CtrlK
BlogDocsLog inGet started
Tessl Logo

salt-typhoon-earth-estries

Adversary-emulation profile for Salt Typhoon (G1045 / Earth Estries / GhostEmperor / FamousSparrow / UNC2286 / RedMike / OPERATOR PANDA), a PRC state-sponsored cyber-espionage actor targeting telecommunications and critical infrastructure worldwide.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/salt-typhoon/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete commands and a well-organized kill-chain structure, but it is a long monolith with no progressive disclosure and lacks explicit validation checkpoints for destructive network operations. Splitting deep reference material into bundle files and adding validation steps would lift the two dimensions scored at 2.

Suggestions

Move the full TTP-by-tactic catalog and signature-tool table into a references/ bundle file (e.g. TTPS.md, TOOLS.md) and keep SKILL.md as a concise overview with one-level-deep links to improve progressive_disclosure.

Add explicit validation checkpoints to the emulation workflow (e.g. confirm lab isolation before modifying routing/SPAN, verify authorization scope before each destructive step) to lift workflow_clarity from 2 to 3.

Tighten the attribution, targeting, and notable-campaign sections to remove overlap with the TTP sections and reduce token cost.

DimensionReasoningScore

Conciseness

The dense TTP-by-tactic catalog, CVE lists, and tool table are genuinely non-obvious value that mostly earns its place, but the attribution, targeting, and notable-campaign sections overlap with the TTP sections and could be tightened. It is mostly efficient but not lean enough for anchor 3.

2 / 3

Actionability

The emulation-guidance and detection sections give concrete, copy-paste-ready commands (e.g. "guestshell enable", "monitor capture mycap interface ... match ipv4 protocol tcp any any eq 49", "copy bootflash:tac.pcap ftp://...", "no iox"), matching anchor 3 ("Fully executable code/commands; specific examples; copy-paste ready").

3 / 3

Workflow Clarity

The emulation guidance is sequenced by kill-chain phase (initial access → persistence → interception → C2 → exfiltration), but it lacks explicit validation checkpoints or validate-then-proceed feedback loops for destructive network-device operations, which the scoring notes cap at 2.

2 / 3

Progressive Disclosure

Headers organize the content clearly, but the ~185-line body is a monolith with no bundle files and no external references; content that could be split out (full TTP catalog, signature-tool table) is inline. The under-50-line exception does not apply, so it fits anchor 2 rather than 3.

2 / 3

Total

9

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is rich in natural trigger terms and highly distinctive due to its specific actor aliases, but it omits an explicit 'Use when...' trigger clause and does not enumerate concrete actions, which cap completeness and specificity at 2. Adding a trigger clause and naming the actions the profile enables would lift both dimensions.

Suggestions

Add an explicit 'Use when...' trigger clause, e.g. 'Use when emulating Salt Typhoon / Earth Estries TTPs, mapping the group's ATT&CK techniques, or generating detections for telecom and edge-device compromises.'

Enumerate concrete actions the profile supports (e.g. 'maps TTPs to MITRE ATT&CK, provides emulation guidance for edge-device exploitation, and lists detection and hardening measures') to raise specificity from 2 to 3.

DimensionReasoningScore

Specificity

Names the domain ("Adversary-emulation profile") and the subject (a PRC cyber-espionage actor targeting telecommunications and critical infrastructure), but does not enumerate concrete actions Claude performs such as mapping TTPs or generating detections. Anchor 2 ("Names domain and some actions, but not comprehensive") fits better than 3, which requires multiple specific concrete actions.

2 / 3

Completeness

It clearly states what the skill is (an adversary-emulation profile for Salt Typhoon) but contains no "Use when..." clause or equivalent explicit trigger guidance; per the judging guidelines a missing trigger clause caps completeness at 2.

2 / 3

Trigger Term Quality

The description is dense with the exact natural terms a user would say when needing this skill — "Salt Typhoon", "Earth Estries", "GhostEmperor", "FamousSparrow", "UNC2286", "RedMike", "OPERATOR PANDA" — matching the anchor 3 ("Good coverage of natural terms users would say").

3 / 3

Distinctiveness Conflict Risk

The highly specific actor aliases and narrow telecom/critical-infrastructure espionage niche make it clearly distinguishable and unlikely to trigger for the wrong skill, matching anchor 3 ("Clear niche with distinct triggers; unlikely to conflict").

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.