CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-havoc

Havoc C2 framework (C5pider/Havoc) — modern Sliver/CS alternative, Demon agent with indirect syscalls, sleep obfuscation (Ekko/Zilean/FOLIAGE), Donut PIC loader integration, profile-driven HTTP comms, MaterialUI web client. Best when you need modern OPSEC without Cobalt Strike cost.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2/havoc/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A practical, actionable operator skill with good code/config examples and a useful comparison table, but it is somewhat verbose with tutorial-style concept explanations, lacks validation checkpoints around destructive operations, and does not split detailed material into bundle reference files.

Suggestions

Trim explanatory prose about EDR hooking, static-string hashing, and module stomping to the operational essentials — Claude already understands these concepts.

Add explicit validation/verification checkpoints around destructive workflows (e.g., confirm listener is reachable before building a payload, verify payload executes before lateral movement).

Move the OPSEC technique deep-dive and the full command reference into separate files under references/ and link to them from SKILL.md to improve progressive disclosure.

DimensionReasoningScore

Conciseness

Mostly efficient with dense, useful tables and config/command examples, but several sections explain concepts Claude largely already knows ('Most EDRs hook NtAllocateVirtualMemory...', 'strings demon.exe | grep -i shell returns nothing', module stomping primer) that could be trimmed.

3 / 5

Actionability

Provides copy-paste-ready build commands, a full HCL profile example, numbered client-UI build steps, and a concrete command cheatsheet; minor gaps only (the CLI build path is explicitly noted as unavailable, forcing the Qt UI).

4 / 5

Workflow Clarity

A clear sequence (Setup → Configure profile → Build Demon → Run commands) is present, but destructive/batch operations (payload generation, lateral movement via jump, mimikatz) have no validation or verification checkpoints, capping this dimension at 3 per the rubric.

3 / 5

Progressive Disclosure

Well-organized section headers, but the skill is a single long file with no bundle files in references/scripts/assets; content like the OPSEC deep-dive, command reference, and comparison table that could live in one-level-deep reference files is inlined.

3 / 5

Total

13

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete capabilities and a clear use-case trigger, clearly distinguishing Havoc from alternatives. It could add a few more explicit 'when' trigger phrases and natural synonyms to reach the top level.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — 'indirect syscalls', 'sleep obfuscation (Ekko/Zilean/FOLIAGE)', 'Donut PIC loader integration', 'profile-driven HTTP comms', 'MaterialUI web client' — with comprehensive coverage of the framework's features.

5 / 5

Completeness

Clearly states what it does (capability list) and includes a 'Best when you need modern OPSEC without Cobalt Strike cost' trigger clause, but the 'when' is a single narrow scenario rather than multiple explicit trigger phrases.

4 / 5

Trigger Term Quality

Good natural keyword coverage ('Havoc C2', 'Demon agent', 'sleep obfuscation', 'Cobalt Strike') that a red-teamer would actually say, but misses some synonyms/common variations; not a 5 because coverage is not exhaustive.

4 / 5

Distinctiveness Conflict Risk

A clear niche (Havoc/Demon specifically) with named techniques and a named alternative; minimal conflict risk with other skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.