CtrlK
BlogDocsLog inGet started
Tessl Logo

kill-chain-analysis

Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/decepticon/kill-chain-analysis/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is lean, well-structured, and highly actionable as a decision-support skill, with a clear decision framework and a thorough blocked-objective tree. Its main limitation is the absence of explicit validation checkpoints and a few abstract decision points that could be made more concrete.

Suggestions

Add concrete thresholds or decision criteria to abstract branches (e.g. quantify 'high probability' or specify when to escalate from 'retry' to 'mark permanently BLOCKED').

Consider moving the large MITRE ATT&CK mapping and common-pivots tables into a references file to keep SKILL.md a tighter overview while preserving the decision framework inline.

Introduce an explicit validation/review checkpoint after vector selection (e.g. 'confirm selected vector is in scope and OPPLAN-aligned before delegating') to strengthen workflow clarity.

DimensionReasoningScore

Conciseness

The body is dense and efficient — decision frameworks, ranked tables, a scoring formula, and a decision tree — with no padding or re-explanation of concepts Claude already knows; every section earns its place.

5 / 5

Actionability

Provides concrete decision rules (a ranking formula, prioritized vector lists, named pivot alternatives like SSTI and nanodump), but some decision points remain abstract ('retry with evasion') without specific thresholds or commands.

4 / 5

Workflow Clarity

Decision processes are clearly sequenced (OPPLAN → findings → risk/reward → OPSEC, plus a well-branched blocked-objective decision tree), but there are no explicit validation/checkpoint steps since the skill is advisory rather than destructive.

4 / 5

Progressive Disclosure

No bundle files exist and the body is self-contained with clear section headers and easy navigation; some reference-style tables (MITRE mapping, common pivots) are inlined rather than split out, which is a minor organization gap.

4 / 5

Total

17

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and reasonably distinct, naming several concrete decision-support activities, but it omits an explicit 'when to use' trigger clause, which caps its completeness. Trigger terms are present in metadata rather than in the description itself.

Suggestions

Add an explicit 'Use when...' clause to the description with natural trigger phrases such as 'when deciding the next attack step, selecting an attack vector, or prioritizing targets'.

Surface a few natural trigger phrases (e.g. 'which technique next', 'blocked — what now', 'next attack step') directly in the description rather than only in metadata.when_to_use.

Include common synonyms or concrete artifacts (e.g. 'attack path', 'OPPLAN', 'phase transition') to broaden natural keyword coverage.

DimensionReasoningScore

Specificity

Names several concrete analytical actions ('findings analysis', 'attack vector selection', 'target prioritization', 'phase transitions') rather than vague language, with only minor coverage gaps.

4 / 5

Completeness

Clearly states what the skill does but provides no explicit 'Use when...' clause; per the guidelines a missing when-clause caps completeness at 3.

3 / 5

Trigger Term Quality

Includes relevant domain terms ('kill chain', 'attack path', 'attack vector') but the description itself lacks natural 'when-to-use' phrasing, synonyms, and the trigger terms that live in metadata.when_to_use.

3 / 5

Distinctiveness Conflict Risk

'Kill chain analysis and attack path decision-making' carves a fairly distinct niche with minimal overlap risk against unrelated skills, though it sits near other offensive-security decision skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.