CtrlK
BlogDocsLog inGet started
Tessl Logo

fin7

FIN7 (Carbon Spider / Sangria Tempest) adversary-emulation playbook — revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware. Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware. Triggers on: 'emulate FIN7', 'Carbanak', 'Carbon Spider', 'Sangria Tempest', 'big game hunting', 'EDR evasion', 'AvNeutralizer'.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary orchestration-style skill body: dense, operational, and safe. The kill chain is explicitly sequenced with concrete sub-skill routing, the destructive operations are fenced with explicit authorization, rollback, canary-only, and abort gates, and the only weakness is minor — unverifiable external reference paths and slightly cramped table cells.

DimensionReasoningScore

Conciseness

The ~90-line body is lean and operational: a copy-paste ThreatProfile seed, a compact phase table, a CONOPS list, and terse safety gates. It assumes Claude's competence (no explanation of MITRE, DCSync, or Kerberoast) and every section carries engagement-specific value — anchor 5, not 4, since nothing trimmable stands out.

5 / 5

Actionability

Guidance is fully concrete: a copy-paste-ready 'plan/threat-profile.json' JSON block, an explicit 'copy into conops.json' list, per-phase executing-agent and skill routing with specific paths, and named artifacts (deconfliction.json, cleanup.json). As an instruction-only skill its guidance is executable throughout — anchor 5.

5 / 5

Workflow Clarity

The kill chain is a numbered 11-phase table with MITRE mappings plus a grouped CONOPS sequence, and the destructive operations (EDR tampering, ransomware impact) have explicit validation gates: authorization, lure-deconfliction, lab/canary host first, 'confirm rollback', canary-only impact, an EMERGENCY abort criterion, and a deconfliction checklist. Validation is present (no cap at 3) and the gates plus abort loop match anchor 5; it exceeds anchor 4 because checkpoints are explicit rather than implicit.

5 / 5

Progressive Disclosure

The body is a well-sectioned overview that routes detail outward: '../../references/apt-groups.md' is clearly signaled and one level deep, and each phase names its executing skill. However the skill ships no bundle of its own, so the referenced paths cannot be verified, and a few table cells cram two skill paths into one cell — good structure with minor organization gaps, anchor 4 rather than 5.

4 / 5

Total

19

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly and explicitly states both what the skill does and when to use it, with concrete trigger phrases and actor synonyms. The main weaknesses are minor: jargon-y trigger terms, a 'Carbanak' conflation, and a couple of broad triggers that slightly raise conflict risk.

Suggestions

Replace the 'Carbanak' trigger with a FIN7-accurate alias (e.g. 'GOLD NIAGARA' or 'Sangria Tempest', both already present) since Carbanak is generally tracked as a separate group and could route to the wrong skill.

Add one or two plainer natural-language triggers such as 'ransomware emulation' or 'FIN7 emulation' alongside the tool-name jargon like 'AvNeutralizer' to broaden natural-match coverage.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — 'revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware' — giving comprehensive coverage of the playbook's scope in third-person voice. It goes beyond anchor 4's 'several specific actions with minor gaps' by covering the full kill chain.

5 / 5

Completeness

It explicitly answers both what ('adversary-emulation playbook — revenue-targeted spearphishing... ransomware') and when ('Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware'), and adds a concrete 'Triggers on:' phrase list. This matches the anchor-5 example structure exactly.

5 / 5

Trigger Term Quality

Trigger terms include natural user phrases and actor synonyms ('emulate FIN7', 'Carbon Spider', 'Sangria Tempest', 'big game hunting'), but 'AvNeutralizer' is deep tool jargon, 'Carbanak' conflates a distinct group, and plainer variations like 'ransomware emulation' or 'FIN7 emulation' are absent. Good coverage with a few natural terms missing — anchor 4, not 5.

4 / 5

Distinctiveness Conflict Risk

The FIN7/Carbon Spider niche is clearly distinct, but the trigger terms 'EDR evasion', 'big game hunting', and especially 'Carbanak' could pull in other EDR-testing, ransomware-emulation, or Carbanak-specific skills. Mostly distinct with minor overlap risk against closely related skills — anchor 4.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.