CtrlK
BlogDocsLog inGet started
Tessl Logo

bloodhound-bhce

Operate BloodHound Community Edition v9.2.2 via Decepticon's bhce_* tools — health check, Cypher passthrough, SharpHound ZIP ingest. Replaces the in-house ingest + ESC* post-process pipeline per ADR-0005.

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/ad/bloodhound-bhce/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with a clear, validated workflow and concrete copy-paste examples. Its main weaknesses are inline time-sensitive version/date details and a lack of bundle-file progressive disclosure for the sizable query library.

Suggestions

Move version/date-sensitive details (v9.2.2, 2026-06-01, PR #560..#578) into a dedicated 'Version / upstream' or deprecated-patterns section so they can be maintained without bloating the operational guidance.

Extract the battle-tested Cypher query library into a references/ file (e.g., references/queries.md) referenced from the body, trimming the inline SKILL.md to the loop and failure modes.

Tighten the 'Why we use BHCE rather than our own ingest' section to the essential edges-list pointer, removing rationale that the agent does not need to act.

DimensionReasoningScore

Conciseness

The body is mostly lean and operational, but embeds time-sensitive specifics ('v9.2.2', '2026-06-01', 'PRs #560..#578') outside any deprecated/old-patterns section and includes a 'Why we use BHCE' justification that could be trimmed.

2 / 3

Actionability

Provides fully executable guidance: concrete tool calls (bhce_status(), bhce_ingest_zip(path=...)), expected result envelopes, copy-paste Cypher queries, and file:line diagnostics for failures.

3 / 3

Workflow Clarity

A numbered four-step end-to-end loop with explicit validation checkpoints (version match, principal_name non-empty, terminal_status enum) and a failure-modes section giving error-recovery guidance for the batch ingest operation.

3 / 3

Progressive Disclosure

Sections are well-organized and external references (ADR, upstream source, docs site) are clearly signaled one level deep, but no bundle files exist and the dense inline Cypher query library and operational content could be split out rather than kept inline.

2 / 3

Total

10

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-differentiated, naming three concrete operations on a clearly bounded niche. It is capped by an absent explicit 'Use when' trigger clause and trigger terms that lean on internal jargon over natural user phrasing.

Suggestions

Add an explicit 'Use when...' clause naming natural triggers (e.g., 'Use when ingesting SharpHound collections, querying AD attack paths, or checking BloodHound CE health').

Replace or supplement internal jargon ('Decepticon's bhce_* tools', 'ADR-0005', 'ESC* post-process pipeline') with terms a user would naturally say, such as 'BloodHound', 'Active Directory attack paths', and 'ADCS escalation'.

Consider including common variations like 'attack path', 'active directory', and 'domain compromise' alongside the existing keywords.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'health check, Cypher passthrough, SharpHound ZIP ingest' — naming specific operations rather than vague abstractions.

3 / 3

Completeness

Clearly answers what the skill does but lacks an explicit 'Use when...' trigger clause, which caps completeness at 2 per the judging guidelines.

2 / 3

Trigger Term Quality

Contains some natural terms users would say (BloodHound, Cypher, SharpHound) but mixes in internal jargon ('Decepticon's bhce_* tools', 'ADR-0005', 'ESC* post-process pipeline') and omits common variations like 'attack path' or 'active directory'.

2 / 3

Distinctiveness Conflict Risk

Targets a clear niche (BloodHound CE via the bhce_* tool family) with distinct triggers unlikely to conflict with other skills.

3 / 3

Total

10

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.