CtrlK
BlogDocsLog inGet started
Tessl Logo

supply-chain-overview

Use when the engagement scope includes supply-chain attack simulation — typosquatted package publication, dependency confusion, GitHub Actions secret mining, internal mirror poisoning, OAuth-app impersonation, or vendor portal credential abuse.

59

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/supply-chain/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

58%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is well-organized and concise with a useful technique catalog and clear scope boundaries, but it lacks executable code/commands and validation feedback loops for destructive publish operations. Progressive disclosure is weakened by an inline reference to a non-existent external file and the absence of separate playbook reference files.

Suggestions

Add at least one executable code block or concrete command per playbook (e.g., the dep-confusion-probe availability check command) to move from description to instruction.

Insert an explicit validation checkpoint in the dry-run/real-publish workflow (e.g., 'validate artifact + hit probability, halt for HITL approval before upload') with a fix-and-retry loop.

Either create the referenced ../../red-team/tools-techniques.md or remove the broken link, and split per-technique playbooks into one-level-deep reference files signaled from the overview.

DimensionReasoningScore

Conciseness

The body is reasonably lean, using a compact technique table and bullets without over-explaining concepts Claude already knows; minor instances of framing prose ('Most rewarding attack class in 2024-2026', 'Defense in depth') could be trimmed.

4 / 5

Actionability

It catalogs techniques and misconfigurations concretely but provides no executable code or commands for executing the playbooks — the dry-run section lists steps but as prose, and the GitHub Actions enumeration is descriptive rather than instructive.

3 / 5

Workflow Clarity

The dry-run mode lists a numbered sequence and flags a real-publish gate, but for destructive/batch publish operations there is no validate-then-fix feedback loop; the destructive-operation cap therefore limits this to 3.

3 / 5

Progressive Disclosure

The body is well-sectioned and self-contained, but the one inline link points to an external path (../../red-team/tools-techniques.md) that does not exist in the bundle, and detailed per-technique playbooks are summarized inline rather than split into one-level-deep reference files.

3 / 5

Total

13

/

20

Passed

Description

80%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive with concrete trigger terms and an explicit 'Use when' clause tied to supply-chain attack simulation. It is slightly more enumeration-heavy than action-oriented, keeping it just below the top anchor on specificity and completeness.

Suggestions

Lead the description with the concrete verbs/actions the skill performs (e.g., 'Simulates, publishes, and probes...') before enumerating targets, to strengthen the 'what it does' framing.

Add one or two everyday synonyms (e.g., 'typosquatting', 'package impersonation') to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

Lists several concrete attack techniques (typosquatted package publication, dependency confusion, GitHub Actions secret mining, OAuth-app impersonation, vendor portal credential abuse) rather than vague language, though it enumerates targets more than executable actions.

4 / 5

Completeness

Has an explicit 'Use when the engagement scope includes...' clause (clear 'when') and enumerates the technique scope (clear 'what'); the 'when' is concrete but scoped to engagement context rather than everyday user phrasing.

4 / 5

Trigger Term Quality

Natural trigger terms like 'typosquat', 'dependency confusion', 'gh actions secret', 'oauth app impersonation', and 'vendor portal' are present and likely to be said by users; minor synonyms/extensions missing.

4 / 5

Distinctiveness Conflict Risk

The supply-chain attack-simulation niche with MITRE T1195 references is highly distinct from other skills and unlikely to trigger for the wrong skill.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.