CtrlK
BlogDocsLog inGet started
Tessl Logo

sandworm

Sandworm (APT44 / Seashell Blizzard, GRU Unit 74455) adversary-emulation playbook — IT→OT intrusion ending in ICS manipulation or destructive impact, executed with living-off-the-land Windows tooling. SAFETY-CRITICAL: destructive and ICS-write steps are canary/lab-only and gated on explicit OT authorization. Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate. Triggers on: 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya'.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary planning playbook body: compact, actor-specific, and highly actionable, with strong safety gating on the destructive and ICS-write steps (authorization, named test points, abort triggers, deconfliction scope). The two residual gaps are the absence of post-action verification checkpoints and reliance on cross-directory catalog references rather than a self-contained bundle structure.

Suggestions

Add explicit post-action verification steps after the gated ICS write and canary detonation — e.g., verify only the named coil/register changed, confirm the canary file set is restored, and confirm cleanup.json inventory is complete before closing the phase (workflow_clarity).

Consolidate the external catalog references (sub-skill paths and `../../references/apt-groups.md`) into a single 'Referenced skills' section, or move shared lookup content like the industry → actor map into a references/ file within this bundle so navigation does not depend on the parent directory layout (progressive_disclosure).

State a concrete fallback checkpoint when no OT lab is available — the body says the ICS step is 'fully simulated' but does not specify what evidence the simulated path must produce for the deliverable (workflow_clarity).

DimensionReasoningScore

Conciseness

The ~98-line body is dense and operational with zero filler: it never explains generic concepts (what MITRE is, what a PLC is) and every section carries unique content — the ThreatProfile seed, kill-chain table, CONOPS, OPSEC fidelity, safety gates, deconfliction, and deviation notes. Nothing is padded; every token earns its place, matching the lean anchor.

5 / 5

Actionability

Guidance is fully concrete and copy-paste ready: a fill-in ThreatProfile JSON seed for `plan/threat-profile.json`, a 10-row kill-chain table mapping each phase to MITRE technique, executing agent, and exact sub-skill path, a numbered CONOPS for `conops.json`, named tools (pymodbus, python-snap7, Sliver, NetExec), and quoted abort-trigger text for `abort.json`. Per the rubric's instruction-skill note, absence of code is not penalized since the routing guidance is exact and executable.

5 / 5

Workflow Clarity

The destructive-operation cap does not apply — validation is explicitly present (written OT-write authorization, OT engineer on the contact plan, named test points, EMERGENCY abort trigger with halt + page + 1hr cooldown, deconfliction scope list, maintenance window). The 10-phase sequence is coherent with gates at each risky step, but there is no explicit post-action verification (e.g., confirm the ICS write landed only on the named test point, confirm canary restoration, confirm cleanup complete), which is the minor validation gap separating it from anchor 5.

4 / 5

Progressive Disclosure

Structure is good: clear section headers, an overview-length body, and well-signaled one-level-deep references to per-phase sub-skills. However, the skill has no bundle files of its own and its references point into the surrounding catalog layout (e.g., `../../references/apt-groups.md` and `/skills/standard/...` paths) that cannot be resolved from this bundle, which is a minor navigation/organization gap versus the clean anchor-5 structure.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names the actor and aliases, states exactly what the playbook does (IT→OT intrusion ending in ICS manipulation or destructive impact via LOTL tooling), flags the safety posture, and gives explicit 'Use when' guidance with a comprehensive trigger list. The only weakness is that a couple of broad trigger phrases ('ICS attack', 'OT destructive') could collide with other ICS-focused skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'IT→OT intrusion ending in ICS manipulation or destructive impact, executed with living-off-the-land Windows tooling' — and covers the playbook's full scope, including the safety posture ('canary/lab-only and gated on explicit OT authorization'). It matches the anchor for multiple specific concrete actions with comprehensive coverage; nothing is vague or generic.

5 / 5

Completeness

Both questions are explicitly answered: 'what' is the adversary-emulation playbook for the Sandworm IT→OT kill chain with LOTL tooling, and 'when' is stated directly — 'Use when emulating Sandworm against an ICS/OT or critical-infrastructure estate. Triggers on: ...'. This matches the top anchor (clear what AND when with concrete trigger phrases), not the anchor-4 case where 'when' could be more specific.

5 / 5

Trigger Term Quality

Explicit trigger list covers the natural phrasings and all actor synonyms a user would actually say: 'emulate Sandworm', 'APT44', 'Seashell Blizzard', 'Voodoo Bear', 'ICS attack', 'OT destructive', 'Industroyer', 'NotPetya'. This is comprehensive synonym-level coverage; not merely 'some relevant keywords' (3) or 'a few natural terms missing' (4).

5 / 5

Distinctiveness Conflict Risk

The niche is clear (Sandworm/GRU Unit 74455 destructive ICS emulation) and most triggers ('APT44', 'NotPetya', 'Industroyer') are uniquely identifying. However, the generic triggers 'ICS attack' and 'OT destructive' could also match sibling ICS/OT or other APT-emulation skills in the same catalog, which is minor overlap risk — matching anchor 4 rather than 5's 'minimal conflict risk'.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.