CtrlK
BlogDocsLog inGet started
Tessl Logo

dfir-overview

Use to close the Offensive Vaccine loop on the defender side. The Detector agent produces Sigma / YARA rules from offensive operations; this catalog validates those rules against real memory dumps, event logs, and forensic artifacts using Volatility 3, plaso, and sigma-cli. Without this catalog, detection rules are theoretical.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/dfir/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

66%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured with a strong, explicitly validated workflow and a clear feedback loop. It is held back by a non-actionable marketing/differentiation section and several workflow steps that describe collection/replay actions without giving the actual commands.

Suggestions

Replace or cut the 'Why this is differentiating' section; keep only one sentence of rationale and remove the competitor-comparison prose to reclaim tokens.

Add concrete collection/replay commands for the steps that currently only describe them (e.g., the event-log collection command from the DC and the Velociraptor/OSQuery replay invocation).

Give each playbook row a one-line example invocation so the table doubles as a copy-paste command reference.

DimensionReasoningScore

Conciseness

The playbook table, workflow, and tools list are lean and assume Claude's knowledge, but the 'Why this is differentiating' section is marketing-style rationale ('Strix doesn't have this. XBOW doesn't have this') that adds tokens without aiding execution.

3 / 5

Actionability

Concrete fragments exist (sigma-cli convert --target sqlite, sigma_to_* rule pushers, named Volatility plugins, yr path), but key collection steps ('Collecting the event log from the DC at attack time', 'Replay an attack against a target') lack actual commands, leaving the workflow partly high-level.

3 / 5

Workflow Clarity

A clear 5-step numbered sequence with an explicit validation checkpoint (match count check) and a defined error-recovery feedback loop ('If match count is 0 -> iterate with Detector'), matching the anchor for explicit validation and feedback loops.

5 / 5

Progressive Disclosure

Deliberately flat, self-contained structure with clearly labeled sections and an explicit note that the playbook entries are inline references (not separately loadable skills); no nested references, though the dense inline playbook table could benefit from a small reference split.

4 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, well-scoped to a distinct DFIR validation niche, and includes strong natural trigger keywords for the domain. Its main gap is that the 'when to use' framing leans on purpose/rationale rather than an explicit, user-said trigger clause.

Suggestions

Add an explicit 'Use when ...' trigger clause naming user-side phrases (e.g., 'Use when validating Sigma/YARA detection rules against captured .evtx logs, memory dumps, or forensic artifacts').

Include common file extensions and synonyms (.evtx, .dmp, .yara, super-timeline) alongside the tool names to broaden trigger coverage.

Lead with the skill's primary action verb rather than 'Use to close the loop' so the 'what' lands before the rationale.

DimensionReasoningScore

Specificity

Names concrete tools (Volatility 3, plaso, sigma-cli), artifacts (memory dumps, event logs, forensic artifacts), and rule types (Sigma/YARA), with a concrete 'validates those rules against real...' action; gaps are minor (the description's action verbs are fairly singular).

4 / 5

Completeness

Clearly states what the catalog does (validates detection rules against real artifacts) and offers a trigger/purpose clause ('Use to close the Offensive Vaccine loop on the defender side'), but the 'when' is framed as purpose rather than an explicit user-said trigger phrase.

4 / 5

Trigger Term Quality

Strong keyword coverage of the DFIR domain's natural terms ('memory dumps, event logs, forensic artifacts', 'Sigma / YARA', 'detection rules', 'blue team'), but lacks file extensions (.evtx, .dmp, .yara) and synonyms that would lift it to 5.

4 / 5

Distinctiveness Conflict Risk

A clearly distinct niche (defender-side detection-rule validation within the Offensive Vaccine loop) with tool-specific triggers, making conflict with other skills minimal.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.