CtrlK
BlogDocsLog inGet started
Tessl Logo

mustang-panda-bronze-president

Adversary-emulation profile for Mustang Panda (G0129 / Bronze President / Stately Taurus / RedDelta / TA416 / TEMP.Hex), a China-based state-sponsored cyber-espionage actor operating since at least 2012.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/mustang-panda/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, highly actionable adversary-emulation profile with concrete emulation and detection guidance, but it is a monolithic inline document lacking validation checkpoints in its workflows and any reference-file structure. Splitting the campaign/TTP/tooling catalogs into reference files and adding verify steps for destructive operations would improve it.

Suggestions

Move the campaign timeline, full ATT&CK TTP catalog, and tooling table into one-level-deep reference files (e.g. references/campaigns.md, references/ttps.md) and keep SKILL.md as an overview with signaled links.

Add explicit validation/checkpoint steps for destructive or lab-only operations (USB worm, kernel-driver deployment), e.g. verify isolation and scope before executing, and confirm cleanup afterward.

Trim redundant alias repetitions and prose in the body to tighten token use without losing the reference value.

DimensionReasoningScore

Conciseness

The body is dense reference material (campaigns, malware families, ATT&CK mappings) that Claude does not already know, so most tokens earn their place, but the volume is large and could be tightened or offloaded to reference files rather than held inline.

2 / 3

Actionability

The 'Emulation guidance' and 'Detection & defense' sections give concrete, executable guidance — specific technique chains, signed-EXE/DLL/payload triads, registry keys, and commands like `code.exe tunnel`, `rar.exe a -hp`, `vssadmin create shadow` — well beyond abstract description.

3 / 3

Workflow Clarity

Content is logically sequenced by ATT&CK tactic and phase, but there are no explicit validation checkpoints or feedback loops, and the destructive USB-worm / kernel-driver operations only carry an authorized-use caveat rather than verify steps, which caps the score at 2.

2 / 3

Progressive Disclosure

Sections are well-organized, but no references/scripts/assets bundle exists and the entire profile — campaigns, TTP catalog, tooling table, detections — lives inline in one large SKILL.md, so content that should be split across one-level-deep reference files is kept inline.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and rich in natural trigger aliases, but it only implies when to use the skill and frames it as a profile rather than listing concrete actions. Adding an explicit 'Use when...' clause and one or two concrete actions would raise completeness and specificity.

Suggestions

Append an explicit trigger clause, e.g. 'Use when emulating Mustang Panda / Bronze President / Stately Taurus operations or mapping their TTPs to detection coverage.'

Add concrete actions to the description, e.g. 'emulate TTPs, map ATT&CK techniques, and generate detections for Mustang Panda campaigns.'

DimensionReasoningScore

Specificity

It names the domain ('Adversary-emulation profile for Mustang Panda') and the actor with aliases, but describes a profile rather than enumerating multiple concrete actions (e.g. emulate TTPs, generate detections), so it stops at naming the domain.

2 / 3

Completeness

It clearly states what the skill is, but lacks any 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 2 per the judging guidelines.

2 / 3

Trigger Term Quality

It densely packs natural terms a user would say — 'Mustang Panda', 'Bronze President', 'Stately Taurus', 'RedDelta', 'TA416', 'TEMP.Hex', 'G0129' — giving strong coverage of alias variants.

3 / 3

Distinctiveness Conflict Risk

The highly specific actor naming plus MITRE G0129 identifier carves out a clear niche unlikely to trigger for the wrong skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.