CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-profile

Threat actor profiling for adversary emulation — APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable threat-profiling workflow with concrete schemas, technique IDs, and real reference files, held just below top marks by mild over-explanation and an implicit rather than explicit validation feedback loop.

Suggestions

Make the Step 3→Step 5 validation loop explicit (e.g. 'If a planned TTP conflicts with RoE, prune it and re-confirm the kill chain before writing') to strengthen the feedback loop.

Trim the opening framing sentence and any restated rationale to tighten token efficiency.

Consolidate the emulation-playbook references into a short bulleted reference list so navigation paths are scannable at a glance.

DimensionReasoningScore

Conciseness

The body is mostly efficient — tables, a JSON schema, and concrete MITRE IDs carry the load — with only minor over-explanation (e.g. the opening 'Without a clear profile, the engagement devolves into arbitrary tool usage...' framing) that could be trimmed.

4 / 5

Actionability

Guidance is largely executable: a copy-paste-ready ThreatProfile JSON block, specific MITRE technique IDs per RoE constraint, and concrete load_skill() paths, with only minor gaps where steps are guidance rather than runnable commands.

4 / 5

Workflow Clarity

A clear 5-step sequence with an explicit validation checkpoint (Step 3: Validate Against RoE) and a feedback reference (Step 5 prunes RoE-forbidden techniques before writing); minor gap is that the validation→fix→retry loop is implicit rather than an explicit re-check loop.

4 / 5

Progressive Disclosure

Overview content is kept inline while detail is pushed to clearly signaled, one-level-deep references that exist as real files ('references/adversary-archetypes.md', 'references/apt-groups.md', 'emulation/<actor>/SKILL.md'); minor organization gap is that the emulation catalog reference is described in prose rather than a tidy reference list.

4 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description that names concrete capabilities and natural trigger terms, but it lacks an explicit 'when to use' clause in the description itself, capping completeness.

Suggestions

Add an explicit trigger clause to the description, e.g. 'Use when selecting a threat actor for adversary emulation, APT simulation, or mapping engagement scope to attacker behaviors.'

Lead capability phrases with verbs (e.g. 'Research APT groups, map sophistication tiers, map TTPs to MITRE ATT&CK') to lift specificity toward comprehensive.

Include a common synonym or phrasing a user might naturally say (e.g. 'red team threat actor') to round out trigger coverage.

DimensionReasoningScore

Specificity

Lists several concrete sub-activities ('APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes') with minor gaps; they read as noun-phrase capabilities rather than verb-led actions, keeping it just below comprehensive.

4 / 5

Completeness

The 'what' is clear and concrete, but there is no explicit 'Use when...' clause or equivalent trigger guidance in the description itself — trigger phrasing exists only in the metadata.when_to_use field, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Natural terms a user would say are present ('threat actor', 'APT group', 'adversary emulation', 'MITRE ATT&CK'), but a few common synonyms (e.g. 'red team', 'who should we emulate') live only in metadata, so coverage is good rather than comprehensive.

4 / 5

Distinctiveness Conflict Risk

The niche (threat actor profiling for adversary emulation) is clear and fairly distinct, with only minor overlap risk against broader engagement-planning or threat-modeling skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.