CtrlK
BlogDocsLog inGet started
Tessl Logo

adversary-emulation

Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

92%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly actionable skill body with a clear validated methodology; its only structural gap is that the existing reference bundle files (IOC and CVE-to-APT mappings) are not linked from the SKILL.md overview. Signaling those references would complete the progressive-disclosure picture.

Suggestions

Add a '## References' section linking references/anyrun-free-iocs.md and references/cve-apt-mapping.md so the available bundle material is discoverable from the overview.

Optionally move the 22-row actor catalog into a references file and keep a condensed pointer in SKILL.md, since the catalog is reference data rather than methodology.

Make the scope-validation step an explicit validate→fix→retry loop (e.g. 'if a planned TTP is out of RoE, down-scope and re-confirm before proceeding') to strengthen the error-recovery feedback path.

DimensionReasoningScore

Conciseness

Lean and information-dense — a tight emulation/pentest distinction, a RoE warning, a 5-step methodology, and a catalog of attributed actors — with no padding of generic concepts Claude already knows, so it earns 3 rather than 'mostly efficient but could be tightened' (2).

3 / 3

Actionability

Gives concrete, copy-ready guidance — `load_skill <slug>` with a worked example, `ask_user_question`, the explicit kill-chain sequence to walk, and 'cite the ATT&CK ID' — which is actionable instruction rather than vague direction or pseudocode (2).

3 / 3

Workflow Clarity

A clear 5-step sequence (Select → Load → Scope → Emulate → Measure) with explicit validation gates in the destructive context — step 3's scope intersection, tool-call-time out-of-scope checks, and canary substitution for wipers — so validation is present, not missing (which would cap it at 2).

3 / 3

Progressive Disclosure

The body is well-organized as an overview, but the two bundle files present in references/ (anyrun-free-iocs.md, cve-apt-mapping.md) are never referenced or signaled from SKILL.md, matching the anchor 'references present but not clearly signaled' rather than the well-signaled one-level-deep ideal (3).

2 / 3

Total

11

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, distinctive description with strong trigger-term coverage and concrete actions, weakened only by the absence of an explicit 'Use when...' trigger clause. Adding an explicit usage trigger would lift completeness to full marks.

Suggestions

Append an explicit 'Use when...' clause naming concrete triggers (e.g. 'Use when emulating a named threat actor, running a purple-team/ATT&CK evaluation, or replaying a group's TTPs within RoE scope').

Expand trigger phrasings inside the description itself rather than relying solely on the metadata when_to_use field.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response' — matching the anchor for several specific concrete actions; it is not merely naming a domain (2).

3 / 3

Completeness

Clearly answers 'what' (threat-informed adversary emulation reproducing TTPs) but provides no explicit 'Use when...' clause or equivalent trigger guidance, so per the judging guidelines completeness is capped at 2 rather than 3.

2 / 3

Trigger Term Quality

Covers natural terms a user would say — 'adversary emulation', 'emulate APT', 'threat actor', 'threat-informed', 'mimic adversary' — giving good coverage rather than only jargon or a single keyword (2).

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche — 'Threat-informed adversary emulation' reproducing a named actor's TTPs within RoE scope — with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.