CtrlK
BlogDocsLog inGet started
Tessl Logo

scattered-spider

Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/scattered-spider/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is thorough, accurate and well-organized with concrete ATT&CK mappings and per-phase emulation guidance, but it is verbose with all detail inline (no progressive disclosure), gives descriptive rather than executable instruction, and lacks explicit validation checkpoints. Splitting reference material into bundle files and adding executable examples or validation gates would lift it.

Suggestions

Move the detailed campaign timeline and full TTP-by-tactic catalog into reference files (e.g. references/campaigns.md, references/ttps.md) and keep SKILL.md as a concise overview with one-level-deep pointers.

Add executable or copy-paste-ready snippets for the signature emulation steps (e.g. example vishing/MFA-fatigue emulation commands, Entra ID federation-trust commands) instead of descriptive guidance.

Insert explicit validation checkpoints in the emulation workflow (e.g. 'confirm scope/authorization before each phase', 'verify controls detected the simulated TTP before proceeding').

DimensionReasoningScore

Conciseness

The body is information-dense rather than padded with basics Claude knows, but it is long — full campaign timelines, a complete TTP-by-tactic catalog, tool lists and detection rules are all inline with no offloading, so it could be tightened; not the lean level-3 anchor.

2 / 3

Actionability

It gives concrete guidance (specific ATT&CK IDs, named tooling, per-phase emulation steps in the 'Emulation guidance' section) but instructs via description ('emulate...', 'use the cloud skills to emulate...') rather than copy-paste-ready executable code or commands, so it is not at level 3.

2 / 3

Workflow Clarity

The 'Emulation guidance' section sequences phases (initial access -> cloud pivot -> AD -> lateral/C2 -> virtualization -> exfil -> impact) with safety cautions ('Authorized use only', 'stop short of encryption'), but there are no explicit validate->fix->retry checkpoints and the gates are cautionary rather than validation steps, so it sits at the mid anchor.

2 / 3

Progressive Disclosure

No bundle files exist (references/scripts/assets are empty) and the body references no external files; all reference material (campaign timeline, full TTP catalog, detection guidance) is inline in a single document, which is content that could be split out, so it is not the clean overview-with-one-level-references level-3 anchor.

2 / 3

Total

8

/

12

Passed

Description

57%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and names its niche well, but it states a category rather than concrete actions and omits an explicit 'Use when' trigger clause, leaving it mostly at the mid-level anchors. It would benefit from naming concrete emulation actions and an explicit usage trigger.

Suggestions

Add concrete actions the skill performs, e.g. 'emulate help-desk vishing, MFA-fatigue, and Entra ID federation abuse'.

Append an explicit 'Use when...' clause naming task-oriented triggers (e.g. 'Use when emulating Scattered Spider/UNC3944 identity-centric TTPs in an authorized engagement').

Surface a few natural task keywords ('social-engineering emulation', 'MFA bypass emulation') directly in the description rather than only in when_to_use metadata.

DimensionReasoningScore

Specificity

Names the subject, aliases, motive and ATT&CK mapping ('Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group'), but describes a category ('adversary-emulation profile') rather than listing multiple concrete actions the skill performs, so it is not at level 3.

2 / 3

Completeness

It clearly answers 'what' (an ATT&CK-mapped emulation profile) but contains no 'Use when...' or equivalent explicit trigger clause in the description field; per the rubric, a missing explicit 'when' caps completeness at 2.

2 / 3

Trigger Term Quality

The description surfaces the group's natural names/aliases (Scattered Spider, UNC3944, Octo Tempest), but task-oriented keywords a user would actually say (e.g. 'emulate', 'social-engineering emulation') live in when_to_use metadata rather than the description itself, so coverage is only partial.

2 / 3

Distinctiveness Conflict Risk

It targets a uniquely named threat actor (G1015 / Scattered Spider with aliases) plus Decepticon tooling, giving it a clear niche that is unlikely to trigger for the wrong skill.

3 / 3

Total

9

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.