CtrlK
BlogDocsLog inGet started
Tessl Logo

sandworm-team

Adversary-emulation profile for Sandworm Team (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM), Russia's GRU Unit 74455 destructive ICS/OT and influence actor (ATT&CK G0034).

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/sandworm-team/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-structured adversary profile with actionable emulation guidance and strong safety/authorization gating for its destructive content; its main weakness is verbosity from re-explaining ATT&CK techniques Claude already knows and the absence of formal validation feedback loops.

Suggestions

Trim the per-technique ATT&CK glosses in the TTP section to just the actor-specific behavior (e.g., drop generic 'Vulnerability-scans target infrastructure' and keep only the Sandworm-specific application), improving conciseness without losing the mapping.

Add a brief validate-fix-retry loop to the emulation guidance (e.g., 'verify the beacon checked in and the GPO payload executed on a sample host before fleet-wide deployment') to push workflow clarity toward 5.

Consider moving the full TTP-by-tactic enumeration and signature-tooling table into a references/ file (e.g. TTPS.md) referenced one level deep, so SKILL.md stays a lean overview.

DimensionReasoningScore

Conciseness

Mostly efficient dense reference content (specific dates, CVEs, malware families earn their place), but the per-tactic TTP section re-explains ATT&CK techniques Claude already knows ('Vulnerability-scans target infrastructure', 'profiles software in use'), which could be tightened to just the actor-specific mapping.

3 / 5

Actionability

Emulation guidance gives concrete, specific direction referencing named tools and skills ('Stand up c2/sliver with HTTPS and TLS-tunneled profiles', 'Use the AD skills to enumerate via LDAP, dump LSASS/NTDS'), with minor gaps (no literal copy-paste commands, but instruction-style guidance is actionable).

4 / 5

Workflow Clarity

The emulation guidance follows a clear attack-lifecycle sequence (initial access → phishing → AD escalation → C2 → evasion → lateral → cloud → impact → OT) with prominent authorization and safety verification gates ('Authorized use only', 'ONLY in an isolated lab range', 'never issue control commands against real equipment'); the destructive-safety validation is present so the cap at 3 does not trigger, though formal validate-fix-retry loops are absent.

4 / 5

Progressive Disclosure

Well-organized with clear section headers and a single-level self-contained structure (no nested references); the large TTP-by-tactic enumeration and tooling table could plausibly split into a reference file, a minor organization gap rather than a structural defect.

4 / 5

Total

15

/

20

Passed

Description

72%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly specific and distinctive with excellent natural trigger-term coverage, but it is a noun phrase lacking concrete action verbs and omits an explicit 'Use when…' clause, which caps completeness at 3.

Suggestions

Add an explicit trigger clause, e.g. 'Use when emulating Sandworm Team / APT44 destructive ICS-OT or influence operations, or when the user mentions Voodoo Bear, Seashell Blizzard, Industroyer, NotPetya, or GRU Unit 74455.'

Lead with concrete actions ('Maps Sandworm TTPs to ATT&CK and guides Decepticon emulation of…') instead of a pure noun phrase, to lift specificity above 3.

DimensionReasoningScore

Specificity

Names the domain richly ('adversary-emulation profile for Sandworm Team', 'GRU Unit 74455 destructive ICS/OT and influence actor', 'ATT&CK G0034') but uses a noun phrase with no concrete action verbs, so it sits at the 'names domain, minimal actions' boundary rather than listing specific actions.

3 / 5

Completeness

Has a clear 'what' (an adversary-emulation profile for Sandworm Team) but no explicit 'Use when…' trigger clause, so per the cap 'when' is only weakly implied and completeness cannot exceed 3.

3 / 5

Trigger Term Quality

Comprehensive natural alias coverage a user would actually say — 'sandworm', 'voodoo bear', 'seashell blizzard', 'apt44', 'electrum', 'GRU Unit 74455', 'ICS/OT', 'ATT&CK G0034' — including multiple synonyms for the same actor.

5 / 5

Distinctiveness Conflict Risk

A clear, narrow niche (a single named GRU actor) whose alias set (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM) is uniquely Sandworm, giving minimal conflict risk with sibling profiles.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.