CtrlK
BlogDocsLog inGet started
Tessl Logo

phishing-overview

Phishing / social-engineering catalog for the Phisher agent. Use ONLY when the engagement RoE authorizes a phishing engagement. Covers pretext design, GoPhish campaigns, evilginx2 MFA-bypass proxying, O365 credential/token harvest, lookalike domains, and the mandatory blue-team deconfliction handshake.

69

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, efficient catalog that delegates detail to sub-skills and includes a concrete failsafe, but its main workflow is presented as a table rather than a sequenced, validated process.

Suggestions

Replace the Playbooks table with a short numbered end-to-end sequence (pretext -> domain/infra -> deconfliction gate -> campaign launch -> harvest -> failsafe) so the workflow order is explicit.

Add an explicit validation checkpoint after the deconfliction gate (e.g., 'Confirm blue-team ack received before proceeding to send') to give the batch send a clear feedback loop.

Trim the gating/legal preamble and clarify the bare "Soundwave's phishing template" reference (link it or drop it) to tighten token efficiency.

DimensionReasoningScore

Conciseness

Mostly lean and efficient — the infrastructure diagram and failsafe earn their tokens without re-explaining what phishing or GoPhish is — but the gating/legal preamble and the opaque "Soundwave's phishing template" reference add minor slack. Not a 5 because a couple of lines could be trimmed.

4 / 5

Actionability

Gives concrete specifics — an NGiNX routing diagram, the engagement header `X-Decepticon-Eng: <slug>`, a 502/5-minute failsafe, named tools (acme.sh, Let's Encrypt) — but as a catalog it points to sub-skills rather than providing copy-paste commands, so it sits just below fully executable.

4 / 5

Workflow Clarity

A hard gate (deconfliction before first send) and an ordered failsafe give a rough sequence, but the main flow is delivered via a playbook table rather than an explicit step sequence, and there are no validation/retry checkpoints beyond the single gate.

3 / 5

Progressive Disclosure

A clear overview structured into labeled sections (Playbooks, Infrastructure, Deconfliction, Failsafe) that points to six one-level-deep sub-skill files via a clean table, with no nested references and easy navigation.

5 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and explicitly states both what it covers and when to use it under a tight authorization gate. It is a strong, low-conflict activation description.

DimensionReasoningScore

Specificity

Enumerates multiple concrete capabilities — "pretext design, GoPhish campaigns, evilginx2 MFA-bypass proxying, O365 credential/token harvest, lookalike domains" — giving comprehensive coverage of the phishing workflow rather than vague abstractions.

5 / 5

Completeness

Explicitly answers both what ("Covers pretext design, GoPhish campaigns...") and when ("Use ONLY when the engagement RoE authorizes a phishing engagement"), with a concrete trigger clause.

5 / 5

Trigger Term Quality

Natural user-facing keywords are comprehensive with synonyms — "phishing, social engineering, gophish, evilginx2, mfa bypass, lure, pretext, o365 oauth, lookalike domain, deconfliction" — matching the breadth a user would actually say.

5 / 5

Distinctiveness Conflict Risk

A sharply scoped niche (authorized phishing engagements under RoE) with distinctive triggers makes triggering for an unrelated skill very unlikely.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.