CtrlK
BlogDocsLog inGet started
Tessl Logo

apt36-transparent-tribe

Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities.

53

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The profile is a comprehensive, accurate, ATT&CK-grounded reference with strong actionability in the emulation guidance, but it is a monolithic single-file skill with no progressive disclosure and lacks explicit validation checkpoints for destructive emulation workflows. Splitting reference material into bundle files and adding verify-steps would materially raise the score.

Suggestions

Move the campaign timeline, full per-tactic TTP catalog, and detection guidance into separate reference files (e.g. references/campaigns.md, references/ttps.md, references/detection.md) and link to them from a concise overview, improving progressive disclosure.

Add explicit validation/verification checkpoints to the emulation guidance (e.g. confirm scope/authorization before each destructive step, verify payload staging, validate C2 reachability) to lift workflow clarity above the destructive-skill cap of 3.

Tighten the TTP sections by collapsing redundant per-technique prose and relying on the ATT&CK IDs plus the tooling table, since Claude already knows most technique definitions.

DimensionReasoningScore

Conciseness

The body is information-dense and well-organized rather than padded with concepts Claude already knows, but it is long (TTP enumerations across many tactics, a campaign timeline, detection guidance) and some sections restate ATT&CK technique names Claude already knows, so it is mostly efficient with room to tighten.

3 / 5

Actionability

The 'Emulation guidance' section gives concrete, executable direction (registry Run key paths, 15-day sleep timer, LNK+HTA+mshta.exe chain, Telegram/Slack/Google Drive C2) with specific ATT&CK IDs throughout; minor gaps in that it describes techniques to emulate rather than providing copy-paste tooling commands.

4 / 5

Workflow Clarity

There is a clear conceptual kill-chain sequence (initial access -> execution -> persistence -> evasion -> collection -> C2 -> exfiltration) and an authorized-use caveat, but no explicit validation/verification checkpoints or feedback loops; the emulation work is destructive/offensive, so missing validation caps workflow clarity at 3 per the feedback_loops scoring note.

3 / 5

Progressive Disclosure

It is a single ~180-line monolithic SKILL.md with no bundle files in references/scripts/assets and no one-level-deep reference links; the campaign timeline, full TTP catalog, and detection guidance are strong candidates for separate reference files but are all inlined, matching the 'content that clearly belongs in separate files is inlined' anchor.

2 / 5

Total

12

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and rich in natural alias-based trigger terms with low conflict risk, but it omits any explicit 'Use when...' guidance, which caps completeness. Adding a trigger clause would lift the description to the top anchor band.

Suggestions

Append an explicit trigger clause, e.g. 'Use when emulating APT36 / Transparent Tribe activity, planning South-Asian espionage scenarios, or mapping detections to APT36 TTPs.'

Lead with the concrete actions the profile enables (e.g. 'Maps APT36 TTPs to emulation and detection guidance') so the 'what' reads as capability rather than a label.

Keep the alias list but trim the least-recognized ones to keep the description concise per the 'do not reward verbosity' guideline.

DimensionReasoningScore

Specificity

Names the concrete artifact type ('Adversary-emulation profile'), the specific actor and five aliases, and concrete targets ('Indian government, defense, and diplomatic entities') — several specific concrete elements, though it is more of a profile description than a list of discrete actions.

4 / 5

Completeness

Has a clear 'what' (an adversary-emulation profile for APT36) but no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines.

3 / 5

Trigger Term Quality

Rich natural trigger terms ('APT36', 'Transparent Tribe', 'Mythic Leopard', 'ProjectM', 'COPPER FIELDSTONE', 'cyber-espionage', 'adversary-emulation') that a user would plausibly say; a few common variations (e.g. G0134) are present but it leans on proper nouns rather than action phrases.

4 / 5

Distinctiveness Conflict Risk

The APT36 / Transparent Tribe naming carves a clear niche with minimal overlap risk against unrelated skills; minor residual overlap only with other South-Asia adversary-emulation profiles.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.