CtrlK
BlogDocsLog inGet started
Tessl Logo

muddywater-mango-sandstorm

Adversary-emulation profile for MuddyWater (G0069 / Mercury / Mango Sandstorm / Static Kitten / TEMP.Zagros / Seedworm), Iran's MOIS cyber-espionage actor.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/muddywater/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill delivers highly actionable, concrete emulation and detection guidance grounded in well-sourced threat intelligence. Its weaknesses are length and structure: a monolithic ~270-line body with no bundle offloading, and tactic-organized rather than sequenced guidance lacking validation checkpoints.

Suggestions

Split the campaign timeline, signature-tooling table, and full TTP-by-tactic catalog into one-level-deep reference files (e.g. references/campaigns.md, references/tooling.md, references/ttps.md) and keep SKILL.md as a concise overview with signaled links.

Reframe the emulation guidance as an ordered workflow (initial access → persistence → credential access → C2 → exfiltration) with explicit validation/verification checkpoints, especially around any destructive or batch actions.

Add a concise executive summary at the top so the core emulation playbook is skimmable without loading the full reference material.

DimensionReasoningScore

Conciseness

The body is dense, non-redundant threat intelligence Claude would not reliably know rather than concept padding, but at ~270 lines of encyclopedic campaign timeline, full TTP catalog, and tooling table it is verbose for an inline SKILL.md and could be tightened or offloaded.

2 / 3

Actionability

The emulation-guidance section maps each signature play to concrete, executable actions (craft macro docs, run Sliver over HTTPS, Rclone to Wasabi, Mimikatz DCSync, specific Run-key and proxy-execution binaries), and the detection section gives equally specific monitoring rules.

3 / 3

Workflow Clarity

Content is organized by ATT&CK tactic rather than as a sequenced execution workflow, and there are no validation/verification checkpoints or feedback loops for the destructive/batch operations the guidance describes, which caps workflow clarity at 2.

2 / 3

Progressive Disclosure

Section headings provide reasonable structure, but with no bundle files present the entire TTP catalog, tooling table, campaign timeline, and sources list live inline in a monolithic SKILL.md instead of being split into one-level-deep reference files.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific to a named threat actor with rich alias coverage, giving strong trigger-term quality and distinctiveness. Its main weakness is the absence of an explicit 'when to use' trigger clause, which caps completeness, and it describes the subject rather than enumerating concrete skill actions.

Suggestions

Append an explicit trigger clause, e.g. 'Use when emulating MuddyWater/Mercury/Mango Sandstorm TTPs or generating detection coverage for Iranian MOIS espionage activity.'

Add concrete actions the skill performs (e.g. 'maps TTPs to emulation plays, lists signature tooling, and gives detection guidance') to lift specificity above a subject description.

DimensionReasoningScore

Specificity

The description names the domain ("Adversary-emulation profile") and the specific actor with aliases, but it states the subject rather than listing concrete actions the skill performs, matching the 'names domain and some actions, but not comprehensive' anchor.

2 / 3

Completeness

It clearly answers 'what' (an adversary-emulation profile for MuddyWater) but lacks an explicit 'Use when...' trigger clause, which per the guidelines caps completeness at 2.

2 / 3

Trigger Term Quality

It packs in the natural terms a user would actually say — MuddyWater, G0069, Mercury, Mango Sandstorm, Static Kitten, Seedworm, TEMP.Zagros, Iran's MOIS — giving strong coverage of alias variations.

3 / 3

Distinctiveness Conflict Risk

The MuddyWater-specific aliases and MOIS attribution form a clear niche with distinct triggers unlikely to fire for an unrelated skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.