Cleanup & restoration plan generator — artifact inventory, persistence removal commands, pre-engagement baseline, post-engagement verification.
64
76%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/standard/soundwave/cleanup-template/SKILL.mdThe cleanup plan is the anti-foothold roster — every artifact the kill chain will create must have a concrete removal command and a verifier, or dummy accounts / scheduled tasks / beacons routinely outlive the engagement.
For every phase in CONOPS.kill_chain, infer which CleanupArtifact.artifact_type entries will be produced:
| Kill Chain Phase | Likely artifact_types |
|---|---|
| recon | tool (installed scanners), network-rule (firewall whitelist) |
| initial-access | account (test users), file (uploaded payloads), tool (web shells) |
| post-exploit | persistence-mechanism (scheduled-task / service / registry-run), account (created backdoor users), file (dropped binaries) |
| c2 | beacon (C2 implants), network-rule (egress allow), tool (sliver / cobalt-strike payloads) |
| exfiltration | file (staged exfil archives), network-rule (DNS tunneling) |
For each expected artifact, set:
artifact_type — category abovehost — placeholder (e.g. "<initial-access target>") — operations agents replace at run timepath — likely filesystem / registry / account-name locationpersistence_mech — concrete mechanism if applicableremoval_command — idempotent shell or API call to removeverifier_command — zero-exit on successcreated_by_objective — left blank; operations agents fill on creationremoved=False, removed_at=""Set pre_engagement_baseline to whatever snapshot reference the operator gives during the interview (volume ID, AWS AMI, hypervisor snapshot, manual filesystem hash list). If no baseline is available, record that explicitly — it's a critical risk signal for the engagement owner.
Default schema text covers most engagements. Override only when the engagement specifies different completion semantics (e.g. "leave honeyfile FILE_X in place for blue team training" — note as a cancellation_reason on that artifact later).
Before writing plan/cleanup.json:
removal_commandpath references an out-of-scope hostpre_engagement_baseline is either set or explicitly marked "no baseline available"removal_command empty — operations agents will skip the artifact entirely/workspace/<eng> inside the sandbox; cleanup runs on TARGETS not the workspace)Write to plan/cleanup.json validating against decepticon.core.schemas.CleanupPlan.
e34afba
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.