CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-domain-fronting

Domain fronting and CDN abuse for C2 concealment — CloudFront, Azure CDN, Fastly setup, TLS SNI vs Host header technique, CDN-based redirectors, and integration with Cobalt Strike and Sliver.

66

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2-domain-fronting/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced operational guide with strong validation feedback via its decision gate and error tables. It loses points for verbosity/conceptual padding and for keeping everything in a single monolithic file rather than splitting deep provider/tool references.

Suggestions

Trim the conceptual 'How It Works' intro and ASCII diagram to a one-line summary; Claude already understands TLS SNI vs Host header fronting.

Extract the per-provider setups (CloudFront/Azure/Fastly) and the Cobalt Strike/Sliver profiles into separate reference files (e.g. references/cloudfront-setup.md, references/malleable-profiles.md) and link them one level deep from SKILL.md.

DimensionReasoningScore

Conciseness

The bulk is action-dense (commands, JSON/nginx/malleable configs, worker code, tables), but the intro paragraph, ASCII diagram, and 'TLS layer / HTTP layer' breakdown re-explain fronting concepts Claude already knows, and the ~488-line length is verbose even though accurate.

2 / 3

Actionability

Fully executable, copy-paste-ready guidance throughout — aws/az/curl commands, CloudFront JSON config, malleable C2 profile, Sliver profile, nginx and Cloudflare Worker code — with explicit placeholders and expected outputs.

3 / 3

Workflow Clarity

Numbered setup steps, a 'Test fronting' checkpoint with explicit success/failure criteria (HTTP 200 vs 403), a Decision Gate tree, and Error Handling tables provide clear sequencing with feedback loops for recovery.

3 / 3

Progressive Disclosure

No bundle files exist and the entire skill is one monolithic 488-line file; well-organized sections keep it above 1, but provider-specific setups and C2 profiles that could be split into separate references are all inline.

2 / 3

Total

10

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-triggered description naming concrete providers, techniques, and C2 frameworks. Its only gap is the missing explicit 'Use when...' guidance, which bounds completeness at 2.

Suggestions

Append an explicit trigger clause, e.g. 'Use when concealing C2 traffic via domain fronting, CDN redirectors, or SNI/Host header mismatch on CloudFront, Azure CDN, or Fastly.'

Surface the high-value trigger shorthand from metadata.when_to_use (e.g. 'cdn c2', 'SNI mismatch') directly in the description so natural phrasings are present.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — 'CloudFront, Azure CDN, Fastly setup', 'TLS SNI vs Host header technique', 'CDN-based redirectors', 'integration with Cobalt Strike and Sliver' — rather than vague language.

3 / 3

Completeness

Clearly answers 'what' (fronting setup, technique, redirectors, C2 integration) but has no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 2 per the guidelines.

2 / 3

Trigger Term Quality

Covers natural terms an operator would actually say — 'domain fronting', 'CDN', 'C2', 'CloudFront', 'Azure CDN', 'Fastly', 'SNI', 'Cobalt Strike', 'Sliver' — with good breadth.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (CDN-based C2 concealment via fronting) with provider- and tool-specific triggers, making it unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.