CtrlK
BlogDocsLog inGet started
Tessl Logo

pink-sandstorm-agrius

Adversary-emulation profile for Pink Sandstorm (G1030 / Agrius / Agonizing Serpens / AMERICIUM / BlackShadow / DEV-0227), Iran's MOIS-linked destructive wiper and pseudo-ransomware operator.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/pink-sandstorm/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized and highly actionable in its emulation guidance, but it is a monolithic document with no progressive disclosure and lacks validation checkpoints around its destructive-operation workflow.

Suggestions

Add explicit validation/verification checkpoints to the wiper and destructive-operation workflow (e.g., confirm isolation/scope before each destructive step, verify lab containment) to lift workflow clarity above 2.

Move the detailed campaign narratives, the full ATT&CK TTP catalog, and the signature-tooling table into separate reference files (e.g., CAMPAIGNS.md, TTPS.md, TOOLING.md) referenced one level deep from SKILL.md to improve progressive disclosure.

Trim the background-heavy attribution/targeting/campaign prose to only what is needed to inform emulation, reducing token cost.

DimensionReasoningScore

Conciseness

The actionable core (TTPs, tooling table, emulation guidance) is efficient, but lengthy 'Attribution & motivation', 'Targeting', and 'Notable campaigns' narrative sections repeat threat-intel background that could be trimmed; it is mostly efficient with some padding.

2 / 3

Actionability

The 'Emulation guidance (Decepticon)' section gives concrete, specific direction — exact tools (ASPXSpy variant, Plink renamed 'systems.exe', Mimikatz), exact staging paths ('C:\windows\temp\s\'), ATT&CK IDs, and a numbered 5-step wiper chain — which is actionable guidance for an instruction-only skill.

3 / 3

Workflow Clarity

The emulation phases are sequenced (initial access → impact → hack-and-leak) with a numbered wiper chain, but there are no explicit validation/verification checkpoints or fix-retry feedback loops; per the rubric, destructive operations without validation cap workflow clarity at 2.

2 / 3

Progressive Disclosure

Content is organized into clear sections, but it is a single monolithic ~170-line SKILL.md with no references/, scripts/, or assets/ files; detailed campaign histories, the full TTP catalog, and the tooling table are inline content that could be split into one-level-deep reference files.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and rich in natural trigger aliases, but it lacks an explicit 'Use when' clause and does not enumerate the skill's concrete actions, capping completeness and specificity.

Suggestions

Add an explicit 'Use when...' clause, e.g., 'Use when emulating Pink Sandstorm / Agrius destructive-wiper or pseudo-ransomware operations in an authorized engagement.'

Name the concrete actions the skill performs (e.g., 'maps ATT&CK TTPs, lists signature tooling, and generates Decepticon emulation guidance') to raise specificity from 2 to 3.

DimensionReasoningScore

Specificity

Names the domain ('Adversary-emulation profile') and the subject's operations ('destructive wiper and pseudo-ransomware operator') but does not list the concrete actions the skill itself performs (e.g., map TTPs, generate emulation plans), so it stops short of the multi-action anchor.

2 / 3

Completeness

The 'what' is clear (an adversary-emulation profile for a named actor), but there is no explicit 'Use when...' trigger clause in the description; per the rubric a missing explicit trigger caps completeness at 2.

2 / 3

Trigger Term Quality

Quotes a strong cluster of natural aliases a threat-intel or red-team user would actually say — 'Pink Sandstorm', 'G1030', 'Agrius', 'Agonizing Serpens', 'AMERICIUM', 'BlackShadow', 'DEV-0227' — plus 'MOIS-linked destructive wiper and pseudo-ransomware operator'.

3 / 3

Distinctiveness Conflict Risk

It targets a highly specific named threat actor with distinctive aliases, making it unlikely to trigger for an unrelated skill; the niche is clearly delineated.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.