CtrlK
BlogDocsLog inGet started
Tessl Logo

apt34-oilrig

Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a thorough, well-structured adversary-emulation profile with concrete TTP-to-tool mappings and detection guidance. Its weaknesses are verbosity from inlined encyclopedic reference material and missing explicit validation checkpoints in the destructive-adjacent emulation workflow.

Suggestions

Move the full TTP catalog, signature-tooling list, and notable-campaigns history into separate reference files under references/ and replace them with concise one-level-deep pointers to improve progressive disclosure and conciseness.

Add explicit per-step validation/authorization checkpoints to the emulation sequence (e.g. 'Confirm target is on the signed scope list before each active technique') to lift the workflow-clarity cap.

Trim the attribution/multi-vendor-naming prose to the minimum needed to identify the actor, since much of it is background Claude already has.

DimensionReasoningScore

Conciseness

The ~154-line body is mostly purposeful TTP mapping but carries substantial encyclopedic background (attribution rationale, multi-vendor naming, full campaign histories, a long signature-tooling catalog) that could be tightened without losing actionable value.

3 / 5

Actionability

Provides concrete mappings of TTPs to named Decepticon capabilities/skills, specific LOLBin recon sequences, registry paths to monitor, and a concrete emulation sequence — mostly executable guidance with minor gaps (no literal commands for every step).

4 / 5

Workflow Clarity

A clear kill-chain sequence is given ('phish → execute loader → DNS/HTTP C2 → recon → credential harvest → escalate → lateral to DC → stage → exfil'), but for a destructive-adjacent red-team workflow there are no per-step validation/authorization checkpoints, capping this dimension at 3 per the rubric.

3 / 5

Progressive Disclosure

Section headers are clear and the file is well-organized, but at 154 lines with no bundle files (references/, scripts/, assets/ are empty), large reference blocks (full TTP catalog, signature-tooling list, notable campaigns, sources) are inlined rather than split into one-level-deep reference files.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and highly distinctive, naming the actor, domain, and concrete purpose. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which limits the completeness dimension.

Suggestions

Append an explicit trigger clause, e.g. 'Use when emulating APT34/OilRig (G0049) tradecraft for an authorized red-team or purple-team engagement.'

Surface a couple of the most common synonyms from metadata.when_to_use (e.g. 'OilRig', 'Helix Kitten', 'Iranian APT') directly in the description so users who say those terms match naturally.

DimensionReasoningScore

Specificity

Names a concrete domain ('adversary-emulation profile') and several specific actions ('mapping its ATT&CK TTPs to Decepticon tooling', 'red-team emulation'), which matches the 'several specific actions; minor gaps' anchor rather than the fully comprehensive 5.

4 / 5

Completeness

There is a clear 'what' (an adversary-emulation profile mapping TTPs to Decepticon tooling) but no explicit 'Use when...' or equivalent trigger clause, which per the judging guidelines caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural terms a red-teamer would say ('APT34 / OilRig (G0049)', 'Iranian state-sponsored espionage group', 'ATT&CK TTPs', 'red-team emulation'); a few common synonyms/aliases are missing from the description itself (though present in metadata).

4 / 5

Distinctiveness Conflict Risk

Targets a clearly defined niche (a single named actor APT34/OilRig with G0049 identifier) with distinct triggers and minimal overlap risk against other skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.