CtrlK
BlogDocsLog inGet started
Tessl Logo

opcua

OPC-UA (TCP 4840) attack playbook — endpoint enumeration, SecurityPolicy mapping, anonymous/weak-auth abuse, address-space browsing and tag read, HistoryRead exfiltration, Method call for control actions, session-exhaustion DoS. Modern IT/OT DMZ convergence protocol replacing legacy fieldbus.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/exploit/ics-ot/opcua/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced attack playbook with strong executable code and clear safety gating, but it is a single monolithic document with no bundled references and limited validation feedback loops on destructive operations.

Suggestions

Add explicit validate/verify checkpoints for destructive and batch phases (e.g., confirm session count and server liveness before and after DoS testing).

Split the large per-phase code blocks into a bundled references/ or scripts/ directory and link to them one level deep to improve progressive disclosure.

DimensionReasoningScore

Conciseness

The body is largely action-oriented code with little concept overexplaining, but includes some optional commentary (intro paragraph, Wireshark aside, OPSEC prose) that could be tightened, matching the score-2 anchor of mostly efficient with some unnecessary explanation.

2 / 3

Actionability

Each phase supplies copy-paste-ready, executable asyncua Python and nmap commands with concrete node IDs and credential lists, matching the score-3 anchor of fully executable, specific examples.

3 / 3

Workflow Clarity

Phases are clearly sequenced with a SAFETY GATE before write-class Method calls, but destructive/batch phases (DoS, Method call) lack explicit validate→fix→retry feedback loops, which the guidelines cap at 2 for risky operations.

2 / 3

Progressive Disclosure

No bundle files exist; the skill is a monolithic SKILL.md with per-phase code inline and only prose external-URL references, fitting the score-2 anchor of some structure but content that could be separate remaining inline.

2 / 3

Total

9

/

12

Passed

Description

67%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-differentiated protocol attack description that clearly conveys capabilities but relies on jargon-heavy trigger terms and omits an explicit 'Use when...' invocation clause.

Suggestions

Add an explicit 'Use when ...' clause naming natural user phrasings (e.g., 'Use when enumerating or abusing OPC-UA servers, browsing OT/SCADA address spaces, or attacking TCP 4840 services').

Soften jargon-heavy triggers by pairing protocol terms with plain-language equivalents users would actually say.

DimensionReasoningScore

Specificity

The description enumerates many concrete actions — 'endpoint enumeration, SecurityPolicy mapping, anonymous/weak-auth abuse, address-space browsing and tag read, HistoryRead exfiltration, Method call for control actions, session-exhaustion DoS' — matching the score-3 anchor of listing multiple specific concrete actions.

3 / 3

Completeness

It strongly answers 'what does this do' but contains no explicit 'Use when...' or equivalent trigger clause in the description, which the guidelines cap at 2.

2 / 3

Trigger Term Quality

Terms are largely technical protocol jargon ('SecurityPolicy mapping', 'HistoryRead exfiltration', 'session-exhaustion DoS') rather than natural phrasings a user would say; some relevant keywords exist but common user variations are missing.

2 / 3

Distinctiveness Conflict Risk

The OPC-UA / ICS-OT, TCP 4840 niche is distinct and the listed capabilities are unlikely to trigger for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.