CtrlK
BlogDocsLog inGet started
Tessl Logo

emulation-scattered-spider

Scattered Spider (UNC3944 / Octo Tempest) adversary-emulation playbook — help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion. Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate. Triggers on: 'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, well-organized planning playbook: a copy-paste ThreatProfile seed, a phase-by-phase kill-chain table delegating execution to named skills, an explicit CONOPS, and strong RoE/deconfliction gates for the destructive operations. The residual gaps are the absence of a feedback loop when a gate fails and single-file organization with no reference split.

Suggestions

Add a short feedback loop for the RoE gates — e.g., 'if written authorization or the lure-deconfliction pass is not in place, pause the phase and escalate to the engagement POC' — to raise workflow clarity to the top anchor.

The 'Fidelity notes (deviations)' section repeats the canary-only impact and engagement-controlled MFA/RMM points already stated under 'RoE / safety gates' and 'OPSEC & signature fidelity'; trim it to deviations not stated elsewhere.

If the per-phase kill-chain detail (MITRE mappings, executing agents) grows further, move it into a references/ file so SKILL.md stays a lean overview with well-signaled one-level-deep references.

DimensionReasoningScore

Conciseness

The body is dense and lean throughout — tables, tight bullets, and a copy-paste JSON seed — with no explanation of concepts Claude already knows (no 'what is Okta/vishing' padding). Every section carries actor-specific delta (e.g., "help-desk reset anomaly, a new MFA device, an unexpected RMM install, a new VM" as the detection signature), so every token earns its place per the top anchor.

5 / 5

Actionability

Guidance is fully concrete: a copy-paste ThreatProfile JSON seed ("copy into `conops.json`" numbered mapping), a 10-phase table assigning each phase an executing agent and a specific skill path (e.g., "/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md"), named artifact files ("`deconfliction.json` + `cleanup.json`"), and quoted abort-trigger text. This matches the 5 anchor's copy-paste-ready coverage of the common cases.

5 / 5

Workflow Clarity

The sequence is clear (10-phase kill-chain table mapped to a 5-step CONOPS) with real checkpoints for the destructive operations — written authorization gates, canary-only impact, an explicit "EMERGENCY abort trigger", and time-boxed vishing windows — which avoids the destructive-ops cap. It falls short of the 5 anchor only because there is no feedback/recovery loop for a failed gate (e.g., what to do when written authorization or the lure-deconfliction pass is not yet in place).

4 / 5

Progressive Disclosure

Structure is good: clean sections at overview altitude, with execution detail correctly delegated via one-level-deep direct skill paths in the kill-chain table (no bundle files exist to verify or split into). It sits at the 4 anchor rather than 5 because all content lives in a single ~94-line file — appropriate here, but navigation depends entirely on inlined cross-skill paths rather than well-signaled reference files.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states what the playbook covers (a five-stage identity-first eCrime chain) and when to use it, backed by an explicit, synonym-rich trigger list of actor aliases and natural technique terms. Its only weakness is minor overlap risk with other identity-attack/emulation skills via broad triggers like 'identity attack'.

DimensionReasoningScore

Specificity

The description lists a chain of five concrete actions — "help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion" — which comprehensively covers the emulation scope from initial access through impact. This matches the anchor for multiple specific concrete actions with comprehensive coverage; a 4 would require minor gaps in coverage, but the full kill chain is named.

5 / 5

Completeness

It explicitly answers both questions: what ("adversary-emulation playbook — help-desk vishing → MFA takeover → … → data-theft extortion") and when ("Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate", plus an explicit 'Triggers on:' clause with concrete trigger phrases). This matches the 5 anchor exactly; the 4 anchor requires a 'when' that could be more explicit, which is not the case here.

5 / 5

Trigger Term Quality

The explicit trigger list — "'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'" — covers the actor name plus multiple aliases/synonyms and natural technique phrases a user would actually say. Comprehensive synonym coverage (UNC3944, Octo Tempest, 0ktapus) fits the top anchor rather than the 4 anchor's 'a few natural terms missing'.

5 / 5

Distinctiveness Conflict Risk

The actor-specific framing (Scattered Spider / UNC3944 / Octo Tempest) carves a clear niche, but generic technique triggers like "'identity attack'", "'SIM swap'", and "'MFA fatigue'" are also used by other threat actors and could overlap with sibling identity-attack or adversary-emulation skills. This fits the 4 anchor (mostly distinct, minor overlap with closely related skills) better than the 5 anchor's minimal conflict risk.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.