CtrlK
BlogDocsLog inGet started
Tessl Logo

lateral-movement

Network lateral movement — Pass-the-Hash, Pass-the-Ticket, WMI/WinRM/PsExec/RDP execution, SMB operations, network tunneling with Ligolo-ng and Chisel.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/post-exploit/lateral-movement/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands and clear comparison tables, but it operates on destructive/batch operations without validation checkpoints, capping workflow clarity, and it is a monolithic inlined knowledge base rather than a progressive-disclosure overview pointing to bundle files.

Suggestions

Add explicit validation/verification checkpoints after risky steps (e.g., confirm 4624 Type-3 logon succeeded, verify PsExec service was deleted, confirm tunnel route resolves) to lift workflow clarity above the cap.

Split per-technique detail into bundle files under references/ (e.g., pth.md, kerberos.md, tunneling.md) and keep SKILL.md as a concise overview with one-level-deep links.

Trim the Quick Reference block that duplicates sections 1-5, or replace it with a single pointer table to reduce token redundancy.

DimensionReasoningScore

Conciseness

The body is a dense, mostly lean reference with terse code blocks and a single tight intro paragraph; the main redundancy is the Quick Reference duplicating commands elaborated in sections 1-5, placing it at the score-4 (efficient, minor trimmable instances) anchor rather than 5.

4 / 5

Actionability

Quotes fully executable commands across all sections (nxc, psexec.py, wmiexec.py, Rubeus, Mimikatz, Ligolo-ng, Chisel) with real flags and placeholders that are copy-paste ready and cover the common cases, matching the score-5 anchor.

5 / 5

Workflow Clarity

Operations are destructive/batch (remote code execution, hash spraying, NTDS dumping) yet no validation checkpoints are provided — only a post-success Decision Gate — so per the rubric's feedback-loop cap workflow clarity cannot exceed 3.

3 / 5

Progressive Disclosure

No bundle files exist (references/scripts/assets absent) and the ~460-line skill is a single inlined knowledge base; section headers and comparison tables give some structure, but content that could live in separate reference files is inlined, fitting the score-3 anchor.

3 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-targeted to a clear offensive-security niche with strong trigger terms, but it lacks an explicit "Use when..." clause inside the description field, capping completeness. Adding a trigger-guidance sentence would raise it to a 5-level description.

Suggestions

Append an explicit "Use when..." trigger clause to the description field, e.g. "Use when performing lateral movement, pass-the-hash/ticket, remote execution, or network pivoting."

Include a few more synonyms in the description (e.g. "PTH", "kerberos tickets", "reverse tunnel") to round out trigger-term coverage.

DimensionReasoningScore

Specificity

Quotes "Pass-the-Hash, Pass-the-Ticket, WMI/WinRM/PsExec/RDP execution, SMB operations, network tunneling with Ligolo-ng and Chisel" — multiple named concrete actions and tools with comprehensive coverage, matching the score-5 anchor.

5 / 5

Completeness

The description field clearly states what ("Network lateral movement — ...") but contains no "Use when..." trigger clause; per the judging guidelines a missing explicit when-guidance caps completeness at 3, and the when_to_use lives only in metadata rather than the description itself.

3 / 5

Trigger Term Quality

Quotes "lateral movement, pass the hash, pass the ticket, WMI exec, evil-winrm, psexec, pivot, tunnel, Ligolo, Chisel, smbexec" — strong natural attacker-term and tool-name coverage with a few synonyms missing, fitting the score-4 anchor rather than 5.

4 / 5

Distinctiveness Conflict Risk

Quotes the clearly bounded niche "Network lateral movement — Pass-the-Hash... network tunneling with Ligolo-ng and Chisel," which has distinct triggers and minimal overlap risk with other skills, matching the score-5 anchor.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.