CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-cobalt-strike

Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.

66

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured operational reference with executable commands and useful error/OPSEC tables, though it is a large monolithic document that does not split detail into bundled reference files.

Suggestions

Move the full Malleable C2 profile and the detection-signature/OPSEC tables into bundled reference files (e.g. references/profiles.md, references/detection.md) and link to them from the body to improve progressive disclosure.

Add an explicit validate→fix→retry checkpoint around profile loading (run c2lint, fix on failure, only start teamserver when clean) to strengthen workflow clarity.

Trim the introductory paragraph that explains what Cobalt Strike is, since Claude already knows this.

DimensionReasoningScore

Conciseness

The body is mostly lean operational reference — real commands, profile syntax, and tables — with only minor over-explanation (e.g. the opening 'Cobalt Strike is a commercial adversary simulation platform' sentence) that could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready, fully executable guidance: concrete teamserver/listener commands, a complete Malleable C2 profile, and specific Arsenal kit build commands with flags covering the common cases.

5 / 5

Workflow Clarity

Sections are sequenced teamserver → listener → generation → profile → injection, with a branching Decision Gate and an Error Handling table providing recovery guidance; validation exists (c2lint) but is not woven into an explicit validate→fix→retry loop as a primary workflow.

4 / 5

Progressive Disclosure

Good section structure with clear headers, but the file is a ~420-line monolith with a full malleable profile, OPSEC tables, and detection signatures all inlined and no references to separate files, so content that should be split remains inline.

3 / 5

Total

16

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description with concrete capabilities and strong natural trigger terms, but it lacks an explicit 'Use when...' clause to tell Claude when to invoke it.

Suggestions

Append an explicit trigger clause such as 'Use when working with Cobalt Strike, configuring beacons or listeners, or authoring Malleable C2 profiles.'

Consider adding a couple of operator-synonym terms (e.g. 'teamserver', 'aggressor') to the description itself, not just metadata.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

The 'what' is explicit and concrete, but there is no 'Use when...' clause or equivalent trigger guidance in the description field, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Includes the natural terms operators actually say — 'Cobalt Strike', 'Beacon', 'Malleable C2', 'listener', 'process injection', 'Arsenal kit' — with strong synonym coverage of the niche.

5 / 5

Distinctiveness Conflict Risk

Targets a clearly distinct niche (Cobalt Strike specifically) with trigger terms unlikely to fire for unrelated skills, so conflict risk is minimal.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.