CtrlK
BlogDocsLog inGet started
Tessl Logo

patchwork-dropping-elephant

Adversary-emulation profile for Patchwork (G0040 / Dropping Elephant / Chinastrats / MONSOON / Hangover Group / Operation Hangover), an India-linked cyber-espionage actor.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/patchwork/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers concrete, actionable emulation and detection guidance grounded in specific CVEs and tradecraft, but it is verbose with background narrative, lacks validation checkpoints in its kill-chain workflow, and is monolithic with no progressive disclosure.

Suggestions

Condense the attribution, targeting, and campaign-narrative sections to only what drives emulation decisions, trimming the threat-intel-report prose to improve token efficiency.

Add explicit validation checkpoints to the emulation workflow (e.g., verify the document exploit fires, confirm the C2 beacon before exfiltrating) to add the missing feedback loops.

Split the detailed TTP catalog, campaign history, and detection guidance into reference files (e.g., TTPS.md, CAMPAIGNS.md, DETECTION.md) with a concise overview in SKILL.md for proper progressive disclosure.

DimensionReasoningScore

Conciseness

The body is well-organized and accurate, but the lengthy attribution rationale, vendor-consensus lists, and dated campaign-by-campaign narratives read like a threat-intel report and could be condensed without losing emulation value, fitting the 'mostly efficient but could be tightened' anchor.

2 / 3

Actionability

The emulation and detection guidance is concrete and specific — exact CVEs (CVE-2017-11882, CVE-2017-0199), command patterns (`powershell -ExecutionPolicy Bypass -WindowStyle Hidden`), file paths, masquerade names, and target extension lists — which is actionable for an instruction-only profile skill per the scoring notes.

3 / 3

Workflow Clarity

The emulation plays are ordered across the kill chain (initial access → execution → C2 → collection → exfiltration), giving a clear sequence, but there are no explicit validation checkpoints or feedback loops (e.g., verify exploit fires, confirm C2 beacon) for destructive/batch-style operations, capping the score at 2.

2 / 3

Progressive Disclosure

The single ~180-line SKILL.md is monolithic with no bundle files or external references; sections are well-organized, but the detailed TTP catalog, campaign history, and detection guidance are inline content that could be split into reference files for a document this large.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly specific about its subject and rich in natural trigger aliases, but it omits any "Use when..." usage trigger and does not enumerate concrete actions, leaving completeness and specificity at the mid anchor.

Suggestions

Add an explicit 'Use when...' clause to the description (e.g., 'Use when emulating Patchwork/Dropping Elephant TTPs or India-linked South Asian espionage campaigns') so Claude knows when to invoke it.

List one or two concrete capabilities (e.g., 'maps Patchwork TTPs to kill-chain emulation plays') to move specificity beyond merely naming the domain.

DimensionReasoningScore

Specificity

The description names the domain clearly ("Adversary-emulation profile for Patchwork ... an India-linked cyber-espionage actor") but lists no concrete actions or verbs — "profile for" is a noun phrase, not a capability, so it does not reach the multi-action anchor of 3.

2 / 3

Completeness

It answers "what" (an adversary-emulation profile for this actor) but has no "Use when..." clause or equivalent explicit trigger guidance in the description field, capping completeness at 2 per the rubric guidelines.

2 / 3

Trigger Term Quality

It packs the natural alias keywords a threat-intel/emulation user would actually say — "Patchwork", "Dropping Elephant", "Chinastrats", "MONSOON", "Hangover Group", "G0040", "India-linked cyber-espionage" — giving strong coverage of likely trigger terms.

3 / 3

Distinctiveness Conflict Risk

Naming a specific tracked threat actor with multiple unique aliases carves out a clear niche unlikely to conflict with other skills, matching the "clear niche with distinct triggers" anchor.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.