CtrlK
BlogDocsLog inGet started
Tessl Logo

rmm-tool-abuse

Legitimate RMM tool abuse — deploy or hijack Atera, ScreenConnect, AnyDesk, TeamViewer for persistence, lateral movement, and C2. Leverages trusted software to evade EDR and blend with IT admin traffic.

58

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/exploit/rmm-tool-abuse/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and mostly token-efficient, with concrete commands throughout. Its weaknesses are the absence of validation checkpoints in destructive/batch workflows (capping workflow clarity at 3) and a monolithic structure with no progressive disclosure via bundle files.

Suggestions

Add explicit validation/verification checkpoints after risky steps (e.g. 'After install: sc query the service and confirm the agent beacons home before proceeding').

Split per-tool deployment details and the detection-signatures table into referenced bundle files (e.g. references/anydesk.md, references/detection.md) and link them one level deep from SKILL.md.

De-duplicate the 'Quick Reference' against section 2 to recover tokens and remove redundancy.

DimensionReasoningScore

Conciseness

Body is dominated by dense, executable code blocks and tables with minimal concept explanation; e.g. 'curl -sLo anydesk.exe' and 'msiexec /i ... /qn'. Not a 5 because the 'Quick Reference' duplicates commands restated in section 2, and the C2 section leans on prose comments that could be trimmed.

4 / 5

Actionability

Provides concrete, largely copy-paste-ready commands across discovery, deployment, hijacking, and lateral movement (e.g. 'reg query HKLM\SOFTWARE\WOW6432Node\TeamViewer /v ClientID', 'msiexec /i AteraAgent.msi /qn ...'). Not a 5 because several procedures (ScreenConnect extension abuse, TeamViewer mass deployment, the C2 patterns in section 5) are described in prose/comments rather than executable commands, leaving minor gaps.

4 / 5

Workflow Clarity

A numbered sequence (Discovery → Deploy → Leverage → Lateral → C2) plus a 'Decision Gate' gives rough ordering, but there are no validation/verification checkpoints for destructive or batch operations (e.g. no 'verify AnyDesk ID reachable' after install, no 'confirm credential decrypts' after extraction). Per the rubric's batch/destructive cap, this caps workflow clarity at 3; it is not a 4 because checkpoints are entirely missing rather than merely implicit.

3 / 5

Progressive Disclosure

Content is well-sectioned (## headers, numbered sections, tables), but the ~275-line SKILL.md is monolithic with no bundle files in references/, scripts/, or assets/, and detail that belongs in separate files (per-tool deploy guides, detection signatures, error handling) is fully inlined. Not a 2 because section headers provide real structure; not a 4 because no one-level-deep references are signaled.

3 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, tool-named, and highly distinct, with strong natural trigger terms. Its main weakness is the missing explicit 'Use when...' clause, which caps completeness at 3.

Suggestions

Add an explicit 'Use when...' trigger clause, e.g. 'Use when establishing persistence or C2 via commercial RMM tools, or when evading EDR with trusted remote-access software.'

Surface one or two natural synonyms (e.g. 'remote monitoring management', 'remote access tool') into the description itself rather than only in metadata.

DimensionReasoningScore

Specificity

Quotes 'deploy or hijack Atera, ScreenConnect, AnyDesk, TeamViewer for persistence, lateral movement, and C2' and 'evade EDR and blend with IT admin traffic' — names concrete tools and several specific actions. Not a 5 because it does not enumerate the full range of RMM products or OS coverage, leaving minor gaps.

4 / 5

Completeness

Has a clear 'what' (deploy/hijack RMM for persistence, lateral movement, C2) but no explicit 'Use when...' or equivalent trigger guidance, so per the boundary rule completeness is capped at 3. It is not a 4 because the 'when' is entirely absent rather than merely implicit.

3 / 5

Trigger Term Quality

Includes natural trigger terms a practitioner would say — 'RMM', 'Atera', 'ScreenConnect', 'AnyDesk', 'TeamViewer', 'persistence', 'lateral movement', 'C2', 'EDR'. Not a 5 because natural synonyms like 'remote monitoring management' and 'remote access tool' as full phrases are absent (they live in metadata.when_to_use, not the description).

4 / 5

Distinctiveness Conflict Risk

Names a clear niche — abuse of specific commercial RMM products (Atera, ScreenConnect, AnyDesk, TeamViewer) for evasion — with distinct triggers and minimal conflict risk versus other skills. It is not below 5 because the named-tool framing makes it highly distinguishable.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.