CtrlK
BlogDocsLog inGet started
Tessl Logo

emulation-volt-typhoon

Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating stealthy LOTL pre-positioning. Triggers on: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, high-quality playbook body: copy-paste threat-profile seed, fully mapped kill chain with executable hand-offs, actor-accurate OPSEC fidelity rules, and well-considered safety gates for edge-device and OT risks. The only gaps are the absence of an explicit error-recovery loop in the workflow and cross-references that point outside the skill's own bundle.

DimensionReasoningScore

Conciseness

Lean and efficient throughout — every section carries actor-specific information (ThreatProfile seed, kill-chain table with MITRE mappings, CONOPS, OPSEC fidelity rules, RoE gates, deconfliction, deviation notes) with zero padding or explanation of concepts Claude already knows. No time-sensitive content outside a properly framed topical CISA reference.

5 / 5

Actionability

Fully actionable: a copy-paste-ready ThreatProfile JSON block, an 8-row kill-chain table mapping each phase to concrete actions, MITRE techniques, and exact executing-skill paths, named LOLBins (netsh, wmic, ntdsutil, vssadmin), and explicit CONOPS steps. For an instruction-only planning skill, the guidance is specific and executable as written.

5 / 5

Workflow Clarity

A clear 8-phase kill chain with a sequenced 5-step CONOPS and explicit safety checkpoints — 'require device-write authorization and confirm a config backup exists before exploiting', an EMERGENCY abort trigger, and the IT/OT boundary gate appropriately cap the destructive edge-exploitation risk. Not 5 because there is no error-recovery feedback loop (e.g., what to do if the edge exploit fails or the device becomes unresponsive) once execution hands off to the linked skills.

4 / 5

Progressive Disclosure

Good structure for a playbook overview: well-organized sections, all detail delegated to one-level-deep, per-phase skill paths in the kill-chain table, and the single reference to `../../references/apt-groups.md` clearly signaled ('see the industry → actor map'). Not 5 because the apt-groups.md reference sits outside this skill's bundle (no bundle references/, scripts/, or assets/ exist), so the navigation target cannot be verified from the skill itself, and the many cross-skill paths are unverifiable from this SKILL.md.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capability list, explicit 'Use when' plus trigger phrases, actor aliases as natural synonyms, all in third-person noun-phrase voice. Only minor risk is overlap on the generic LOTL/edge-device trigger terms shared with sibling adversary-emulation playbooks.

DimensionReasoningScore

Specificity

The description lists multiple concrete, specific actions — 'edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress' — giving comprehensive coverage of the playbook's capabilities with no generic filler.

5 / 5

Completeness

It explicitly answers both 'what' (adversary-emulation playbook with named capability areas) and 'when' via an explicit 'Use when emulating stealthy LOTL pre-positioning' clause plus a dedicated 'Triggers on:' list — matching the anchor example structure exactly.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including actor synonyms users would actually say: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'. This spans aliases, the LOTL colloquialism, and TTP shorthand.

5 / 5

Distinctiveness Conflict Risk

The actor names and aliases give it a clear, distinct niche, but the generic secondary triggers 'living off the land', 'edge device', and 'pre-positioning' would also match other LOTL/edge-focused actor playbooks in the same suite — a minor overlap risk with closely related skills. Not 5 because those shared terms could fire the wrong actor playbook; not 3 because the dominant triggers are unique actor identifiers.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.