CtrlK
BlogDocsLog inGet started
Tessl Logo

dark-caracal

Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized, technically rich adversary-emulation reference with concrete operational parameters and a clear authorized-use caveat. Its main weaknesses are a monolithic single-file structure with no progressive disclosure, the absence of validation checkpoints in the emulation workflow, and descriptive (rather than directly executable) guidance that depends on other named skills.

Suggestions

Split the large TTP-by-tactic catalog and/or the detection-and-defense section into reference files (e.g., TTPS.md, DETECTION.md) and link them from a concise overview in SKILL.md to improve progressive disclosure.

Add an explicit validation/verification loop to the emulation workflow (e.g., 'validate the dropper unpacks and beacons before deploying; confirm C2 check-in before collection') to lift workflow_clarity past 2.

Dedupe techniques repeated across tactic sections (process hollowing, keylogging) and trim narrative victim-count flavor to tighten conciseness.

DimensionReasoningScore

Conciseness

The body is information-dense and avoids explaining concepts Claude already knows, but at ~165 lines it includes some redundancy (T1055.012 process hollowing and T1056.001 keylogging each appear in two tactic sections) and narrative flavor (exact victim/message counts) that could be tightened.

2 / 3

Actionability

It gives concrete, specific parameters (registry paths, the `&&&` C2 suffix marker, AES/Twofish schemes, `.rev` archives, masquerade identities), but the emulation guidance maps to other named skills and is descriptive rather than copy-paste executable code.

2 / 3

Workflow Clarity

Emulation plays are listed with some numbered sub-steps (e.g., the four-step dropper chain) and an authorized-use caveat, but it reads as a menu of plays rather than a sequenced end-to-end workflow, and there are no validation/verification checkpoints for risky implant deployment.

2 / 3

Progressive Disclosure

The single file is well-sectioned for easy navigation, but it is monolithic with no external references; at well over 50 lines the simple-skill exemption does not apply, and splittable content (the full TTP catalog, detection guidance, campaign history) is inline.

2 / 3

Total

8

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description precisely identifies a distinct, specific subject (Dark Caracal / G0070) in third person, but it functions more as an actor characterization than an action/capability list and lacks an explicit 'Use when...' trigger clause. Adding concrete actions and explicit use-trigger guidance would raise specificity and completeness.

Suggestions

Add an explicit 'Use when...' clause naming the trigger terms (e.g., 'Use when emulating Dark Caracal / G0070, or when the user mentions Bandook, CrossRAT, Pallas, or Poco RAT campaigns').

Append a concise list of concrete capabilities the skill provides (e.g., 'maps TTPs to emulation plays, lists signature tooling, and gives detection guidance') to lift specificity from 2 to 3.

Surface the malware-family trigger terms (Bandook, CrossRAT, Pallas, Poco RAT) into the description itself rather than only in metadata.when_to_use.

DimensionReasoningScore

Specificity

It names a concrete domain ("Adversary-emulation profile") and a specific subject ("Dark Caracal (G0070)... GDGS... operating since at least 2012"), but it characterizes the threat actor rather than listing multiple concrete actions the skill performs.

2 / 3

Completeness

It clearly answers *what* (an adversary-emulation profile for Dark Caracal) but provides no "Use when..." clause or equivalent explicit trigger guidance, which the rubric caps at 2.

2 / 3

Trigger Term Quality

The description contains the primary natural terms a user would say ("Dark Caracal", "G0070", "GDGS"), but omits common variations like the malware family names (Bandook, CrossRAT, Pallas, Poco RAT) that appear only in metadata.when_to_use.

2 / 3

Distinctiveness Conflict Risk

A profile scoped to a single named APT (Dark Caracal / G0070) is a clear niche with distinct triggers and is unlikely to fire for the wrong skill.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.