CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-mythic

Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.

58

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2/mythic/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is dense, actionable, and well-organized with copy-paste-ready CLI commands and useful matrices. Weaknesses are the absence of validation checkpoints in the operational workflow and a monolithic structure with no progressive disclosure into bundle files.

Suggestions

Add validation checkpoints to the Common workflow — e.g. 'Confirm the callback is healthy (whoami/hostname return expected host) before lateral movement' and 'If no callback within N intervals, rebuild the payload and re-deliver.'

Split the agent/profile matrices and the Sliver/Cobalt Strike/Havoc comparison into reference files (e.g. AGENTS.md, PROFILES.md) referenced one level deep, keeping SKILL.md an overview.

Verify or correct the Python scripting example's imports against the actual mythic package so the snippet is copy-paste runnable.

DimensionReasoningScore

Conciseness

Lean and action-oriented — bash commands, compact matrices, and a one-line intro with minimal padding; it assumes Claude knows C2 concepts. Not 5 because the 'Comparison vs Sliver / Cobalt Strike / Havoc' table and the intro 'Strengths:' sentence restate some context Claude largely already knows.

4 / 5

Actionability

Mostly executable guidance — full install/build/profile CLI commands are copy-paste ready and cover the common cases, matching the 'mostly executable; minor gaps' anchor. Not 5 because the Python scripting snippet imports modules ('mythic_utilities', 'mythic_callbacks') whose names are questionable, making that part not reliably runnable.

4 / 5

Workflow Clarity

A clear 9-step 'Common workflow' sequence is present (setup → redirector → build → deliver → survey → enum → lateral → persistence → cleanup), but it has no validation/verification checkpoints or feedback loops. Because this is a destructive C2 operational workflow, the rubric caps workflow clarity at 3.

3 / 5

Progressive Disclosure

The skill is well-sectioned (Setup, Agent matrix, Profile matrix, Build, Tasking, OPSEC, Workflow, Comparison, References) but is a monolithic ~130-line body with no bundle files, and inline content (agent/profile matrices, comparison table) that could be split into reference files. The References section points to external URLs, not clearly-signaled local files.

3 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is dense, specific, and highly distinctive, naming the framework, its agents, and concrete capabilities. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which caps completeness.

Suggestions

Add an explicit trigger clause, e.g. 'Use when operating Mythic C2, tasking Apollo/Poseidon/Athena/Apfell/Medusa agents, or designing HTTP/SMB/DNS C2 profiles.'

Lead with user-facing actions (task agents, build payloads, design profiles) before architectural facts (RabbitMQ, PostgreSQL, port 7443) to lift specificity.

Include common synonyms users say ('beacon', 'callback', 'implant', 'post-exploitation') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists several specific concrete capabilities — 'multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa)', 'building an agent via mythic-cli', 'profile design (HTTP/SMB/named pipe/peer-to-peer)', 'opsec defaults' — which matches the 'several specific actions; minor gaps' anchor. It is not a clean 5 because several items ('web UI on 7443', 'RabbitMQ + PostgreSQL backend', 'JSON-RPC tasking model') are architecture facts rather than user-facing actions.

4 / 5

Completeness

The 'what' is clear and detailed, but there is no explicit 'Use when...' clause or equivalent trigger guidance in the description field, which per the rubric caps completeness at 3. The 'when' is only weakly implied by naming Mythic and its agents.

3 / 5

Trigger Term Quality

Strong natural keyword coverage — 'Mythic C2', agent names (Apollo, Poseidon, Athena, Apfell, Medusa), 'mythic-cli', plus the when_to_use metadata adding 'command and control', 'payload', 'tasking', 'opsec'. Not 5 because common synonyms a user might say ('beacon', 'callback', 'implant', 'post-exploitation') are absent from the description.

4 / 5

Distinctiveness Conflict Risk

Clear niche with distinct triggers — names the Mythic framework specifically, its agent roster, port 7443, and a Sliver comparison — so it would only activate for Mythic C2 work with minimal conflict risk.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.