CtrlK
BlogDocsLog inGet started
Tessl Logo

fin7-carbanak

Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/fin7-carbanak/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-organized adversary-emulation profile with strong TTP-to-tooling mapping and clear authorization guardrails, but it is verbose for a skill body, contains no standalone executable code, and is monolithic rather than split across reference files.

Suggestions

Tighten or move background threat-intel (campaign dates, sector lists, vendor citations) into a reference file so the body stays lean and respects the context budget.

Add a few concrete, executable commands or one-line snippets in the emulation-guidance steps (e.g., a Sliver listener config, a Kerberoasting command) to raise actionability.

Add explicit validation checkpoints in the impact/ransomware workflow (e.g., confirm scope authorization before the benign canary routine) and split the campaign/TTP/tool catalogs into separate reference files for progressive disclosure.

DimensionReasoningScore

Conciseness

The profile is mostly efficient for a reference doc, but it spends tokens on background narrative Claude largely already knows (campaign dates, sector lists, vendor citations), which pads a skill body; it is not lean enough for a 3.

2 / 3

Actionability

The emulation-guidance section gives concrete, TTP-mapped steps (typosquatted IT-tool page, POWERTRASH-style loader, Sliver listeners, Kerberoasting via AD skills), but it is instruction-style referencing other skills with no standalone copy-paste executable code, so it is not fully 3.

2 / 3

Workflow Clarity

The emulation chain is well sequenced with scope/authorization guardrails and 'do not encrypt real data' markers, but the destructive ransomware workflow has no explicit validate-then-proceed checkpoints, which caps destructive-workflow clarity at 2 per the rubric.

2 / 3

Progressive Disclosure

The skill is a single monolithic SKILL.md with no references/, scripts/, or assets/ bundle present, and content that could be split (campaign history, full TTP catalog, tool inventory) is inline, so there is structure but no one-level-deep file split.

2 / 3

Total

8

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is clearly scoped to a specific adversary and unlikely to trigger for the wrong skill, but it reads as a one-line tagline: it states the domain without listing concrete actions and lacks an explicit 'Use when' trigger clause.

Suggestions

Append an explicit trigger clause to the description, e.g. 'Use when emulating FIN7/Carbanak TTPs or building detections for this actor.'

List a few concrete actions in the description (e.g. 'map FIN7 TTPs to Decepticon tooling, stand up phishing/BadUSB delivery, reproduce POWERTRASH-style loading') to lift specificity to 3.

Fold a couple of the most natural user phrases (actor names, 'ransomware affiliate emulation') into the description itself instead of relying solely on metadata.when_to_use.

DimensionReasoningScore

Specificity

Names the domain ('adversary-emulation profile') and a couple of actions ('mapping its TTPs to Decepticon tooling', 'red-team emulation') but does not enumerate multiple specific concrete actions, so it is not a comprehensive 3.

2 / 3

Completeness

It answers 'what' (a TTP-to-tooling emulation profile) but only implies 'when'; with no explicit 'Use when...' clause, completeness is capped at 2 per the judging guideline.

2 / 3

Trigger Term Quality

The description contains the actor aliases and 'financially motivated... red-team emulation', but the rich natural trigger terms ('emulate this actor', 'build detections for it') live in metadata.when_to_use rather than the description, so common variations a user would say are missing.

2 / 3

Distinctiveness Conflict Risk

Pinning a specific threat-actor cluster (FIN7/Carbanak/G0046) to Decepticon tooling gives it a clear niche with distinct triggers unlikely to conflict with other skills.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.