CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-mythic

Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

87%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable skill body with copy-paste-ready commands and well-organized sections. The main gap is the engagement workflow, which lists steps but omits explicit validation checkpoints for its destructive/risky phases.

Suggestions

Insert validation/verification gates into the Common workflow — e.g. after delivery confirm a callback before enumerating, and verify lateral SMB reachability before pivoting — to lift workflow clarity to 3.

Add a brief 'verify / cleanup confirmation' checkpoint before the teardown step so destructive actions are gated on an explicit check.

DimensionReasoningScore

Conciseness

Dense, action-oriented content with no padded explanations of what a C2 is or basic concepts; tables and commands earn their tokens and assume Claude's competence.

3 / 3

Actionability

Fully executable, copy-paste-ready commands throughout — the full 'mythic-cli payload create' invocation with all parameters, install commands, and a complete Python scripting example.

3 / 3

Workflow Clarity

A clear 9-step 'Common workflow' sequence exists, but it involves destructive/risky operations (lateral movement, persistence, teardown) with no explicit validation or verify-before-proceeding checkpoints, capping clarity at 2 per the rubric.

2 / 3

Progressive Disclosure

No bundle files exist, but the body is cleanly organized into well-signaled sections (Setup, Agent matrix, Profile matrix, Build, Tasking, OPSEC, Workflow, Comparison) with no nested references and easy navigation.

3 / 3

Total

11

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description rich in natural trigger terms and concrete capabilities, distinct to the Mythic C2 niche. Its only weakness is the absence of an explicit 'Use when...' trigger clause, which leaves the 'when to use' half only implied.

Suggestions

Add an explicit trigger clause such as 'Use when operating Mythic C2, building/tasking Apollo/Poseidon/Apfell/Athena/Medusa agents, or designing C2 profiles.' to raise completeness to 3.

Consider trimming the backend detail ('RabbitMQ + PostgreSQL backend') which is less of a user-facing trigger and more implementation trivia.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'building an agent via mythic-cli', 'profile design (HTTP/SMB/named pipe/peer-to-peer)', 'opsec defaults', and names the specific agents (Apfell, Apollo, Athena, Poseidon, Medusa).

3 / 3

Completeness

Clearly answers 'what' (framework operations, agents, profiles, opsec) but lacks any 'Use when...' clause or equivalent explicit trigger guidance in the description field itself, which caps completeness at 2 per the rubric guidelines.

2 / 3

Trigger Term Quality

Natural operator-facing terms an engager would actually say are present — 'Mythic', 'C2', 'Apollo', 'Poseidon', 'Apfell', 'Athena', 'Medusa', 'mythic-cli', 'opsec' — with good coverage across the named agents.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (Mythic C2 specifically, with named agents) and would not trigger for unrelated skills; the named framework and agents make it highly distinguishable.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.