CtrlK
BlogDocsLog inGet started
Tessl Logo

aatmf-t14-infra-warfare

AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/plugins/llm-redteam/t14-infra-warfare/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a concise, well-structured overview with a concrete probe command and clear detection/severity/defender sections, but it lacks explicit validation checkpoints for its batch/load-testing workflow and a few techniques are described without runnable guidance.

Suggestions

Add an explicit workflow with validation checkpoints for the probe pattern, e.g. '1. Baseline cost/latency → 2. Run spike → 3. Verify error-rate/other-tenant impact captured → 4. Only scale concurrency if metrics are meaningful' to lift workflow clarity above the destructive/batch cap of 3.

Give each technique at least one concrete probe or detection query (e.g. a streaming-slot script for T14.007, a cache-thash payload for T14.006) rather than description-only bullets.

Consider splitting the per-technique detail into a references/ file and keeping SKILL.md as a tighter index, which would push progressive disclosure toward 5.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — technique bullets and a tight probe snippet with no padding or explanation of basic DoS/cost concepts, with only minor phrases ('Adjacent to classical DoS but LLM-specific cost dynamics') that could be trimmed.

4 / 5

Actionability

Provides a concrete, executable hey-based spike-test command with real flags and a payload-generation trick, plus specific detection signals and defender mitigations; gaps are that some techniques (T14.002, T14.005, T14.006) give only direction without a runnable probe.

4 / 5

Workflow Clarity

A rough load-test sequence is implied (pick tool, run spike, monitor metrics) and detection/severity/defender sections order the analysis, but there is no explicit validate-then-proceed checkpoint, and for batch/load operations the rubric caps workflow clarity at 3 when validation feedback loops are absent.

3 / 5

Progressive Disclosure

Well-organized single-file overview with clear section headers (Techniques, Probe pattern, Detection, Severity, Defender, Cross-references); no bundle files exist so no nested references to verify, and the inlined content is appropriately scoped for an overview with only minor bulk that could live in a reference file.

4 / 5

Total

15

/

20

Passed

Description

56%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a clear niche and several concrete vectors but is written as a taxonomy label rather than a user-facing trigger description, omitting any 'Use when...' guidance and leaning on specialist jargon over natural user phrasing.

Suggestions

Add an explicit trigger clause, e.g. 'Use when planning or assessing infrastructure/economic attacks against LLM endpoints — cost amplification, GPU starvation, account/quota exhaustion, billing abuse.'

Soften jargon with natural synonyms a user might say (e.g. 'cost/billing attacks', 'denial of service', 'rate/budget exhaustion') to improve trigger-term quality.

Keep the AATMF T14 niche tag but lead with a plain-language action statement so the 'what' reads as a skill capability rather than a taxonomy entry.

DimensionReasoningScore

Specificity

Lists several concrete attack vectors ('Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization') rather than vague abstractions, though it enumerates capabilities more than naming discrete actions a skill performs.

4 / 5

Completeness

The 'what' is clear (infrastructure/economic warfare techniques), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

Uses specialist jargon ('AATMF T14', 'GPU resource starvation', 'billing weaponization') with a few natural-ish phrases ('Endpoint DoS', 'account exhaustion') but lacks the common phrasings and synonyms a user would naturally speak when requesting this skill.

3 / 5

Distinctiveness Conflict Risk

The 'AATMF T14 — Infrastructure & Economic Warfare' niche is fairly distinct and tied to a specific tactic ID, with only minor overlap risk against adjacent cost/abuse skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.