CtrlK
BlogDocsLog inGet started
Tessl Logo

sandworm

Sandworm (APT44 / Seashell Blizzard, GRU Unit 74455) adversary-emulation playbook — IT→OT intrusion ending in ICS manipulation or destructive impact, executed with living-off-the-land Windows tooling. SAFETY-CRITICAL: destructive and ICS-write steps are canary/lab-only and gated on explicit OT authorization. Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate. Triggers on: 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya'.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a concise, well-structured adversary-emulation playbook with strong safety gating and clear sequencing appropriate to a destructive/ICS skill. Actionability and progressive disclosure are solid but not maximal because guidance points to external skill paths rather than bundled, self-contained detail files.

Suggestions

Add a short in-bundle references/ file (e.g. apt-groups.md or an OT-safety checklist) so the cross-referenced detail lives within this skill's bundle rather than only outside it.

For the ICS-write and canary-destruction phases, include a compact inline command snippet (e.g. a read-only pymodbus read call and the canary artifact naming convention) to make those steps more directly executable.

Make the referenced external skill paths consistent (some rows use /skills/standard/... while the apt-groups reference uses ../../references/...); standardizing the path style would improve navigation clarity.

DimensionReasoningScore

Conciseness

Lean and efficient; assumes Claude's competence without explaining what ICS, LOTL, or a wiper is, and every section (ThreatProfile seed, kill-chain table, CONOPS, OPSEC, RoE gates, deconfliction, fidelity notes) earns its place.

5 / 5

Actionability

Concrete, specific guidance — per-phase MITRE techniques, named tools (NetExec, Impacket, Sliver, pymodbus/python-snap7), referenced skills per row, and named artifact files — but it points to external skills/files rather than being fully self-contained executable steps, leaving minor gaps.

4 / 5

Workflow Clarity

The kill chain is clearly sequenced (phases 1–10, CONOPS 1–5) with prominent validation/safety checkpoints — read-only default, explicit OT-write authorization gate, OT safety engineer requirement, abort.json EMERGENCY trigger, and maintenance-window standby — satisfying the destructive-operation validation requirement.

5 / 5

Progressive Disclosure

Well-organized with clear section headers and clearly signaled one-level-deep inline references, but no in-bundle references/scripts/assets exist and the referenced paths (e.g. ../../references/apt-groups.md, /skills/standard/...) point outside this skill's bundle.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and distinctive — it states concrete capabilities, an explicit 'Use when...' clause with natural trigger terms and synonyms, and a narrow niche that minimizes conflict risk. Third-person voice is maintained throughout. No changes needed.

DimensionReasoningScore

Specificity

Names concrete actions — 'IT→OT intrusion ending in ICS manipulation or destructive impact', 'living-off-the-land Windows tooling', canary/lab-only steps 'gated on explicit OT authorization' — comprehensively covering the niche.

5 / 5

Completeness

Explicitly answers both 'what' (adversary-emulation playbook ending in ICS manipulation or destructive impact) and 'when' ('Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural trigger terms including synonyms and aliases — 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya' — exactly what a user would say.

5 / 5

Distinctiveness Conflict Risk

A clear, narrow niche (Sandworm/APT44 ICS-OT destructive emulation) with highly specific triggers and minimal overlap risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.