CtrlK
BlogDocsLog inGet started
Tessl Logo

opsec

Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/opsec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured OPSEC reference with executable commands, validation checkpoints, and feedback loops, though it carries some conceptual padding and is a long monolithic file that could offload detail to reference files.

Suggestions

Trim the opening motivation paragraph and the 'OPSEC Mindset' list to the concrete, non-obvious guidance that Claude cannot already infer.

Consider moving the larger tables (scan-rate matrix, IDS/WAF signature table) and code blocks into reference files under references/ with one-line pointers, to shorten the SKILL.md overview.

DimensionReasoningScore

Conciseness

The body is mostly lean reference material (tables, flags, commands), but the opening motivation paragraph and the 'OPSEC Mindset' principles restate conceptual justification Claude already understands and could be trimmed.

2 / 3

Actionability

Provides copy-paste-ready, executable commands with specific flags across nmap, ffuf, nuclei, curl, and dig, plus concrete rate tables and a runnable scope-check script; placeholders like <CHROME_VER> are explicitly justified to avoid stale signatures.

3 / 3

Workflow Clarity

Risky batch scanning is gated by an explicit scope-verification checkpoint, and detection response is a clear numbered feedback loop (pause, assess, reduce rate, document) with checklists for pre-engagement and clean-up, matching the anchor for explicit validation and feedback loops.

3 / 3

Progressive Disclosure

The skill is well organized into nine numbered sections with no nested references, but it is a single long monolithic document with no split-out reference files, fitting the anchor where content that could be separate remains inline.

2 / 3

Total

10

/

12

Passed

Description

67%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, third-person description that names concrete capabilities and occupies a clear niche, but it omits an explicit 'Use when...' trigger clause and leans on some technical jargon over natural user phrasing.

Suggestions

Add an explicit 'Use when...' clause naming natural trigger phrases (e.g., stealth, rate limiting, staying undetected, scope checks) so users and Claude know when to invoke it.

Soften technical jargon like 'tool signature avoidance' with natural equivalents users would actually say, while keeping the precise terms.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities directly: 'traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns', matching the anchor for enumerating several specific actions rather than vague language.

3 / 3

Completeness

It clearly states what the skill does, but there is no 'Use when...' clause or equivalent explicit trigger guidance in the description, which per the rubric caps completeness at 2.

2 / 3

Trigger Term Quality

Relevant terms like 'scan rate limiting', 'evidence handling', and 'anti-detection patterns' are present, but several are technical jargon ('traffic shaping', 'tool signature avoidance') and common natural variations a user would say (e.g., 'stealth', 'rate limit', 'stay undetected') are missing.

2 / 3

Distinctiveness Conflict Risk

The operational-security niche is specific and the listed capabilities form a distinct trigger profile unlikely to overlap with unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.