CtrlK
BlogDocsLog inGet started
Tessl Logo

apt10-stone-panda

Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor.

32

Quality

27%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

32%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is thorough and well-structured as an adversary reference, with a genuinely actionable emulation-mapping section and an authorized-use caveat. Its weakness is conciseness — it doubles as a CT encyclopedia rehashing known ATT&CK content — and the absence of bundle files leaves it monolithic.

Suggestions

Move the encyclopedic attribution, campaign history, full ATT&CK TTP catalog, and tool table into a references file (e.g., references/TTPS.md), keeping SKILL.md as a lean emulation-guidance overview with signaled links.

Add explicit validation checkpoints in the emulation guidance for destructive/batch steps (e.g., confirm scope/ROE before credential dumping; validate C2 staging before exfiltration) to support a validate→fix loop.

Replace descriptive prose in the TTP section with terse, instruction-oriented guidance that assumes Claude's ATT&CK knowledge rather than re-explaining each technique.

DimensionReasoningScore

Conciseness

The body is a dense, encyclopedic catalog — attribution, campaigns, full TTP-by-tactic enumeration, a large tool table — much of which restates ATT&CK/CT knowledge Claude already knows; it is padded with background rather than lean, token-efficient guidance.

1 / 3

Actionability

The 'Emulation guidance' section maps TTPs to concrete skills and named tools (Mimikatz, secretsdump.py, Sliver/Cobalt Strike, certutil) and includes an authorized-use caveat, giving actionable direction; however most of the document describes rather than instructs, with no copy-paste commands.

2 / 3

Workflow Clarity

Sequencing is present in the emulation guidance as a logical attack-chain progression (initial access → ... → exfiltration) and detection mappings, but there are no explicit validation checkpoints or validate→fix→retry feedback loops for the destructive/batch operations referenced.

2 / 3

Progressive Disclosure

The content is well-organized into clear sections and includes a real sources list, but it is a single monolithic SKILL.md with no bundle files or one-level-deep references, so heavy reference material (full TTP catalog, tool table) that should be split out is inlined.

2 / 3

Total

7

/

12

Passed

Description

22%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is accurate and well-attributed but reads as an actor encyclopedia entry rather than a capability-and-trigger statement. It lacks concrete actions and any 'Use when...' guidance, weakening both specificity and completeness.

Suggestions

Lead with the concrete actions the skill performs (e.g., 'Emulates APT10/Stone Panda TTPs including MSP supply-chain pivots, DLL side-loading, and credential harvesting'), not just the actor's identity.

Add an explicit 'Use when...' clause naming natural user triggers (e.g., 'Use when emulating APT10, Stone Panda, menuPass, or Cloud Hopper-style MSP supply-chain attacks').

Trim the dense alias list from the description and move it to metadata so the description stays a concise what+when statement.

DimensionReasoningScore

Specificity

The description states only the identity/attribution of an actor group ('Adversary-emulation profile for APT10... China's MSS Tianjin State Security Bureau cyber-espionage actor') rather than listing concrete actions the skill performs; it names the subject, not the capabilities.

1 / 3

Completeness

It describes 'what' the skill concerns (an emulation profile) but provides no 'Use when...' clause or equivalent explicit trigger guidance, capping completeness at 2 per guidelines; the 'when' is entirely absent.

1 / 3

Trigger Term Quality

It surfaces relevant actor/alias terms a user might reference (APT10, Stone Panda, menuPass, CVNX, G0045), but the natural trigger phrasing is buried in aliases rather than framed as user-spoken need statements, missing common variations.

2 / 3

Distinctiveness Conflict Risk

The group-specific naming gives it a clear niche unlikely to conflict broadly, but as one of several adversary-emulation profiles it could overlap with sibling actor skills without sharper trigger differentiation.

2 / 3

Total

6

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.