CtrlK
BlogDocsLog inGet started
Tessl Logo

lazarus

Lazarus Group (Hidden Cobra, DPRK RGB) adversary-emulation playbook — financially-motivated crypto/DeFi theft and supply-chain intrusion: fake-job social engineering, trojanized apps, wallet/key theft, and on-chain DeFi/bridge exploitation (testnet/fork only). Use when emulating DPRK financial actors against a crypto/exchange/DeFi target. Triggers on: 'emulate Lazarus', 'Hidden Cobra', 'DPRK crypto', 'AppleJeus', '3CX supply chain', 'DeFi bridge attack', 'crypto theft'.

76

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, well-structured adversary-emulation playbook that is fully actionable as an orchestrator: complete threat-profile seed, unambiguous kill-chain routing with MITRE mapping, and unusually strong safety/RoE gates with verbatim abort criteria. The only notable gap is the absence of an explicit pre-flight verification checkpoint for the destructive on-chain phases, leaving workflow clarity just short of the top anchor.

Suggestions

Add an explicit pre-flight validation step to the kill-chain or CONOPS: e.g. 'Before phases 7–9, verify the configured RPC URL is the testnet/Anvil fork endpoint recorded in deconfliction.json — abort if it resolves to a mainnet RPC.'

Turn the RoE safety gates into a short copy-paste checklist (fork RPC verified → canary wallets funded → persona marked → lure deconflicted) so the gates function as sequenced checkpoints rather than prose rules.

In the CONOPS kill_chain, annotate steps 3–4 (on-chain phases) with their testnet/fork precondition inline, so the constraint is visible at the point of execution rather than only in the RoE section.

DimensionReasoningScore

Conciseness

The ~93-line body packs threat-profile seed, an 11-phase kill-chain routing table, CONOPS, OPSEC, RoE gates, deconfliction, and fidelity notes with zero filler — it never explains concepts Claude already knows (what a DLL side-load or a DeFi bridge is) and assumes competence throughout. Every section maps to a concrete planning artifact, matching the level-5 anchor ('lean and efficient; every token earns its place'); level 4 would require trimmable over-explanation, and none is evident.

5 / 5

Actionability

Guidance is copy-paste ready: the complete `plan/threat-profile.json` seed JSON, exact routing paths per phase (e.g. `/skills/standard/contracts/bridge-exploit/SKILL.md`), a numbered CONOPS to copy into `conops.json`, and verbatim EMERGENCY-abort language. Per the rubric's instruction-only-skill note, absence of code is not penalized when guidance is actionable — and this is fully actionable with specific named artifacts (`deconfliction.json`, `cleanup.json`). It exceeds level 4 ('minor gaps'): execution detail is deliberately and correctly delegated to the routed sub-skills.

5 / 5

Workflow Clarity

The 11-phase sequence is clearly numbered, mapped to MITRE techniques and CONOPS stages, and includes explicit safety checkpoints (MUST-run-on-fork rule, verbatim `EMERGENCY` abort criterion, lure deconfliction requirement). However, for inherently destructive on-chain operations (phases 7–11) there is no explicit pre-flight validation step in the sequence itself — e.g. 'verify the RPC endpoint is an Anvil fork/testnet before executing phases 7–9' — so the level-5 anchor's 'explicit validation steps' is not fully met; this fits level 4 ('clear sequence with most checkpoints present; minor validation gaps') better than level 5.

4 / 5

Progressive Disclosure

The SKILL.md is itself an overview that routes all execution detail to one-level-deep, clearly signaled sub-skill paths (dedicated routing column in the kill-chain table, plus inline links like `(see ../../references/apt-groups.md)` and the lure-deconfliction path in RoE). No content that belongs in a separate file is inlined; the structure matches the level-5 anchor (clear overview with well-signaled one-level-deep references, easy navigation), which is why it sits above level 4 rather than merely at it.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary skill description: third-person, dense without padding, and it answers both 'what' and 'when' with concrete, naturally-voiced trigger phrases and actor-specific synonyms. Safety-relevant scope constraint ('testnet/fork only') is stated inline, which is a plus for this domain.

DimensionReasoningScore

Specificity

The description names the domain ("adversary-emulation playbook") and lists multiple concrete action classes — "fake-job social engineering, trojanized apps, wallet/key theft, and on-chain DeFi/bridge exploitation" plus "supply-chain intrusion" — comprehensively covering the actor's TTP surface. It clearly matches the level-5 anchor (multiple specific concrete actions, comprehensive coverage) and exceeds level 4, which anticipates gaps in coverage; none are apparent.

5 / 5

Completeness

Both questions are explicitly answered: what ("Lazarus Group ... adversary-emulation playbook — financially-motivated crypto/DeFi theft and supply-chain intrusion: ...") and when ("Use when emulating DPRK financial actors against a crypto/exchange/DeFi target. Triggers on: ..."). This matches the level-5 anchor — clear 'what' and 'when' with concrete trigger phrases — and is well above level 4's 'when could be more explicit'.

5 / 5

Trigger Term Quality

Explicit trigger phrases cover the natural vocabulary of this niche with synonyms: "'emulate Lazarus', 'Hidden Cobra', 'DPRK crypto', 'AppleJeus', '3CX supply chain', 'DeFi bridge attack', 'crypto theft'", reinforced by in-body phrases like "fake-job social engineering" and "wallet/key theft". Coverage is comprehensive for the domain (a user emulating this actor would naturally say these terms), fitting the level-5 anchor; level 4 ('a few natural terms missing') would understate it — even variations like ZINC/Diamond Sleet appear in the frontmatter's when_to_use metadata.

5 / 5

Distinctiveness Conflict Risk

A named-threat-actor (Lazarus/Hidden Cobra, G0032) emulation niche with operation-specific triggers ('AppleJeus', '3CX supply chain') is unambiguous and would not fire for unrelated skills; the only conceivable overlap is with sibling DPRK actor-emulation skills, which the actor-specific triggers disambiguate. Fits the level-5 anchor (clear niche, distinct triggers, minimal conflict risk).

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.