CtrlK
BlogDocsLog inGet started
Tessl Logo

apt36-transparent-tribe

Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, well-structured adversary-emulation profile with concrete TTP-to-capability mapping, but it is monolithic and verbose with overlapping sections, relies on external tools without runnable examples, and lacks validation checkpoints in its workflow.

Suggestions

Split the detailed TTP catalog and campaign history into reference files (e.g., references/TTPs.md, references/campaigns.md) and keep SKILL.md as a concise overview with one-level-deep links.

Add explicit validation/verification checkpoints to the emulation workflow (e.g., confirm payload executes in the lab, verify C2 beacon, validate scope authorization before each phase) rather than only an upfront authorized-use caveat.

Tighten redundancy between the 'TTPs by ATT&CK tactic' section and the 'Emulation guidance' section so each technique is described once.

DimensionReasoningScore

Conciseness

The body is information-dense with genuinely APT36-specific intel rather than concepts Claude already knows, but it is verbose: the TTP-by-tactic catalog and the emulation guidance overlap, and the attribution/campaign narrative could be tightened.

2 / 3

Actionability

Emulation guidance gives concrete specifics (LNK+HTA+mshta.exe chain, the HKCU Run-key path, a 15-day sleep timer, .NET custom TCP C2, Telegram/Slack C2), but it delegates execution to external 'skills' and 'Decepticon capabilities' with no self-contained runnable steps or code, leaving key implementation details missing.

2 / 3

Workflow Clarity

The emulation phases are clearly sequenced along the attack lifecycle (initial access through exfiltration), but there are no validation checkpoints or validate-fix-retry feedback loops for the risky payload-deployment operations, capping workflow clarity at 2.

2 / 3

Progressive Disclosure

The document is well-organized into sections, but it is a single ~177-line monolith with no bundle files, and content that could be split out (the full TTP catalog, campaign history, tooling table) is kept inline rather than referenced one level deep.

2 / 3

Total

8

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly distinctive and rich in natural trigger terms for APT36, but it states what the skill profiles rather than what concrete actions it performs and omits an explicit 'Use when' trigger clause.

Suggestions

Add an explicit trigger clause such as 'Use when emulating APT36 / Transparent Tribe attacks or when the user references Pakistan-linked espionage against Indian government, defense, or diplomatic targets.'

Enumerate the concrete emulation actions the skill supports (e.g., 'Map APT36 TTPs to emulation capabilities, generate weaponized lure documents, and plan CapraRAT-style mobile surveillance') to strengthen specificity.

DimensionReasoningScore

Specificity

It names a clear domain ('Adversary-emulation profile for APT36') and the targeting context ('Indian government, defense, and diplomatic entities'), but enumerates only the implicit action of emulation rather than a list of concrete actions the skill performs, so it is not comprehensive.

2 / 3

Completeness

It answers the 'what' (an emulation profile for APT36 and its targets) but lacks any explicit 'Use when...' trigger clause, so the 'when' is only implied — capping completeness at 2 per the guidelines.

2 / 3

Trigger Term Quality

It packs in the natural names a security analyst would actually say — 'APT36', 'Transparent Tribe', 'Mythic Leopard', 'ProjectM', 'COPPER FIELDSTONE', 'G0134' — giving strong coverage of the actor's common aliases.

3 / 3

Distinctiveness Conflict Risk

The highly specific niche (a named nation-state actor with multiple distinct aliases) makes it clearly distinguishable and unlikely to trigger for the wrong skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.