CtrlK
BlogDocsLog inGet started
Tessl Logo

apt34-oilrig

Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, well-structured APT34 adversary-emulation reference with genuinely novel TTP/tooling detail and a clear kill-chain sequence. Its weaknesses are verbosity in narrative prose, emulation guidance that defers to other skills rather than giving executable steps, absent operational validation checkpoints, and a monolithic structure that underuses progressive disclosure.

Suggestions

Tighten the Attribution/Notable-campaigns prose into compact reference rows (date, vector, tooling, source) and drop narrative Claude could infer, to lift conciseness.

Add explicit operational validation checkpoints to the emulation sequence (e.g. 'verify in-scope authorization and access before each tactic', 'confirm beacon/DNS callback before proceeding to recon') to satisfy the destructive-workflow feedback-loop requirement.

Move the full TTP-by-tactic catalog, signature-tooling list, and detailed detection rules into references/ files (e.g. TTPS.md, TOOLING.md, DETECTION.md) and keep SKILL.md as a concise overview that links one level deep, improving progressive disclosure.

DimensionReasoningScore

Conciseness

Much of the threat-intel detail (specific campaign dates, software S-IDs, exact TTP mappings) is genuinely novel reference content that earns its place, but the attribution narrative ('It conducts long-running, reconnaissance-heavy intrusions...') and campaign prose are explanatory padding that could be tightened. It is mostly efficient but not 'every token earns its place', sitting below the lean anchor and above the verbose 'explains concepts Claude knows' anchor.

2 / 3

Actionability

Concrete specifics exist — the LOLBin recon sequence ('whoami', 'net user'/'net group', 'ipconfig /all', 'netstat -an', 'net accounts', 'sc query'), 'certutil -decode', and registry paths like 'HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages' — but the emulation guidance largely defers to other skills ('use the phishing skill to craft...', 'Configure your C2/Sliver profile...') rather than giving complete, copy-paste-ready executable content. As an instruction-only skill it is actionable yet incomplete, matching the 'some concrete guidance but incomplete' anchor.

2 / 3

Workflow Clarity

A clear kill-chain sequence is stated ('phish → execute loader → DNS/HTTP C2 → recon → credential harvest → escalate → lateral to DC → stage → exfil via mail/DNS') and the body is organized by tactic, but there are no explicit validate→fix→retry checkpoints for the destructive/risky red-team operations. Per the rubric, missing validation/feedback loops in destructive-operation workflows caps workflow clarity at 2 rather than 3.

2 / 3

Progressive Disclosure

The body is well-organized into clear sections (Attribution, Targeting, Notable campaigns, TTPs by tactic, Tooling, Emulation guidance, Detection, Sources), but it is a single 150+ line monolithic file with no bundle references; the full TTP catalog, campaign history, and detection rules are inline content that could be split into separate reference files. This matches 'some structure but content that should be separate is inline' rather than the well-signaled one-level-deep reference pattern of the top anchor.

2 / 3

Total

8

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a clear, distinctive, third-person statement of a specialized red-team emulation niche with strong natural trigger terms. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which leaves the 'when to use' guidance only implied.

Suggestions

Append an explicit 'Use when...' trigger clause naming concrete invocation moments, e.g. 'Use when emulating APT34/OilRig (Iranian espionage, G0049) in an authorized red-team engagement, or when the user mentions OilRig, Helix Kitten, or DNS-tunneling C2 emulation.'

List a few more concrete actions the profile performs (e.g. 'maps TTPs to Decepticon tooling, sequences a phish→C2→cred-harvest→lateral→exfil kill chain, and provides detection guidance') to lift specificity from one stated action to multiple.

DimensionReasoningScore

Specificity

It names the domain ('APT34 / OilRig (G0049)... Iranian state-sponsored espionage group') and one concrete action ('mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation'), but it does not enumerate multiple distinct concrete actions the way the top anchor expects. It sits above the vague anchor ('Helps with documents') yet below 'Lists multiple specific concrete actions', and uses third person with no first/second-person penalty.

2 / 3

Completeness

The 'what' is explicit ('Adversary-emulation profile... mapping its ATT&CK TTPs to Decepticon tooling'), but there is no 'Use when...' clause or equivalent explicit trigger guidance; the 'when' is only implied by 'for authorized red-team emulation'. Per the guideline, a missing 'Use when...' clause caps completeness at 2 rather than the 3 that requires explicit when-triggers.

2 / 3

Trigger Term Quality

Phrases like 'APT34 / OilRig (G0049)', 'Iranian state-sponsored espionage group', 'ATT&CK TTPs', and 'red-team emulation' are exactly the natural terms a user would say to surface this skill. It is not jargon-only or generic, so it clears the 'good coverage of natural terms' anchor rather than the 'some relevant keywords' level below.

3 / 3

Distinctiveness Conflict Risk

The APT34/OilRig Iranian espionage adversary-emulation niche mapped to Decepticon is a clear, narrow niche with distinct triggers and is unlikely to fire for the wrong skill. It is well above the 'somewhat specific but could overlap' anchor.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.