CtrlK
BlogDocsLog inGet started
Tessl Logo

zigbee-touchlink

Touchlink commissioning abuse on Zigbee Light Link (ZLL) devices using the well-known ZLL transport key, ZCL command injection (toggle/move/step), network key extraction, and factory reset via touchlink. Toolchain covers KillerBee, zbstumbler, zbreplay, and Sonoff Zigbee 3.0 Dongle E running Wireshark live capture.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/iot/zigbee-touchlink/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable attack playbook with concrete commands and code across five phases, but it lacks explicit validation checkpoints before its destructive factory-reset operation, which caps workflow clarity. Conciseness and progressive disclosure are strong with minor room for improvement.

Suggestions

Add an explicit validation/verification checkpoint before the destructive factory-reset step in Phase 3 (e.g. confirm target PAN/device via zbfind and re-confirm authorization before replaying the reset frame).

Complete the scapy ZCL injection example with an actual send call rather than the placeholder comment '# send via scapy raw socket'.

Trim the opening blockquote and inter-PAN mode explanation, which restate Zigbee/Touchlink fundamentals Claude already knows.

DimensionReasoningScore

Conciseness

Mostly efficient with phase-structured commands and code, though the opening blockquote and a few explanatory asides (e.g. the inter-PAN mode note) restate context Claude largely already knows and could be trimmed.

4 / 5

Actionability

Provides concrete executable commands (zbstumbler, zbdump, zbreplay, zbfind) and Python code for key derivation, scapy packet construction, and NWK key decryption, with only minor gaps such as the scapy packet lacking an actual send call.

4 / 5

Workflow Clarity

Phases 1-5 are clearly sequenced, but the destructive factory-reset step (Phase 3) has no explicit validation/verification checkpoint before execution, capping workflow clarity at 3 per the destructive-operations guideline.

3 / 5

Progressive Disclosure

Well-organized into clear sections (Prerequisites, Phases, Evidence, OPSEC, References) with external links clearly listed; no bundle files exist so all content is inline, which is acceptable for an attack playbook though some detailed scripts could theoretically be split out.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive, naming concrete attack actions and a clear toolchain, but it omits any explicit 'when to use' trigger guidance, which limits its completeness. Adding a 'Use when...' clause referencing natural user phrases would raise the score.

Suggestions

Append a 'Use when...' clause, e.g. 'Use when assessing Zigbee/Touchlink/ZLL device security, factory-resetting smart bulbs, or extracting Zigbee network keys.'

Include consumer-facing synonyms users actually say (smart bulb, Philips Hue, IKEA Tradfri) in the description rather than only in metadata.when_to_use.

Keep the third-person voice (already correct) but ensure the trigger phrase reads naturally as something a user would say.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Touchlink commissioning abuse', 'ZCL command injection (toggle/move/step)', 'network key extraction', and 'factory reset via touchlink' — giving comprehensive coverage of capabilities.

5 / 5

Completeness

The 'what' is clearly and concretely stated, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Strong keyword coverage ('Zigbee', 'Touchlink', 'ZLL', 'ZCL', 'KillerBee', 'zbstumbler', 'zbreplay', 'factory reset'), though common consumer synonyms like 'smart bulb', 'Philips Hue', or 'IKEA Tradfri' that users might say are absent from the description field.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Zigbee Light Link touchlink commissioning abuse) with highly specific triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.