CtrlK
BlogDocsLog inGet started
Tessl Logo

ros2-dds-attack

ROS2/DDS network attack: unauthenticated topic enumeration, message injection, and telemetry interception against robotic platforms and autonomous systems.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/iot/ros2-dds-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sequenced, executable attack playbook with strong safety gating on the destructive injection phase. It is concise and actionable, with only minor room to tighten the Background and split out auxiliary reference material.

Suggestions

Trim the Background's acronym expansion and DDS transport explanation, which restate concepts Claude already knows.

Verify the cyclonedds Python snippet's API (e.g. lookup_topicdescriptions) against the installed package version and mark it as version-sensitive.

Consider moving the ATT&CK mapping and Detection sections into a bundled reference file so the main body stays a lean overview.

DimensionReasoningScore

Conciseness

Dense with executable commands and tables; the only over-explanation is the brief Background paragraph expanding ROS2/DDS acronyms and transport behavior Claude largely already knows, which could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready tshark, docker ros2, tcpdump, and ros2 topic pub commands across all phases, with only minor gaps (interface/IP placeholders, a commented-out non-zero PoC, and an approximate cyclonedds API call).

4 / 5

Workflow Clarity

Phases 1–4 are clearly sequenced and the destructive injection step is explicitly gated ('STOP. Confirm safety_critical_confirmed=true ... before executing any publish command'), satisfying the validation requirement; no error-recovery feedback loop is present, keeping it just below 5.

4 / 5

Progressive Disclosure

Well-organized into Background, four phased sections, ATT&CK, Detection, and References with no nested or buried references; as a single self-contained file with no bundle files it is cleanly structured, though ATT&CK/Detection/MiR-variant content could optionally live in separate reference files.

4 / 5

Total

16

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and occupies a well-defined niche, but it omits an explicit 'Use when' trigger clause and leans on technical jargon over natural user phrasing, capping completeness and trigger-term quality.

Suggestions

Add an explicit 'Use when ...' clause naming natural triggers (e.g. 'Use when assessing ROS2/DDS robot networks, or when the user mentions ROS2, DDS, Unitree, MiR, or ros2 topic commands').

Include common natural synonyms and vendor/product names (robot, ROS, ros2 topic, Unitree, MiR) directly in the description rather than only in metadata.

Mention credential/key extraction alongside enumeration, injection, and interception to make the capability list comprehensive.

DimensionReasoningScore

Specificity

Lists several concrete attack actions — 'unauthenticated topic enumeration, message injection, and telemetry interception' — but omits credential/key extraction covered in the body, leaving a minor coverage gap rather than full comprehensiveness.

4 / 5

Completeness

The description field gives a clear 'what' (three enumerated attack actions) but contains no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Includes relevant keywords ('ROS2/DDS', 'robotic platforms', 'autonomous systems') but leans technical and misses common natural variations users would say (e.g. 'robot', 'ROS topic', vendor names like Unitree/MiR that live only in metadata).

3 / 5

Distinctiveness Conflict Risk

Targets a clear niche (ROS2/DDS network attacks on robotic/autonomous platforms) with distinct triggers and minimal overlap risk against other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.