CtrlK
BlogDocsLog inGet started
Tessl Logo

dark-caracal

Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is a thorough, well-structured adversary-emulation profile with strong actionability in its emulation guidance. Its main weaknesses are verbosity from inlined campaign history and ATT&CK enumerations, and the absence of explicit validation/feedback loops for destructive or surveillance operations.

Suggestions

Move the detailed campaign timeline and full ATT&CK ID enumeration into a separate reference file (e.g. references/campaigns.md, references/ttps.md) and keep SKILL.md as a concise overview with one-level-deep links.

Add explicit validation checkpoints in the emulation guidance (e.g. verify scope/authorization before each phase, confirm lab isolation before mobile/Pallas deployment, validate payload execution before collection).

Trim narrative attribution prose that Claude can derive from the cited sources, retaining only the operationally relevant TTP and tooling detail.

DimensionReasoningScore

Conciseness

The body is information-dense and mostly avoids generic concept explanations, but it is long and includes narrative attribution/campaign history and a large enumeration of ATT&CK IDs that pads context beyond what an emulation skill strictly needs.

3 / 5

Actionability

The 'Emulation guidance' section maps signature plays to concrete capabilities and tools (Sliver, .rev archives, process hollowing into iexplore.exe, the '&&&' C2 marker) with specific, executable direction, though it references other skills generically rather than giving standalone commands.

4 / 5

Workflow Clarity

TTPs are well-organized by tactic and emulation plays are listed as discrete steps, but the destructive/surveillance operations lack explicit validation checkpoints or feedback loops, capping workflow clarity at 3 per the rubric's destructive/batch cap.

3 / 5

Progressive Disclosure

Content is cleanly sectioned (attribution, targeting, campaigns, TTPs by tactic, tooling, emulation, detection, sources) with no bundle files to defer to, so the monolithic-but-organized structure is well navigable with only minor bloat that could live in references.

4 / 5

Total

14

/

20

Passed

Description

63%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly specific and distinctive for a named threat actor, but it functions as an attribution summary rather than a use-triggered skill description. Adding an explicit 'Use when...' clause and more action-oriented verbs would raise completeness and specificity.

Suggestions

Add an explicit 'Use when...' trigger clause, e.g. 'Use when emulating Dark Caracal (G0070) TTPs, planning Lebanese GDGS surveillance campaigns, or building Bandook/CrossRAT/Pallas emulation scenarios.'

Reframe the description around concrete actions the skill performs (e.g. 'Profiles and emulates...', 'Maps TTPs to...') rather than only characterizing the actor.

Include common synonyms a user might say, such as 'APT' or 'threat actor profile', to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

The description names the domain and multiple concrete attributes (espionage, surveillance, GDGS attribution, operating since 2012) but reads more as an attribution profile than a list of concrete skill actions, leaving minor coverage gaps.

4 / 5

Completeness

It clearly answers 'what this is' (an adversary-emulation profile for Dark Caracal) but provides no explicit 'Use when...' trigger clause, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Strong natural keywords appear ('Dark Caracal', 'G0070', 'espionage', 'surveillance', 'Bandook RAT', 'CrossRAT'), covering the terms a threat-intel user would actually say, though some common synonyms (e.g. 'APT', 'threat actor profile') are missing.

4 / 5

Distinctiveness Conflict Risk

The description targets a uniquely named actor (G0070 / Dark Caracal / GDGS) with distinct tooling triggers, making conflict with other skills minimal.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.