CtrlK
BlogDocsLog inGet started
Tessl Logo

apt33-elfin

Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-organized adversary-emulation profile with genuinely actionable emulation and detection guidance mapped to ATT&CK. It loses points for missing validation/feedback loops in the workflow and for keeping dense reference material inline rather than splitting it into progressive-disclosure reference files.

Suggestions

Add explicit validation/verification checkpoints to the emulation workflow (e.g., confirm scope authorization and log every artifact before advancing to the next kill-chain phase), especially given the destructive/wiper context.

Move the detailed TTP catalog, campaign history, and signature-tooling reference into a separate references/ file (e.g., TTPS.md) and keep SKILL.md as a concise overview that links out one level deep.

Tighten the attribution/targeting/campaign narrative prose to reduce token weight without losing the specific vendor citations and dates.

DimensionReasoningScore

Conciseness

The body is mostly efficient threat-intel reference (campaign dates, S-numbers, CVEs, vendor citations) that Claude would not reliably know and does not pad with basic concept explanations, but the attribution/targeting/campaign narrative prose is dense and could be tightened.

2 / 3

Actionability

Emulation guidance maps each APT33 TTP chain to concrete Decepticon actions ('stand up a Sliver HTTP listener', 'enable symmetric-crypto transport', 'front C2 through an authorized Azure App Service'), and the detection section gives specific alert/policy actions; as an instruction-only skill with actionable, specific guidance, absence of literal code is not penalized.

3 / 3

Workflow Clarity

Emulation steps are organized in kill-chain order (initial access through persistence), but there are no explicit validation checkpoints or validate-fix-retry feedback loops, and the destructive/wiper context means the missing verification step caps this at 2.

2 / 3

Progressive Disclosure

The body is well-sectioned but no bundle files exist, and the lengthy reference material (full TTP catalog, campaign list, tooling with S-numbers) is kept inline rather than externalized into one-level-deep reference files.

2 / 3

Total

9

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description that clearly conveys the skill's niche and includes strong natural trigger terms. Its main gap is the absence of an explicit 'Use when...' trigger clause inside the description field itself, with that guidance instead placed in metadata.when_to_use.

Suggestions

Append an explicit 'Use when...' clause to the description (e.g., 'Use when emulating APT33/Peach Sandstorm Iranian espionage TTPs under authorized red-team scope') so the trigger guidance is self-contained in the description field.

Consider folding a few of the most natural trigger phrases from metadata.when_to_use (e.g., 'password spray', 'Iranian APT') directly into the description for users who rely on the description alone.

DimensionReasoningScore

Specificity

Names concrete scope — 'adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM)', 'mapped to MITRE ATT&CK G0064', and 'Decepticon emulation guidance' — listing multiple specific, concrete elements rather than vague language.

3 / 3

Completeness

Clearly answers 'what' (profile, ATT&CK mapping, emulation guidance) but the description string itself lacks an explicit 'Use when...' trigger clause; that trigger guidance lives in metadata.when_to_use rather than the description, so 'when' is only implied within the evaluated field.

2 / 3

Trigger Term Quality

Includes the natural terms a user would actually say ('APT33, Elfin, Peach Sandstorm, HOLMIUM'), with broad coverage of the actor's common aliases.

3 / 3

Distinctiveness Conflict Risk

A single actor-specific adversary-emulation profile with distinct, niche triggers ('APT33', 'Peach Sandstorm', 'Decepticon') unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.