CtrlK
BlogDocsLog inGet started
Tessl Logo

apt29

APT29 (Cozy Bear / Midnight Blizzard, SVR) adversary-emulation playbook — malware-light cloud-identity espionage: no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies. Use when emulating APT29 against an M365/Entra/AWS-identity estate. Triggers on: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'cloud identity espionage', 'Golden SAML'.

74

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable adversary-emulation playbook with a concrete kill-chain table, copy-paste templates, and explicit safety gates. Its only weakness is mild verbosity where the intro and targeting sections overlap the description and table.

Suggestions

Trim the opening blockquote and 'When to emulate APT29' section — the description and kill-chain table already convey the targeting and tradecraft signature, so the restatement costs tokens without adding operational value.

Cut editorial asides ('APT29 is patient', 'that is the whole point of the OAuth tradecraft', 'not smash-and-grab') that restate motivation Claude can infer from the actor profile.

Consider moving the ThreatProfile seed JSON to a references/threat-profile.template.json to keep the overview lean, since it is a fill-in template rather than narrative.

DimensionReasoningScore

Conciseness

The body is dense and operational, but the opening blockquote and 'When to emulate APT29' section restate targeting/tradecraft already conveyed by the description and kill-chain table, and editorial asides like 'APT29 is patient' and 'that is the whole point of the OAuth tradecraft' could be trimmed.

2 / 3

Actionability

Provides copy-paste-ready guidance: a complete ThreatProfile JSON seed, a MITRE-mapped kill-chain table with exact executing-agent skill paths, and concrete rules (app naming 'redteam-<engagement-id>-*', spray cadence 'one attempt per account'). For an instruction-only skill the guidance is specific and actionable.

3 / 3

Workflow Clarity

A clearly sequenced 5-phase kill-chain/CONOPS with explicit go/no-go safety gates ('require explicit, written cloud-tenant authorization'), an EMERGENCY abort trigger, deconfliction steps, and end-of-engagement cleanup serving as validation checkpoints for a high-blast-radius operation.

3 / 3

Progressive Disclosure

Organized into clearly headed sections (ThreatProfile, Kill-chain, CONOPS, OPSEC, RoE, Deconfliction, Fidelity) with one-level-deep, clearly signaled cross-skill references — the table's 'Executing agent → skill' column and the '../../references/apt-groups.md' map — and no nested or monolithic walls of text.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A precise, distinctive description that names concrete tradecraft and supplies explicit natural-language triggers covering both what the skill does and when to use it. It is the strongest kind of description anchor with no vague fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'no-MFA password spray, OAuth consent/token abuse, Golden SAML, mailbox collection over residential proxies' — matching the anchor for several specific actions. Voice is third-person/imperative ('Use when emulating'), so the first/second-person penalty does not apply.

3 / 3

Completeness

Clearly answers what ('adversary-emulation playbook — malware-light cloud-identity espionage' with named tradecraft) and when ('Use when emulating APT29 against an M365/Entra/AWS-identity estate') with explicit triggers, satisfying both halves.

3 / 3

Trigger Term Quality

An explicit 'Triggers on' clause surfaces natural terms a red-team user would say: 'emulate APT29', 'Cozy Bear', 'Midnight Blizzard', 'NOBELIUM', 'OAuth abuse', 'Golden SAML', giving broad coverage of common variations.

3 / 3

Distinctiveness Conflict Risk

Highly niche APT29/SVR cloud-identity emulation with distinctive triggers (Cozy Bear, NOBELIUM, Golden SAML) carves a clear slot unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.