CtrlK
BlogDocsLog inGet started
Tessl Logo

kimsuky-velvet-chollima

Adversary-emulation profile for Kimsuky (G0094 / Velvet Chollima / Emerald Sleet / THALLIUM / Black Banshee / APT43 / TA427), North Korea's RGB 63rd Research Center cyber-espionage actor.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/kimsuky/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a rich, actionable adversary-emulation reference with concrete TTP/tool mappings and specific detection guidance, but it is monolithic and relies on an implicit rather than explicit, checkpointed workflow. Splitting bulk reference material into bundled files and tightening the overlapping intro/campaigns prose would improve the lower dimensions.

Suggestions

Move the exhaustive TTP-by-tactic enumeration, the malware/tooling table, and the source URL list into separate reference files (e.g., TTPS.md, TOOLING.md, SOURCES.md) linked from a concise overview, improving progressive disclosure.

Reframe the 'Emulation guidance' bullets as a numbered, phase-sequenced runbook with explicit validation checkpoints (e.g., verify payload executes and beacons before moving to persistence) to lift workflow clarity.

Trim the introductory paragraph and 'Notable campaigns' narratives to avoid restating attribution and targeting already detailed in dedicated sections.

DimensionReasoningScore

Conciseness

The body is dense and specific with no basic-concept fluff, but the intro paragraph (line 14) and the 'Notable campaigns' narratives restate material expanded in later sections and could be tightened.

2 / 3

Actionability

The 'Emulation guidance' section gives concrete, specific instructions with real parameters (lookalike Google/Naver/Kakao pages, GetAsyncKeyState at 50ms, 10-minute exfil intervals, specific staging paths and scheduled-task names), and the detection section lists specific hunt rules, satisfying actionable instruction-only guidance.

3 / 3

Workflow Clarity

The emulation bullets follow an implicit kill-chain order (initial access → persistence → C2 → collection → exfiltration), but there is no explicit numbered runbook and no validation checkpoints between phases.

2 / 3

Progressive Disclosure

The document is well-sectioned with clear headers and easy navigation, but it is a monolithic ~230-line single file with no bundle references, leaving bulk reference material (full TTP enumeration, malware table, 20+ source URLs) inline rather than split out.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly distinctive and rich in natural trigger terms, but it identifies the actor more than it enumerates concrete actions, and it lacks an explicit 'Use when...' trigger clause. Adding a use-when clause and naming a few concrete emulation actions would raise the weaker dimensions.

Suggestions

Add an explicit trigger clause, e.g. 'Use when emulating Kimsuky/APT43 espionage operations or when the user mentions these aliases, G0094, or DPRK credential-phishing campaigns.'

List two or three concrete emulation actions in the description (e.g., 'map Kimsuky TTPs to emulation capabilities, build phishing/clickfix lures, deploy C2 via legitimate services') to lift specificity from 2 to 3.

DimensionReasoningScore

Specificity

The description names a concrete domain ('Adversary-emulation profile') and a specific actor with multiple aliases and origin ('North Korea's RGB 63rd Research Center cyber-espionage actor'), but it does not list multiple specific concrete actions as the score-3 anchor requires.

2 / 3

Completeness

It clearly answers 'what' (an adversary-emulation profile for a named actor), but contains no explicit 'Use when...' clause or equivalent trigger guidance, so completeness is capped at 2 per the judging guidelines.

2 / 3

Trigger Term Quality

It packs the natural aliases a threat-intel user would actually say — 'Kimsuky', 'Velvet Chollima', 'Emerald Sleet', 'THALLIUM', 'Black Banshee', 'APT43', 'TA427', 'G0094' — giving strong coverage of likely trigger terms.

3 / 3

Distinctiveness Conflict Risk

The profile is tightly scoped to one named threat actor with distinct aliases and an ATT&CK group ID, giving it a clear niche unlikely to trigger for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.