CtrlK
BlogDocsLog inGet started
Tessl Logo

apt29-cozy-bear

Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, well-structured adversary-emulation reference with specific tool mappings and built-in detection/verification guidance, but it is verbose with restated background, lacks executable commands, and keeps all reference-grade content inline in a single file.

Suggestions

Trim encyclopedic background (attribution consensus, sector lists, dated campaign histories) that Claude already knows, or move it to a references file, to improve conciseness.

Add concrete, executable command snippets or parameters for the highest-value plays (e.g. a Golden SAML / OAuth-consent workflow) instead of only naming the skill to call.

Split the campaign histories, full tooling catalog, and TTP-by-tactic listing into one-level-deep reference files linked from a concise overview to improve progressive disclosure.

DimensionReasoningScore

Conciseness

The emulation guidance and TTP-to-skill mappings earn their place, but the body is padded with encyclopedic background Claude largely already knows (attribution consensus, sector lists, full campaign histories with time-sensitive dates and version numbers like 'Orion 2019.4-2020.2.1' and '~18,000 organizations'), placing it at 'mostly efficient but could be tightened' rather than lean level 3.

2 / 3

Actionability

The emulation section gives specific direction (e.g. 'Use the c2/sliver skill... HTTPS beacons with long jitter, asymmetric encryption, optional domain-fronting'), but it points to other skills instead of providing executable commands or copy-paste-ready examples, fitting 'some concrete guidance but incomplete; missing key details.'

2 / 3

Workflow Clarity

Phases are sequenced in kill-chain order (Initial Access through Exfil) and include a verification note ('verify the blue cell detects the new app, consent grant, and federation change') plus a detection checklist, but it reads as a tactic-indexed reference rather than a gated procedure and lacks explicit validate->fix->retry feedback loops, so it does not reach level 3.

2 / 3

Progressive Disclosure

Sections are well-organized with clear headers, but the skill is a monolithic ~136-line single file with no external references, and reference-grade content (campaign histories, full malware/tooling catalog, complete TTP listing) is inline rather than split into one-level-deep reference files, matching the level-2 'content that should be separate is inline' anchor.

2 / 3

Total

8

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has strong, natural trigger-term coverage and a clear, distinct niche, but it is capped by a missing explicit 'Use when...' clause and by listing only one abstract action rather than multiple concrete capabilities.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when emulating APT29/Cozy Bear/Midnight Blizzard TTPs in an authorized red-team engagement' to lift completeness to 3.

List concrete emulation actions beyond 'mapping TTPs to tooling' (e.g. 'forge Golden SAML tokens, spray cloud identities, deploy encrypted C2 beacons') to raise specificity.

DimensionReasoningScore

Specificity

It names the domain ('Adversary-emulation profile for APT29') and one concrete action ('mapping its ATT&CK TTPs to Decepticon emulation tooling'), but lists only a single abstract action rather than multiple specific concrete actions, so it sits at 'names domain and some actions, but not comprehensive' rather than the multi-action level 3.

2 / 3

Completeness

It clearly states what the skill does ('adversary-emulation profile... mapping its ATT&CK TTPs to Decepticon emulation tooling') but has no 'Use when...' clause or equivalent explicit trigger guidance, so per the judging guidelines completeness is capped at 2 with 'when' only implied.

2 / 3

Trigger Term Quality

It packs the natural aliases a user would actually say — 'APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'The Dukes', 'SVR', 'cyber-espionage', 'ATT&CK TTPs' — giving good coverage of the tracking names a red-teamer would invoke, matching the level-3 'good coverage of natural terms' anchor.

3 / 3

Distinctiveness Conflict Risk

A profile scoped to one named tracked group (APT29) with its distinct aliases is a clear niche with distinct triggers and is unlikely to fire for the wrong skill, matching the level-3 anchor.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.