CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

Skill

Added

Review

apt36-transparent-tribe

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.md

Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities.

54

apt34-oilrig

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt34-oilrig/SKILL.md

Adversary-emulation profile for APT34 / OilRig (G0049), an Iranian state-sponsored espionage group, mapping its ATT&CK TTPs to Decepticon tooling for authorized red-team emulation.

54

apt33-elfin

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt33-elfin/SKILL.md

Adversary-emulation profile for APT33 (Elfin, Peach Sandstorm, HOLMIUM), a suspected Iranian state-sponsored espionage group, mapped to MITRE ATT&CK G0064 with Decepticon emulation guidance.

62

apt29-cozy-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt29-cozy-bear/SKILL.md

Adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard / NOBELIUM / The Dukes), Russia's SVR-attributed cyber-espionage group, mapping its ATT&CK TTPs to Decepticon emulation tooling.

54

apt28-fancy-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.md

Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor.

54

apt10-stone-panda

packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.md

Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor.

32

adversary-emulation

packages/decepticon/decepticon/skills/shared/adversary-emulation/SKILL.md

Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology.

71

bounty-report-formatter

packages/decepticon/decepticon/skills/plugins/verifier/bounty-report/SKILL.md

Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program.

76

aatmf-t15-human-ai-coupling

packages/decepticon/decepticon/skills/plugins/llm-redteam/t15-human-ai-coupling/SKILL.md

AATMF T15 — Human-AI Coupling. Deepfake escalation, voice clone vishing, deepfake-image-driven social engineering, automation of human-targeted attacks.

57

aatmf-t14-infra-warfare

packages/decepticon/decepticon/skills/plugins/llm-redteam/t14-infra-warfare/SKILL.md

AATMF T14 — Infrastructure & Economic Warfare. Endpoint DoS via expensive prompts, model-API account exhaustion, GPU resource starvation, billing weaponization.

64

aatmf-t13-supply-chain

packages/decepticon/decepticon/skills/plugins/llm-redteam/t13-supply-chain/SKILL.md

AATMF T13 — AI Supply Chain & Artifact Trust. Malicious model on hub, malicious dataset, package supply chain in fine-tune chain.

56

aatmf-t12-rag-poisoning

packages/decepticon/decepticon/skills/plugins/llm-redteam/t12-rag-poisoning/SKILL.md

AATMF T12 — RAG & Knowledge Base Manipulation. PoisonedRAG, vector store flood, embedding collision, retrieval-bias attacks.

57

aatmf-t11-agentic-exploit

packages/decepticon/decepticon/skills/plugins/llm-redteam/t11-agentic-exploit/SKILL.md

AATMF T11 — Agentic & Orchestrator Exploitation. MCP tool poisoning, agent-to-agent prompt injection, tool-result spoofing, orchestrator state confusion.

60

aatmf-t10-confidentiality-breach

packages/decepticon/decepticon/skills/plugins/llm-redteam/t10-confidentiality-breach/SKILL.md

AATMF T10 — Integrity & Confidentiality Breach. System prompt extraction, training-data extraction, model-weight leakage, private-key recovery.

56

aatmf-t09-multimodal

packages/decepticon/decepticon/skills/plugins/llm-redteam/t09-multimodal/SKILL.md

AATMF T9 — Multimodal & Cross-Channel. Image steganography → text exec, audio prompt injection, video frame inject, document-with-hidden-text.

57

aatmf-t08-deception

packages/decepticon/decepticon/skills/plugins/llm-redteam/t08-deception/SKILL.md

AATMF T8 — External Deception & Misinformation. Misinfo generation at scale, persona impersonation, document fabrication, hallucination weaponization.

60

aatmf-t07-output-exfil

packages/decepticon/decepticon/skills/plugins/llm-redteam/t07-output-exfil/SKILL.md

AATMF T7 — Output Manipulation & Exfiltration. Covert channels in output, schema break, exfil via image gen, side-channel via timing.

53

aatmf-t06-training-poisoning

packages/decepticon/decepticon/skills/plugins/llm-redteam/t06-training-poisoning/SKILL.md

AATMF T6 — Training & Feedback Poisoning. Data poisoning, RLHF reward hacks, fine-tune-time exfil, embedding poisoning.

64

aatmf-t05-api-exploitation

packages/decepticon/decepticon/skills/plugins/llm-redteam/t05-api-exploitation/SKILL.md

AATMF T5 — Model & API Exploitation. Rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation.

60

aatmf-t04-memory-manipulation

packages/decepticon/decepticon/skills/plugins/llm-redteam/t04-memory-manipulation/SKILL.md

AATMF T4 — Multi-Turn & Memory Manipulation. Persistent memory injection, conversation-state poisoning, cross-session contamination, ghost-context leak.

55

aatmf-t03-reasoning-exploit

packages/decepticon/decepticon/skills/plugins/llm-redteam/t03-reasoning-exploit/SKILL.md

AATMF T3 — Reasoning & Constraint Exploitation. System prompt override, constraint negation, role-reversal, instruction conflict exploit.

52

aatmf-t02-linguistic-evasion

packages/decepticon/decepticon/skills/plugins/llm-redteam/t02-linguistic-evasion/SKILL.md

AATMF T2 — Semantic & Linguistic Evasion. Foreign-language pivot, encoded payloads, esolang, fictional framing, jailbreak via translation.

68

aatmf-t01-prompt-injection

packages/decepticon/decepticon/skills/plugins/llm-redteam/t01-prompt-injection/SKILL.md

AATMF T1 — Prompt & Context Subversion. Direct + indirect prompt injection, ASCII smuggling, payload-in-image, prompt-leaking via reflection.

62

benchmark

packages/decepticon/decepticon/skills/benchmark/SKILL.md

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

58

decepticon

integrations/agent-skills/decepticon/SKILL.md

Drive Decepticon — an autonomous multi-agent red-team framework — over MCP to run authorized penetration tests and bug-bounty engagements end to end, then watch and steer them live from chat. Launch an engagement against a target, poll its transcript to narrate progress, send messages to refocus it, and pull findings as SARIF. Use when the user asks to run a pentest/red-team engagement, hunt a bug bounty, do recon, exploit/scan a host, web app, API, network, cloud, Active Directory, mobile app, or smart contract WITH Decepticon — or to check/resume a running engagement or report what Decepticon found. Triggers: run a decepticon engagement, pentest this with decepticon, bug bounty, recon this target, red team this, scan this host, resume the engagement, what did decepticon find, decepticon status. Do NOT use for ad-hoc local tool runs (running nmap/sqlmap/ffuf directly) when no Decepticon server is involved — this drives the Decepticon orchestrator, not raw tools.

75