and concrete defender controls (enforced max_tokens, 60s streaming timeout), meeting the fully-executable anchor.

3 / 3

Workflow Clarity

Sections are organized (techniques, probe, detection, severity, defender) but there is no explicit sequenced workflow with validation/feedback checkpoints, and this multi-technique catalog is not a single-action skill that the simple-skill exception covers.

2 / 3

Progressive Disclosure

It is a single self-contained file with clear section navigation and no nested or broken references; no bundle files are present to verify, and the cross-references point appropriately to sibling skills.

3 / 3

Total

11

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and occupies a distinct niche, but it leans on technical jargon for trigger terms and omits an explicit 'Use when...' guidance clause. Adding natural-language trigger phrasing and a usage trigger would raise completeness and trigger-term quality.

Suggestions

Append an explicit trigger clause, e.g. 'Use when assessing LLM endpoint availability, cost-abuse, or economic-DoS risk.'

Soften jargon toward terms users naturally say, e.g. 'API cost spikes' alongside 'model-API account exhaustion'.

Add common trigger variations (rate limits, quota exhaustion, cost amplification) to improve natural-keyword coverage.

DimensionReasoningScore

Specificity

The description lists multiple concrete attack vectors — 'Endpoint DoS via expensive prompts', 'model-API account exhaustion', 'GPU resource starvation', 'billing weaponization' — matching the anchor for multiple specific concrete actions.

3 / 3

Completeness

It clearly states what the skill covers but contains no 'Use when...' clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 2.

2 / 3

Trigger Term Quality

It mixes natural terms a user might say (DoS, billing, GPU) with technical jargon ('model-API account exhaustion', 'billing weaponization') and lacks common phrasings, so it is not the full-coverage level 3.

2 / 3

Distinctiveness Conflict Risk

The 'Infrastructure & Economic Warfare' framing with LLM-specific cost dynamics is a clear niche unlikely to trigger for unrelated skills, despite minor overlap with classical DoS.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.