CtrlK
BlogDocsLog inGet started
Tessl Logo

apt33-elfin

Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is information-dense and actionable with concrete emulation mappings and a strong safety preamble, but it reads as an inline reference monolith without a sequenced validation-bearing workflow or progressive file structure.

Suggestions

Add an explicit ordered emulation workflow with validation checkpoints (e.g. confirm scope/ROE → enumerate authorized targets → execute emulation step → verify artifact logged → teardown) so destructive-adjacent work clears the workflow-clarity cap.

Move the bulk TTP catalogue and detection rules into reference files (e.g. references/ttps.md, references/detection.md) and link to them from SKILL.md to improve progressive disclosure.

Trim the narrative attribution and campaign-history prose to the minimum needed for emulation context, keeping the token budget focused on actionable guidance.

DimensionReasoningScore

Conciseness

Dense and assumes Claude's competence (no basic explanations of ATT&CK or password spraying), but narrative attribution/campaign prose ("FireEye/Mandiant assessed APT33 works at the behest...") pads the body with threat-intel context beyond what an emulation skill strictly needs.

3 / 5

Actionability

Gives concrete, mostly executable guidance — "Stand up a Sliver HTTP listener", "low-and-slow spray...with a custom user-agent and lockout-aware throttling", specific ports 808/880, named tools — with only minor gaps where it defers to "Decepticon's X skill" without exact commands.

4 / 5

Workflow Clarity

The emulation guidance is a set of capability mappings rather than a sequenced workflow, and despite a strong authorized-use safety blockquote and teardown/logging notes, it lacks explicit validate→fix→retry checkpoints, which caps destructive/batch-adjacent workflow clarity at 3.

3 / 5

Progressive Disclosure

No bundle files exist, so all content (full TTP catalogue, detection guidance, campaign history) is inlined in a single SKILL.md; section headers give internal structure but content that could live in separate reference files is not split out.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and terminology-rich, clearly identifying a named threat actor and the artifact type, but it omits an explicit "Use when..." trigger clause, which caps completeness at 3.

Suggestions

Add an explicit "Use when..." trigger clause naming the natural scenarios (e.g. emulating Iranian espionage actors, password-spray/cloud-identity campaigns) so Claude knows when to invoke it.

Surface a couple of the most common trigger phrases (e.g. "Iranian APT", "password spray emulation") directly in the description rather than only in metadata.

Optionally enumerate 1–2 concrete actions (e.g. "maps TTPs to ATT&CK and generates Decepticon emulation steps") to lift specificity toward 5.

DimensionReasoningScore

Specificity

Names the domain ("Adversary-emulation profile for APT33") plus several concrete facets ("mapped to MITRE ATT&CK G0064", "Decepticon emulation guidance"), which lists several specific attributes with only minor coverage gaps.

4 / 5

Completeness

It clearly states what the skill is but lacks any explicit "Use when..." trigger clause, which per the rubric caps completeness at 3 even though the "what" is well articulated.

3 / 5

Trigger Term Quality

Includes the natural names a user would say — "APT33", "Elfin", "Peach Sandstorm", "HOLMIUM", "Iranian", "G0064" — giving good keyword/synonym coverage, though a few common variations (e.g. "Iranian APT", "password spray") live only in metadata rather than the description.

4 / 5

Distinctiveness Conflict Risk

Targets a clearly named APT with aliases and a MITRE group ID (G0064), forming a distinct niche with minimal risk of triggering for the wrong skill.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.