CtrlK
BlogDocsLog inGet started
Tessl Logo

evilginx2-proxy

Author and deploy an evilginx2 phishlet to reverse-proxy a real login and capture the post-authentication session cookie, defeating MFA via session-token theft.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/phisher/evilginx2-proxy/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise, well-structured, and largely actionable, with executable evilginx commands for the core workflow. Its main weakness is the absence of explicit validation/verification checkpoints in the deploy-and-capture flow, which caps workflow clarity.

Suggestions

Add explicit validation steps after Deploy (e.g., 'verify phishlet enabled', 'confirm lures get-url returns a reachable HTTPS URL', 'confirm ACME cert issued') and after Capture (e.g., 'verify sessions <id> shows non-empty token JSON before replay').

Provide a minimal concrete phishlet YAML example in the Authoring section showing auth_tokens and a sub_filter, so authoring is copy-pasteable rather than purely descriptive.

DimensionReasoningScore

Conciseness

Lean and efficient: the intro states only the essential AiTM rationale and the rest is commands and terse directives, with no padding or explanation of concepts Claude already knows.

5 / 5

Actionability

Deploy and Capture sections give copy-paste-ready evilginx console commands, but the Authoring section is descriptive guidance ('list them under auth_tokens') with no concrete phishlet YAML template, leaving a minor gap.

4 / 5

Workflow Clarity

The Prereqs → Deploy → Author → Capture → Evidence → OPSEC sequence is clear, but validation checkpoints are missing or implicit (no 'verify phishlet enabled', 'confirm cert issued', or 'confirm lure URL resolves'), and the rubric caps workflow clarity at 3 without explicit verification steps.

3 / 5

Progressive Disclosure

No bundle files exist and the body is ~50 lines with well-organized, clearly headed sections; per the simple-skill exception this scores 5 with clean section structure and one-level cross-skill references (lookalike-domain, lure-deconfliction).

5 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, actionable, and clearly distinct, but it omits any explicit 'Use when...' trigger guidance, which limits its completeness and natural-discoverability. Adding a trigger clause would lift the weakest dimension.

Suggestions

Append an explicit 'Use when...' clause naming natural trigger phrases (e.g., 'Use when the target enforces MFA and you need evilginx2 phishlet deployment, AiTM reverse-proxy phishing, or session-cookie capture').

Add softer synonyms users actually say ('phishing campaign', 'adversary-in-the-middle', 'cookie stealing') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Author and deploy an evilginx2 phishlet to reverse-proxy a real login and capture the post-authentication session cookie, defeating MFA via session-token theft' — covering authoring, deployment, proxying, capture, and MFA defeat comprehensively.

5 / 5

Completeness

The 'what' is clear and concrete, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the rubric caps completeness at 3; 'when' is only weakly implied.

3 / 5

Trigger Term Quality

Good coverage of niche-relevant terms a practitioner would actually say ('evilginx2', 'phishlet', 'session cookie', 'MFA', 'reverse-proxy'), though softer natural phrasing like 'phishing' or 'Use when...' is absent.

4 / 5

Distinctiveness Conflict Risk

Names a highly specific tool and technique (evilginx2 phishlet, AiTM session-token theft) giving it a clear niche with minimal overlap risk against other skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.