CtrlK
BlogDocsLog inGet started
Tessl Logo

volt-typhoon

Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/volt-typhoon/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actor-specific intelligence profile with actionable emulation guidance mapped to ATT&CK and specific commands. Its main weaknesses are verbosity in prose sections and missing validation/feedback-loop checkpoints for destructive credential and log-clearing operations.

Suggestions

Add explicit validation checkpoints and a fix-and-retry feedback loop to the emulation guidance for destructive/batch steps (e.g. verify ntds.dit extraction and archive integrity before exfil; confirm log-clear actions are within scope and reversible via blue-cell snapshots).

Tighten the intro, attribution, and campaign prose to bullet-style facts to reduce token overhead while preserving the intelligence value.

Consider moving the full ATT&CK ID catalog and signature-tooling list into a references file (e.g. TTPS.md / TOOLING.md) with a one-line pointer, keeping SKILL.md as a lean overview.

DimensionReasoningScore

Conciseness

The body is detailed and mostly focused on actor-specific intelligence Claude could not derive, but the lengthy attribution prose and dense prose paragraphs in sections like the intro and campaigns could be tightened; it sits at the mostly-efficient-with-some-padding anchor.

3 / 5

Actionability

"Emulation guidance (Decepticon)" provides concrete, mapped steps (edge-device-first exploitation, bash/LOTL execution, ntds.dit staging in C:\Windows\Temp, Sliver HTTPS C2 on 443) with specific commands and ATT&CK IDs, leaving only minor gaps versus fully copy-paste-ready procedures.

4 / 5

Workflow Clarity

TTPs are organized by tactic and the emulation guidance is a clear narrative list, but destructive/batch credential operations (ntds.dit capture, multi-volume 7-Zip archives, log clearing) lack explicit validation/verification checkpoints and feedback loops, which caps workflow clarity at 3 per the rubric.

3 / 5

Progressive Disclosure

No bundle files exist and the skill is a single self-contained overview with well-organized section headers (attribution, targeting, campaigns, TTPs by tactic, tooling, emulation, detection, sources); structure is good and navigation is easy, though some dense reference material (full ATT&CK ID list, tool catalog) could be split out.

4 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a specific actor and concrete tradecraft niche with strong distinctiveness, but omits an explicit "Use when..." trigger clause and pushes most user-facing trigger terms into metadata rather than the description itself. Completeness is accordingly capped at 3.

Suggestions

Add an explicit "Use when..." trigger clause to the description field, e.g. "Use when emulating Volt Typhoon / PRC LOTL pre-positioning in authorized red-team engagements."

Surface 2-3 natural trigger keywords (actor aliases, LOTL/LOLBins, critical-infrastructure emulation) directly in the description rather than only in metadata.when_to_use.

List one or two more concrete actions (e.g. "maps TTPs to emulation steps") to push specificity toward comprehensive coverage.

DimensionReasoningScore

Specificity

"Adversary-emulation profile" plus concrete framing ("pre-positioning in US critical infrastructure via living-off-the-land TTPs") names the domain and several specific characteristics, but it lists fewer discrete actions than the comprehensive 5-anchor example.

4 / 5

Completeness

It clearly answers "what" (an adversary-emulation profile for a specific actor) but the description field lacks an explicit "Use when..." trigger clause; per rubric guidance a missing trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

The frontmatter description itself does not embed user-facing trigger keywords (those live in metadata.when_to_use), so evaluated against the description string alone it lacks the natural terms users would say; anchor 4 fits because the named actor/aliases give some natural coverage but several common variations are absent from the description text.

4 / 5

Distinctiveness Conflict Risk

Naming a specific tracked actor (Volt Typhoon / G1017) with a clear niche (PRC LOTL pre-positioning emulation) gives a distinct trigger surface with minimal overlap risk against other skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.