CtrlK
BlogDocsLog inGet started
Tessl Logo

c2

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/c2/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, largely actionable C2 reference with concrete configs, a decision gate, and a validation checklist, with only minor conciseness and progressive-disclosure gaps. The main weakness is the malleable-profiles section, which stays conceptual where an example profile would make it executable.

Suggestions

Add at least one concrete malleable-profile example (e.g., a Sliver HTTP C2 JSON or Havoc YAOTL snippet) so that section matches the actionability of the redirector config.

Trim the intro paragraph and the malleable-profile "Concept" section to assume Claude's existing knowledge of what C2 is.

Add a brief validate-fix-retry loop for redirector/C2 bring-up (e.g., confirm implant callback, check redirector logs for IR probing, retry with fallback channel) to strengthen workflow clarity.

DimensionReasoningScore

Conciseness

The body is dense and table/diagram-driven with little padding; only the brief intro and the malleable-profile "Concept" paragraph lightly restate knowledge Claude already has and could be trimmed.

4 / 5

Actionability

The NGINX redirector config and output-file layout are copy-paste ready and the decision gate is concrete, but the malleable-profiles section gives principles without an actual example profile, leaving a minor gap.

4 / 5

Workflow Clarity

The decision gate and Pre-Lateral-Movement Checklist provide clear sequencing and an explicit validation checkpoint before risky movement; the C2-setup step itself lacks a validate-fix-retry feedback loop.

4 / 5

Progressive Disclosure

Content is organized into eight numbered sections with clearly signaled one-level-deep deferrals to sibling skills ("consult the dedicated skill: c2-sliver"), with no nested references; some large reference blocks (detection signatures, malleable profiles) could be split into separate files.

4 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped to a distinct C2 niche with good trigger-term coverage, but it lacks an explicit "Use when..." trigger clause, which caps its completeness. Adding a concrete when-to-use phrase would lift the strongest remaining weakness.

Suggestions

Append an explicit trigger clause, e.g. "Use when planning or standing up C2 infrastructure, designing listeners/redirectors, or tuning beacon jitter and OPSEC."

Add high-frequency synonyms ("beacon", "command and control", "teamserver", "payload delivery") so the description matches more natural user phrasing.

Reframe topic nouns as actions ("Design redirector architecture", "Tune beacon jitter") to align with the verb-based specificity anchor.

DimensionReasoningScore

Specificity

The description enumerates six concrete domain topics ("listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance"), giving comprehensive coverage, but they are noun-phrase topics rather than the verb-based actions the 5-anchor exemplifies.

4 / 5

Completeness

It clearly states the "what" (framework-agnostic C2 orchestration across named areas) but contains no "Use when..." clause or explicit trigger guidance in the description field, which caps completeness at 3 per the guidelines.

3 / 5

Trigger Term Quality

It surfaces natural operator terms a user would say ("C2", "listener", "implant", "redirector", "jitter", "OPSEC"), but omits common synonyms a user might equally say such as "beacon", "command and control", and "teamserver".

4 / 5

Distinctiveness Conflict Risk

"Framework-agnostic C2 orchestration" carves a clear niche distinct from sibling framework-specific skills, with only minor overlap risk against the c2-sliver/c2-havoc skills it defers to.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.