CtrlK
BlogDocsLog inGet started
Tessl Logo

lazarus-group

Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/lazarus-group/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, well-structured threat-intel and emulation profile with concrete tool mappings and detection guidance, but it is prose-heavy and encyclopedic rather than lean, lacks executable code and validation checkpoints, and keeps all content inline.

Suggestions

Add executable commands or a concrete runbook (e.g., the exact Sliver listener/redirector setup and the marked-impact-file commands) instead of prose-only tool references to lift actionability.

Insert explicit validation/safety checkpoints in the emulation workflow — confirm scope, verify the impact marker is reversible, and confirm detections fired — especially around the destructive-operation steps.

Split the encyclopedic campaign and tooling reference into a separate references file so SKILL.md stays a lean overview that points one level deep.

DimensionReasoningScore

Conciseness

The body is well-organized but dense; the intro and campaign entries restate widely known background (Sony, WannaCry, Bangladesh Bank) that Claude largely already knows, so it could be tightened despite being a threat-intel reference.

2 / 3

Actionability

The 'Emulation guidance (Decepticon)' section maps TTPs to specific tools/skills (Sliver, defense-evasion, Responder) and the detection section names concrete indicators, but the guidance is prose with no executable code or copy-paste commands.

2 / 3

Workflow Clarity

The emulation chain is sequenced (initial access -> C2 -> execution/persistence -> evasion -> credentials -> discovery -> exfil -> impact), but destructive operations lack explicit validate/verify/retry checkpoints, capping this dimension at 2 per the rubric.

2 / 3

Progressive Disclosure

Everything is inline in one monolithic document with clear sections but no bundle files and no one-level-deep references, so content that could live in separate reference files is not split out.

2 / 3

Total

8

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a distinct, well-named niche with strong natural trigger aliases, but it describes the actor rather than the skill's concrete actions and omits any explicit 'when to use' guidance.

Suggestions

Add an explicit 'Use when...' clause naming emulation triggers (e.g., 'Use when emulating North Korean APT activity or when the user mentions Lazarus, Hidden Cobra, WannaCry, TraderTraitor, or DPRK-linked intrusions.') to satisfy the completeness 'when' requirement.

State the concrete actions the skill performs (e.g., 'maps Lazarus signature TTPs to emulation capabilities and produces detection guidance') instead of only characterizing the actor's mission types.

Fold a few high-signal campaign keywords (WannaCry, Operation Dream Job, 3CX, FASTCash) into the description so the trigger terms cover the campaign-level phrasings users actually say.

DimensionReasoningScore

Specificity

It names the domain ('Adversary-emulation profile') and the actor's three mission types ('espionage, destructive, and financially motivated operations'), but states no concrete actions the skill itself performs (e.g., map TTPs to emulation steps, generate detection content).

2 / 3

Completeness

It answers 'what' (an adversary-emulation profile for this actor) but contains no 'Use when...' clause or equivalent explicit trigger guidance, which the rubric caps at 2.

2 / 3

Trigger Term Quality

It surfaces the natural aliases a user would actually say — 'Lazarus Group', 'Hidden Cobra', 'Diamond Sleet', 'Labyrinth Chollima', 'G0032' — giving good coverage of the primary terms that would surface this skill.

3 / 3

Distinctiveness Conflict Risk

Naming Lazarus Group with multiple aliases plus MITRE G0032 carves out a clear, narrow niche that is very unlikely to trigger the wrong skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.