github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
apt41-double-dragon packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.md Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt37-reaper packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.md Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor. | 57 57 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt36-transparent-tribe packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt34-oilrig packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt33-elfin packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt29-cozy-bear packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt28-fancy-bear packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.md Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
apt10-stone-panda packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.md Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
adversary-emulation packages/decepticon/decepticon/skills/shared/adversary-emulation/SKILL.md Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
vulnresearch-orchestrator packages/decepticon/decepticon/skills/plugins/vulnresearch/SKILL.md Five-stage modular vulnerability pipeline orchestrator. Delegates scan → detect → verify → patch → exploit through OPPLAN objectives. Load at orchestrator startup. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
seven-question-gate packages/decepticon/decepticon/skills/plugins/verifier/seven-question-gate/SKILL.md 7-question gate run before promoting a finding to FINDING + opening a report. Kills weak/non-impactful findings before they reach the report stage and damage validity ratio. | 58 58 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
bounty-report-formatter packages/decepticon/decepticon/skills/plugins/verifier/bounty-report/SKILL.md Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
verifier-overview packages/decepticon/decepticon/skills/plugins/verifier/SKILL.md Stage 3 triage and verification playbook. Crafts minimal PoCs, runs them with ZFP controls, promotes validated bugs to FINDING nodes with CVSS. Load at verifier-agent startup. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
scanner-overview packages/decepticon/decepticon/skills/plugins/scanner/SKILL.md Stage 1 broad-spectrum scanner playbook. Sharded sweep over very large codebases producing CANDIDATE nodes for the Detector to reason about. Load at scanner-agent startup. | 56 56 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 0cf691e | |
patcher-overview packages/decepticon/decepticon/skills/plugins/patcher/SKILL.md Stage 4 patch generation playbook. Minimal diffs for validated findings with mandatory patch_verify. Load at patcher-agent startup. | 58 58 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 0cf691e | |
aatmf-t15-human-ai-coupling packages/decepticon/decepticon/skills/plugins/llm-redteam/t15-human-ai-coupling/SKILL.md AATMF T15 — Human-AI Coupling. Deepfake escalation, voice clone vishing, deepfake-image-driven social engineering, automation of human-targeted attacks. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t14-infra-warfare packages/decepticon/decepticon/skills/plugins/llm-redteam/t14-infra-warfare/SKILL.md AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t13-supply-chain packages/decepticon/decepticon/skills/plugins/llm-redteam/t13-supply-chain/SKILL.md AATMF T13 — AI Supply Chain & Artifact Trust. Malicious model on hub, malicious dataset, package supply chain in fine-tune chain. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t12-rag-poisoning packages/decepticon/decepticon/skills/plugins/llm-redteam/t12-rag-poisoning/SKILL.md AATMF T12 — RAG & Knowledge Base Manipulation. PoisonedRAG, vector store flood, embedding collision, retrieval-bias attacks. | 49 49 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t11-agentic-exploit packages/decepticon/decepticon/skills/plugins/llm-redteam/t11-agentic-exploit/SKILL.md AATMF T11 — Agentic & Orchestrator Exploitation. MCP tool poisoning, agent-to-agent prompt injection, tool-result spoofing, orchestrator state confusion. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t10-confidentiality-breach packages/decepticon/decepticon/skills/plugins/llm-redteam/t10-confidentiality-breach/SKILL.md AATMF T10 — Integrity & Confidentiality Breach. System prompt extraction, training-data extraction, model-weight leakage, private-key recovery. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t09-multimodal packages/decepticon/decepticon/skills/plugins/llm-redteam/t09-multimodal/SKILL.md AATMF T9 — Multimodal & Cross-Channel. Image steganography → text exec, audio prompt injection, video frame inject, document-with-hidden-text. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t08-deception packages/decepticon/decepticon/skills/plugins/llm-redteam/t08-deception/SKILL.md AATMF T8 — External Deception & Misinformation. Misinfo generation at scale, persona impersonation, document fabrication, hallucination weaponization. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t07-output-exfil packages/decepticon/decepticon/skills/plugins/llm-redteam/t07-output-exfil/SKILL.md AATMF T7 — Output Manipulation & Exfiltration. Covert channels in output, schema break, exfil via image gen, side-channel via timing. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aatmf-t06-training-poisoning packages/decepticon/decepticon/skills/plugins/llm-redteam/t06-training-poisoning/SKILL.md AATMF T6 — Training & Feedback Poisoning. Data poisoning, RLHF reward hacks, fine-tune-time exfil, embedding poisoning. | 53 53 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e |