CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-alternative-channels

Non-traditional C2 channels — Discord/Telegram bots, DNS-over-HTTPS, blockchain-based C2, email-based C2, and cloud function dead drops for covert command and control.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2-alternative-channels/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with complete executable code across all six channels and a strong decision tree, but it is a monolithic file with no progressive disclosure into bundle references and lacks explicit validation feedback loops in its operational workflows. Splitting channels into reference files and adding validation checkpoints would lift the weaker dimensions.

Suggestions

Add explicit validation/verification checkpoints to operational workflows (e.g., confirm beacon round-trip and validate decoded command before execution) to satisfy the feedback-loop requirement for destructive/batch operations.

Move full per-channel implants and the Solidity contract into reference files under ./references/ (e.g., discord-implant.py, eth-contract.sol) and keep SKILL.md as an overview pointing to them, improving progressive disclosure and conciseness.

Tighten the longest inlined code blocks (Discord/Telegram/Email implants) to minimal illustrative snippets, offloading the full versions to references.

DimensionReasoningScore

Conciseness

Content is largely efficient with no padding about basic concepts, dense executable code, and brief OPSEC notes, though the 488-line monolith inlines full implants and a full Solidity contract that could be trimmed or externalized.

4 / 5

Actionability

Provides fully executable Python, Bash, and Solidity with real API endpoints, message chunking, rate-limit handling, and concrete setup steps — copy-paste ready coverage of common cases.

5 / 5

Workflow Clarity

The Decision Gate gives clear channel-selection sequencing and error-handling tables exist, but the workflows lack explicit validation/verification checkpoints; per the rubric cap, batch/destructive-style operations without validate-fix-retry feedback loops cannot score above 3.

3 / 5

Progressive Disclosure

No bundle files exist; the entire skill is a single monolithic SKILL.md with all six channels fully inlined, which is structurally below the well-signaled one-level-deep reference ideal but retains clear section headers and navigation.

3 / 5

Total

15

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-differentiated with strong trigger term coverage, but the user-facing description field omits an explicit 'when to use' clause, keeping completeness at the midpoint. Moving the trigger guidance into the description itself would raise it.

Suggestions

Add an explicit 'Use when ...' clause to the description field (e.g., 'Use when standard C2 channels are blocked or when blending with legitimate services is required').

Include the natural file/service extensions or protocol names users would mention (e.g., .onion, IMAP, SMTP, MTProto) directly in the description to strengthen trigger term quality further.

Ensure the description stands alone without relying on metadata.when_to_use for the 'when' half of completeness.

DimensionReasoningScore

Specificity

Names five concrete channel types with named services (Discord/Telegram bots, DNS-over-HTTPS, blockchain C2, email C2, cloud function dead drops), matching the comprehensive-coverage anchor.

5 / 5

Completeness

The visible description gives a clear 'what' but lacks a 'Use when...' trigger clause; explicit when-guidance exists only in metadata.when_to_use, so per the rubric completeness is capped at 3.

3 / 5

Trigger Term Quality

metadata.when_to_use provides comprehensive natural terms and synonyms (discord c2, telegram c2, blockchain c2, email c2, dns over https, dead drop resolver, cloud c2, lambda c2, serverless c2), covering the variants users would actually say.

5 / 5

Distinctiveness Conflict Risk

Targets a clear niche (non-traditional/alternative C2) with distinct triggers and a reference to a separate domain-fronting skill, minimizing overlap risk.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.