CtrlK
BlogDocsLog inGet started
Tessl Logo

apt37-reaper

Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly specific and actionable, with concrete CVEs, registry keys, API chains, and cloud-C2 mappings tied to ATT&CK IDs, but it is padded with narrative history, lacks validation feedback loops around its destructive operations, and keeps all reference material inline rather than splitting it across bundle files.

Suggestions

Tighten the attribution and notable-campaigns sections into compact reference entries (drop the vendor-citation prose and confidence rationale) to reduce tokens spent on background Claude already knows.

Add explicit validation checkpoints around destructive and exfil steps (e.g., 'confirm isolated lab scope before T1561.002; verify exfil staging archive before upload') to introduce a validate→fix→retry loop.

Move the malware catalog, campaign timeline, and full per-tactic TTP breakdown into references/ files (e.g., MALWARE.md, CAMPAIGNS.md, TTPS.md) and keep SKILL.md as a concise overview that links one level deep.

DimensionReasoningScore

Conciseness

Operational specifics earn their place (CVEs, registry paths, C2 platforms, API chains), but the attribution rationale and dated campaign chronology with vendor citations are narrative prose Claude largely already knows and could be trimmed, fitting the 'mostly efficient but could be tightened' anchor.

2 / 3

Actionability

The emulation guidance maps each kill-chain phase to concrete artifacts — CVE-2020-1380/CVE-2021-26411 chains, HKCU\...\Run persistence, VirtualAlloc→WriteProcessMemory→CreateRemoteThread injection into cmd.exe, Dropbox/pCloud/Yandex/Box C2, and `shutdown /r /t 1` — which is specific and actionable for an instruction-only skill where executable code is not required.

3 / 3

Workflow Clarity

Phases are sequenced by ATT&CK tactic and gated by an explicit authorized-use caveat, but there are no validate→fix→retry feedback loops for the destructive (MBR wipe) and batch (collection/exfil) operations, which caps workflow clarity at 2 per the rubric.

2 / 3

Progressive Disclosure

Sections and the malware table are well organized, but everything lives inline in one ~180-line SKILL.md with no bundle files and no one-level-deep references, so reference detail that could be split (campaigns, malware catalog, full TTP breakdown) sits inline at the anchor-2 level.

2 / 3

Total

9

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies a distinctive niche and surfaces the natural trigger terms a user would say, but it omits an explicit 'Use when…' clause and does not enumerate concrete actions, capping both completeness and specificity.

Suggestions

Add an explicit 'Use when…' clause naming the triggering situations (e.g., 'Use when emulating APT37/Reaper/ScarCruft TTPs, building a DPRK espionage red-team scenario, or mapping detections for RoKRAT/BLUELIGHT') to lift completeness to 3.

List two or three concrete actions the profile enables (e.g., 'maps APT37 TTPs to emulation plays, catalogs signature malware, and maps detections') so specificity reads as multiple discrete capabilities rather than a single domain label.

DimensionReasoningScore

Specificity

States the domain and subject concretely ("Adversary-emulation profile for APT37 … North Korea's RGB cyber-espionage actor") but lists no multiple discrete actions, matching the 'names domain and some actions' anchor rather than the multi-action anchor 3.

2 / 3

Completeness

Answers 'what' (an APT37 adversary-emulation profile) but the description field itself has no 'Use when…' clause or equivalent explicit trigger guidance, capping completeness at 2 per the rubric guideline.

2 / 3

Trigger Term Quality

Surfaces the natural alias cluster a threat-intel/red-team user would actually say — APT37, Reaper, ScarCruft, Ricochet Chollima, InkySquid, Group123 — giving strong keyword coverage that is not below anchor 3.

3 / 3

Distinctiveness Conflict Risk

The APT37/G0067 alias set carves out a sharply distinct niche unlikely to trigger for unrelated skills, and it is not the generic 'works with files' level of anchor 2.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.