CtrlK
BlogDocsLog inGet started
Tessl Logo

apt29-cozy-bear

Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-organized adversary-emulation profile with specific emulation guidance and a clear kill-chain structure, but it is a monolithic, somewhat verbose document that delegates executable commands to other skills and lacks explicit validation feedback loops.

Suggestions

Split the reference-heavy sections (full TTP-by-tactic catalog, signature tooling list with S-IDs, notable campaigns, sources) into separate reference files and link to them from SKILL.md to improve progressive disclosure for this 135-line skill.

Add explicit validation feedback loops to the emulation guidance (e.g., 'after registering the service principal, confirm the new app/consent grant appears in Entra logs; if not detected, adjust and re-run') to lift workflow clarity above 3.

Tighten the attribution/campaign prose and remove URL duplication between inline campaign entries and the Sources section to improve conciseness.

DimensionReasoningScore

Conciseness

The body is information-dense and mostly relevant, but the verbose attribution prose, inline campaign histories with URLs that are duplicated in the Sources section, and long alias/tooling enumerations could be tightened; it is efficient in places yet padded in others, matching 'mostly efficient but includes some unnecessary explanation'.

3 / 5

Actionability

The emulation-guidance section gives specific, concrete direction (e.g., 'register a controlled service principal / OAuth app, add credentials to it, grant a scoped mailbox/Graph permission') but delegates actual execution to other named skills without providing executable commands or code, leaving command-level details unspecified.

3 / 5

Workflow Clarity

TTPs are organized along a logical kill-chain sequence with a few implicit checkpoints ('verify the blue cell detects...', 'validate controls fire'), but there are no explicit validate→fix→retry feedback loops, and batch/destructive-adjacent operations lack rigorous validation, capping clarity at 3.

3 / 5

Progressive Disclosure

The document is well-structured with clear section headers, but at ~135 lines it is monolithic with no bundle files or external references — the TTP catalog, campaign histories, tooling list, and sources that could live in separate files are all inlined, fitting 'some structure but content that should be separate is inline'.

3 / 5

Total

12

/

20

Passed

Description

72%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A sharply targeted, third-person description with excellent trigger-term coverage and low conflict risk, but it states only one concrete action and omits an explicit 'Use when' trigger clause from the description field itself, capping completeness and specificity.

Suggestions

Add an explicit 'Use when...' clause to the description (e.g., 'Use when emulating APT29/Cozy Bear TTPs, SolarWinds or Midnight Blizzard scenarios, or cloud/identity-centric espionage red team engagements') so completeness is not capped at 3.

Enumerate one or two more concrete capabilities in the description (e.g., 'forge Golden SAML tokens, emulate OAuth/consent abuse, run low-and-slow password sprays') to lift specificity above 3.

DimensionReasoningScore

Specificity

Names the domain (APT29 adversary emulation) and one concrete action ('mapping its ATT&CK TTPs to Decepticon emulation tooling') but does not enumerate multiple specific capabilities, matching the 'names domain and 1-2 concrete actions' anchor; it is not vague (above 2) yet not comprehensive (below 4).

3 / 5

Completeness

The 'what' is clear (an emulation profile mapping APT29 TTPs to Decepticon tooling), but the description field itself has no 'Use when...' clause or explicit trigger guidance, which the guidelines cap at 3; the metadata.when_to_use field is outside the description evaluation target.

3 / 5

Trigger Term Quality

The description packs the exact aliases a user would naturally say — 'APT29, Cozy Bear, Midnight Blizzard, NOBELIUM, The Dukes' — plus 'adversary-emulation', 'ATT&CK TTPs', and 'Decepticon', giving comprehensive synonym-level keyword coverage.

5 / 5

Distinctiveness Conflict Risk

It targets a single named threat actor (APT29 and its aliases) with distinct triggers, occupying a clear niche with minimal risk of firing for an unrelated skill.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.