CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-havoc

Havoc C2 framework (C5pider/Havoc) — modern Sliver/CS alternative, Demon agent with indirect syscalls, sleep obfuscation (Ekko/Zilean/FOLIAGE), Donut PIC loader integration, profile-driven HTTP comms, MaterialUI web client. Best when you need modern OPSEC without Cobalt Strike cost.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable body with concrete build/config/command examples, but it is somewhat verbose (general EDR concept padding and a repeated Ekko explanation), lacks validation checkpoints in the build/deploy workflow, and keeps content that could be externalized inline.

Suggestions

Tighten conciseness by removing general EDR/background explanations ('Most EDRs hook NtAllocateVirtualMemory...') that Claude already knows, and consolidate the Ekko explanation so it appears once.

Add an explicit validation checkpoint in the build workflow — e.g. after starting the teamserver, verify the listener is up before building/dropping the Demon — to lift workflow_clarity.

Move the Havoc-vs-Sliver-vs-Mythic-vs-CS comparison table and the OPSEC deep-dive into separate reference files (e.g. COMPARISON.md, OPSEC.md) referenced one level deep from SKILL.md to improve progressive disclosure.

DimensionReasoningScore

Conciseness

Mostly efficient Havoc-specific detail, but includes general EDR concept explanations Claude already knows ('Most EDRs hook NtAllocateVirtualMemory...') and repeats Ekko twice (build steps and OPSEC section).

2 / 3

Actionability

Provides copy-paste-ready build commands, a complete HCL profile example, a numbered Demon-build sequence, and concrete operator commands — fully executable guidance.

3 / 3

Workflow Clarity

A clear setup→configure→build→deploy sequence exists, but there are no validation checkpoints (e.g. verify the teamserver/listener is live before building the Demon, confirm a check-in).

2 / 3

Progressive Disclosure

Well-organized into sections, but everything is inline in one file — the comparison table, the OPSEC deep-dive, and the full profile reference could be split into one-level-deep reference files rather than living in SKILL.md.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that uses third-person voice, lists concrete capabilities, includes natural trigger terms, and provides an explicit 'Best when...' usage clause. It clearly distinguishes Havoc from adjacent C2 frameworks.

DimensionReasoningScore

Specificity

Names multiple concrete capabilities — 'Demon agent with indirect syscalls', 'sleep obfuscation (Ekko/Zilean/FOLIAGE)', 'Donut PIC loader integration', 'profile-driven HTTP comms' — rather than vague language.

3 / 3

Completeness

Answers both 'what' (the framework and its features) and 'when' via the explicit trigger clause 'Best when you need modern OPSEC without Cobalt Strike cost', so it is not capped at 2.

3 / 3

Trigger Term Quality

Includes natural terms a red-team operator would actually say — 'Havoc C2 framework', 'Demon agent', 'sleep obfuscation', 'indirect syscalls', 'OPSEC', 'Cobalt Strike'.

3 / 3

Distinctiveness Conflict Risk

'Havoc C2 framework' is a narrow, clearly defined niche with distinct triggers, making it unlikely to fire for an unrelated skill.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.