CtrlK
BlogDocsLog inGet started
Tessl Logo

apt28-fancy-bear

Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, well-organized ATT&CK-mapped adversary profile with concrete emulation and detection guidance. It is held back by narrative padding, guidance that points to other skills rather than self-contained procedures, missing validation checkpoints for destructive operations, and a monolithic structure with no bundled reference files.

Suggestions

Move the large TTP-by-tactic catalog, the signature-tooling table, and the notable-campaigns narrative into reference files (e.g. references/ttps.md, references/tooling.md) and link them one level deep from SKILL.md to improve progressive disclosure.

Add explicit validation/verification checkpoints to the emulation workflow (e.g. confirm scope/ROE before destructive T1561/T1498 steps, verify privesc success before credential access) so destructive and batch operations have feedback loops.

Tighten or condense the 'Attribution & motivation' and 'Notable campaigns' sections to only what drives emulation decisions, reducing token spend on background Claude already largely knows.

DimensionReasoningScore

Conciseness

Most of the body is dense, non-obvious reference data (TTP→ATT&CK mappings, tool table, CVEs) that earns its tokens, but the 'Attribution & motivation' and 'Notable campaigns' narrative sections add background not strictly needed for emulation; matches 'mostly efficient but could be tightened'; not a 3 due to that narrative padding, not a 1 because it avoids explaining basic concepts Claude already knows.

2 / 3

Actionability

The 'Emulation guidance' section gives specific direction ('run Responder for LLMNR/NBT-NS poisoning', 'use Sliver over HTTPS', 'split into <1MB chunks', 'Mimikatz for LSASS dump/DCSync') but largely delegates to other skills rather than providing self-contained executable commands; matches 'some concrete guidance but incomplete'; not a 3 because it stops at cross-skill mapping instead of copy-paste-ready steps.

2 / 3

Workflow Clarity

Tactic-phase ordering (initial access → ... → exfil) gives an implicit sequence and an authorized-use caveat, but there are no explicit validation checkpoints or validate→fix→retry loops despite destructive/batch operations (T1561/T1498); per the guidelines this caps workflow clarity at 2; not a 1 because a phase sequence does exist.

2 / 3

Progressive Disclosure

The body is well-sectioned with clear headers, but it is a monolithic ~200-line file with no references/scripts/assets bundle and no one-level-deep split for the large TTP catalog and tool table; matches 'some structure but content that should be separate is inline'; not a 3 because the >50-line reference material is not offloaded to separate files, not a 1 because organization is clean.

2 / 3

Total

8

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly distinctive and rich in natural trigger terms, sharply scoping a single threat-actor emulation skill. Its main weakness is the absence of any explicit 'Use when...' trigger guidance and the lack of stated actions, which caps completeness and specificity.

Suggestions

Add an explicit trigger clause, e.g. 'Use when emulating APT28/Fancy Bear tradecraft in an authorized engagement or when the user mentions GRU Unit 26165, Forest Blizzard, or Sofacy.'

Name concrete actions the skill performs (e.g. 'maps APT28 TTPs to ATT&CK, maps plays to Decepticon capabilities, provides detection guidance') rather than only describing it as a 'profile'.

DimensionReasoningScore

Specificity

Quotes 'Adversary-emulation profile for APT28' and 'Russia's GRU Unit 26165 cyber-espionage actor' — it names a concrete domain and subject but lists no concrete actions the skill performs, matching the 'names domain and some actions' anchor only partially; not a 1 because the subject is sharply specific, not a 3 because no enumerated actions appear.

2 / 3

Completeness

It states what the skill is (an emulation profile) but contains no 'Use when...' clause or equivalent trigger guidance, so per the judging guidelines completeness is capped at 2; not a 1 because the 'what' is explicit, not a 3 because 'when' is entirely absent.

2 / 3

Trigger Term Quality

Natural trigger terms a user would say are densely packed: 'APT28', 'Fancy Bear', 'Forest Blizzard', 'Sofacy', 'STRONTIUM', 'GRU Unit 26165' — good coverage matching the 'good coverage of natural terms' anchor; not below because these are exactly the aliases users invoke.

3 / 3

Distinctiveness Conflict Risk

The niche is a single named threat actor (APT28/G0007) with distinct alias triggers, making conflict with other skills unlikely; matches the 'clear niche with distinct triggers' anchor.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.