CtrlK
BlogDocsLog inGet started
Tessl Logo

emulation-volt-typhoon

Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating stealthy LOTL pre-positioning. Triggers on: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, well-structured adversary-emulation playbook that maps each kill-chain phase to concrete actions and delegated skills, with strong OPSEC, RoE, and deconfliction guidance and no wasted tokens. Main gaps are that execution relies on pointers to external skills rather than inline executable code, and validation is framed as safety gates rather than technical feedback loops.

Suggestions

Add a short validate→fix→retry feedback loop for the technical artifacts the skill does produce (e.g., validate the JSON threat-profile/conops against its schema before recording), which would lift workflow_clarity to a 5.

For the highest-risk step (edge-device exploitation), make the pre-exploit validation an explicit ordered checklist (confirm authorization → confirm config backup exists → exploit) rather than prose, mirroring the level-5 workflow anchor.

Clarify which referenced paths are sibling files in this skill's bundle versus external repo skills, so navigation targets are unambiguous and verifiable.

DimensionReasoningScore

Conciseness

Lean, expert-level body that assumes competence — no padding explaining what an APT or LOTL is, and every section (kill-chain table, CONOPS, OPSEC, RoE gates, fidelity notes) earns its place.

5 / 5

Actionability

Provides a concrete kill-chain table mapping phase→MITRE→action→executing skill, a copy-ready JSON threat-profile seed, and a numbered CONOPS to drop into conops.json; actual execution is delegated to other skills via explicit paths, leaving a minor gap versus fully copy-paste-ready code.

4 / 5

Workflow Clarity

Clear phased sequence with explicit safety/abort gates ('EMERGENCY' abort on OT/safety systems, device-write authorization + config-backup check before exploiting) and deconfliction/cleanup recording; checkpoints are safety gates rather than technical validate→fix→retry feedback loops, leaving a minor gap.

4 / 5

Progressive Disclosure

Well-organized into clearly labeled sections that point one level deep to external skill paths and an apt-groups reference; however those referenced paths (../../references/apt-groups.md, /skills/standard/...) are not part of this skill's bundle and cannot be verified, and some inline reference material could be split out.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete capabilities, provides comprehensive natural trigger terms, and explicitly states both what the skill does and when to use it in third-person voice. No vague fluff or over-claims.

DimensionReasoningScore

Specificity

Names multiple concrete actions — 'edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning ... multi-hop proxy egress' — giving comprehensive coverage of the playbook's capabilities.

5 / 5

Completeness

Explicitly answers both what (adversary-emulation playbook with the listed LOTL capabilities) and when ('Use when emulating stealthy LOTL pre-positioning' plus enumerated trigger phrases), matching the level-5 anchor.

5 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including synonyms and designations users would say: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear, narrow niche (a single named APT's LOTL pre-positioning tradecraft) with distinctive triggers, so conflict with other skills is minimal.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.