CtrlK
BlogDocsLog inGet started
Tessl Logo

c2

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is lean, token-efficient, and highly actionable with concrete configs, tables, and diagrams, but it is a monolithic document with no progressive file structure and its decision-gate workflow lacks explicit validation/feedback loops for the destructive operations it branches into.

Suggestions

Split deep-dive material (per-framework malleable profiles, redirector hardening) into reference files under references/ and signal them with one-level-deep links to improve progressive disclosure.

Add an explicit validate→fix→retry feedback loop around the decision gate (e.g. 'after lateral movement attempt, re-confirm C2 stability and check for new detections before proceeding') to lift workflow clarity.

Treat the pre-lateral-movement checklist as a gated step with pass/fail outcomes rather than a flat checkbox list.

DimensionReasoningScore

Conciseness

The body is dense reference material — tables, ASCII diagrams, and a concrete nginx config — with almost no prose explaining concepts Claude already knows; every section earns its tokens, matching the lean level-3 anchor.

3 / 3

Actionability

It provides copy-paste-ready guidance: a full nginx redirector config, specific jitter/OPSEC tables, output file tree, and concrete tool mappings, matching the level-3 anchor of fully executable code and specific examples.

3 / 3

Workflow Clarity

The 'Pre-Lateral-Movement Checklist' supplies explicit checkpoints, but the destructive/batch operations implied (lateral movement, defense evasion, persistence) lack a validate→fix→retry feedback loop, and per the scoring notes missing feedback loops in these contexts caps workflow_clarity at 2.

2 / 3

Progressive Disclosure

The file is a monolithic 200-line single SKILL.md with no references/ or scripts/ bundle to offload detail (Sliver/Havoc specifics point to other skills, not local files); while well-sectioned, it keeps content that could be split inline, matching the level-2 anchor.

2 / 3

Total

10

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and occupies a clearly distinct C2 niche, but it omits any explicit 'when to use' trigger guidance, so it answers 'what' well while 'when' is only implied by domain terms.

Suggestions

Add an explicit trigger clause, e.g. 'Use when planning or troubleshooting C2 infrastructure, listeners, redirectors, beacon/implant behavior, or OPSEC for command-and-control.'

Soften jargon with at least one natural phrasing a user might actually say (e.g. 'command and control', 'beacon check-ins') to improve trigger-term quality.

Confirm the when-to-use trigger terms currently in metadata.when_to_use are surfaced in the description itself, since the description alone lacks them.

DimensionReasoningScore

Specificity

Enumerates multiple concrete capabilities — 'listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance' — matching the level-3 anchor listing several specific concrete actions.

3 / 3

Completeness

Clearly states what the skill does (orchestration across the listed components) but lacks any explicit 'Use when...' trigger clause; per the judging guidelines a missing when-clause caps completeness at 2.

2 / 3

Trigger Term Quality

Domain terms (C2, implant, redirector, listener, malleable profiles) are technically apt but read as specialist jargon rather than natural phrasing a user would say; coverage of common variations is thin, sitting between anchors 2 and 3 but leaning to 2.

2 / 3

Distinctiveness Conflict Risk

The C2/command-and-control niche is sharply defined and unlikely to trigger for unrelated skills, matching the level-3 anchor of a clear niche with distinct triggers.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.