CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-cobalt-strike

Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

80%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, token-efficient operational reference with concrete commands and a useful decision gate, but it is a single large file with no progressive disclosure and only one embedded validation checkpoint. Splitting detailed sections into referenced files and adding validation feedback loops to risky workflows would lift the weaker dimensions.

Suggestions

Move the large Malleable C2 profile, process-injection, and Arsenal-kit sections into separate referenced files (e.g., references/malleable-profiles.md, references/process-injection.md) and keep SKILL.md as a concise overview, improving progressive disclosure.

Add explicit validate→fix→retry checkpoints to the payload-generation and process-injection workflows (e.g., lint profile, test artifact, verify callback) rather than relying on the standalone Error Handling table.

Tighten the opening paragraph and a few prose OPSEC notes that restate concepts Claude already knows to push conciseness firmly into score-3 territory.

DimensionReasoningScore

Conciseness

The body is dense, reference-style content dominated by executable commands, complete Malleable profile blocks, and compact tables; the only conceptual prose is a single opening sentence and brief OPSEC rationale that carry domain value, so most tokens earn their place.

3 / 3

Actionability

It provides copy-paste-ready, fully executable guidance throughout — teamserver/listener configs, payload generation paths, a complete Malleable C2 profile, sleep/jitter values, injection commands, and Arsenal kit build commands — matching the score-3 anchor.

3 / 3

Workflow Clarity

Topics are well sequenced (teamserver → listener → beacon → profile) and the Decision Gate plus Error Handling table aid recovery, but explicit validate→fix→retry checkpoints are only present for profile linting (c2lint); risky operations like injection and payload deployment lack embedded feedback loops, capping the score at 2.

2 / 3

Progressive Disclosure

Sections are clearly organized, but the ~430-line body is monolithic with no bundle files (references/scripts/assets absent) and no one-level-deep file references, so substantial content that could be split (profiles, injection, Arsenal kit) stays inline.

2 / 3

Total

10

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, third-person description with strong trigger terms and clear distinctiveness, but it lacks an explicit 'Use when...' clause so it does not fully answer when Claude should invoke it. Adding trigger guidance would raise completeness to 3.

Suggestions

Append a 'Use when...' clause (e.g., 'Use when the user mentions Cobalt Strike, beacons, malleable C2 profiles, or teamserver/listener setup') to explicitly answer the 'when' half of completeness.

Mirror the metadata.when_to_use trigger terms (aggressor, teamserver) directly into the description so the natural keywords live in the field Claude matches on.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions — 'Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage' — matching the score-3 anchor of listing several specific concrete actions rather than vague language.

3 / 3

Completeness

It clearly states what the skill does but contains no 'Use when...' clause or equivalent explicit trigger guidance, so per the guideline a missing when-clause caps completeness at 2.

2 / 3

Trigger Term Quality

It surfaces the natural terms an operator would actually say ('Cobalt Strike', 'Beacon', 'Malleable C2', 'listener', 'process injection', 'Arsenal kit'), giving good coverage of domain keywords rather than abstract jargon.

3 / 3

Distinctiveness Conflict Risk

'Cobalt Strike operations' with its specialized Beacon/Malleable C2/Arsenal terminology carves a clear niche unlikely to trigger for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.