CtrlK
BlogDocsLog inGet started
Tessl Logo

c2-sliver

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2-sliver/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands and validation checkpoints, and is mostly concise. The biggest weakness is progressive disclosure: the bundled quickstart duplicates much of the main body rather than cleanly offloading detail.

Suggestions

De-duplicate the quickstart reference: keep only compact command tables in references/sliver-quickstart.md and have the main SKILL.md point to it for bulk command reference, rather than reproducing the same listener/implant/pivot blocks in both files.

Trim expository paragraphs (framework intro, BOF concept explanation) that restate knowledge Claude already has.

Add explicit verify-after-step feedback loops to the pivot and implant-generation workflows, mirroring the validation pattern already used in the connection procedure.

DimensionReasoningScore

Conciseness

The body is command-focused and largely lean, but includes some expository prose (the opening framework description, the BOF concept paragraph, and the 'Why BOFs Over execute-assembly' table) that assumes knowledge Claude already has and could be trimmed.

4 / 5

Actionability

Fully executable, copy-paste-ready commands with concrete flags, paths, timeouts, and session/is_input annotations throughout, plus a worked HTTP C2 profile JSON and a validation checklist covering common cases.

5 / 5

Workflow Clarity

Numbered sections, a sequenced connection procedure, CRITICAL compile-timeout rules, and an explicit validation checklist provide clear checkpoints; a few multi-step flows (e.g. pivot setup) lack verify-after-each-step feedback.

4 / 5

Progressive Disclosure

A one-level-deep reference (references/sliver-quickstart.md) is present and signaled, but it heavily duplicates the main body (listeners, implants, pivoting), so the split is not clean and the main file retains content that should be delegated.

3 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive, naming concrete Sliver capabilities with strong trigger terms. Its main weakness is the missing explicit 'Use when...' trigger clause in the description text itself.

Suggestions

Add an explicit 'Use when...' clause to the description, e.g. 'Use when the user needs Sliver C2 operations: setting up listeners, generating implants, or running BOFs.'

Move or duplicate key trigger phrases (C2, command and control, beaconing) from metadata tags into the description prose so they count toward trigger-term quality.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

The 'what' is clear and concrete, but there is no explicit 'Use when...' clause in the description; trigger guidance lives only in metadata.when_to_use, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Good coverage of natural terms ('Sliver, sliver-client, sliver listener, sliver implant, sliver beacon, armory, BOF'), but a few natural variants (e.g. 'C2', 'command and control') are only present in tags rather than the description prose.

4 / 5

Distinctiveness Conflict Risk

Clearly scoped to the Sliver C2 framework with distinct, product-specific triggers, giving minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.