CtrlK
BlogDocsLog inGet started
Tessl Logo

analyst-overview

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/analyst/SKILL.md
SKILL.md
Quality
Evals
Security

Analyst Skill Catalog

The analyst has specialised playbooks under this tree. Load the one matching your current hunting lane — don't load them all at once.

Taint / source-review playbooks

Use when you have source code and are hunting a specific weakness class.

SkillUse for
/skills/standard/analyst/sql-injection/SKILL.mdString-concat + format-string → SQL sink
/skills/standard/analyst/ssrf/SKILL.mdUser-controlled URL reaches http client
/skills/standard/analyst/deserialization/SKILL.mdpickle / Java ObjectInputStream / .NET BinaryFormatter / YAML
/skills/standard/analyst/ssti/SKILL.mdUser input rendered by Jinja/Twig/Freemarker/Velocity
/skills/standard/analyst/xxe/SKILL.mdXML parser with external entity expansion enabled
/skills/standard/analyst/path-traversal/SKILL.mdUser input reaches filesystem path
/skills/standard/analyst/prototype-pollution/SKILL.mdJS merge / assign / clone of untrusted object
/skills/standard/analyst/command-injection/SKILL.mdUser input → shell, exec, system
/skills/standard/analyst/idor/SKILL.mdMissing authorization check on object reference
/skills/standard/analyst/auth-bypass/SKILL.mdBroken auth state machine, missing session checks
/skills/standard/analyst/prompt-injection/SKILL.mdLLM prompts built from untrusted input

Chain playbooks

Use when you have a bag of individual findings and want to combine them into a critical impact chain.

SkillUse for
/skills/standard/analyst/chains/ssrf-to-rce/SKILL.mdSSRF → metadata → IAM → RCE
/skills/standard/analyst/chains/xss-to-takeover/SKILL.mdSelf-XSS → CSRF → admin creds
/skills/standard/analyst/chains/cred-reuse/SKILL.mdLow-priv cred → service pivot → domain admin
/skills/standard/analyst/chains/idor-to-priv-esc/SKILL.mdIDOR on settings → role elevation

Workflow

  1. kg_stats — see what you already know.
  2. Identify the target's language / framework.
  3. Load the matching vuln-class skill (one or two per iteration).
  4. Run the skill's recipe, record findings as graph nodes.
  5. When enough vulns exist, load a chain playbook and call plan_attack_chains(promote=True) to persist any complete chains.
Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.