CtrlK
BlogDocsLog inGet started
Tessl Logo

red-team

Use when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations. Covers MITRE ATT&CK kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting.

65

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/red-team/SKILL.md

The canonical home for this skill is red-team in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, action-oriented skill body with strong command examples and clear workflows, undermined by references to bundle files (engagement_planner.py, attack-path-methodology.md) that are not actually present. Structure is good but the broken references and inlined reference-heavy content limit progressive disclosure.

Suggestions

Ship the referenced bundle files — create scripts/engagement_planner.py and references/attack-path-methodology.md — or remove the references and inline only what is needed so signaled paths resolve to real files.

Move the large reference tables (Technique Scoring Reference, Common Choke Points, Crown Jewel Classification) into references/attack-path-methodology.md and keep SKILL.md as a concise overview, improving progressive disclosure and token efficiency.

Add an explicit validation/feedback checkpoint to the multi-week workflow (e.g., 'verify detection events logged before advancing to the next phase') to strengthen workflow clarity for a destructive-domain operation.

DimensionReasoningScore

Conciseness

Largely lean and efficient — dense reference tables and concrete commands that assume Claude's knowledge (no padding explaining what MITRE ATT&CK or LSASS is), with only minor sections like the distinction table that could be trimmed.

4 / 5

Actionability

Provides concrete, copy-paste-ready bash commands with full flag examples and an exit-code table, but the primary executable `scripts/engagement_planner.py` is referenced yet not present in the bundle, so commands are not actually runnable as-is.

4 / 5

Workflow Clarity

Three clearly sequenced workflows with checkpoints (the OPSEC checklist before each phase, the `--authorized` exit-code gate, and the Workflow 1 'Decision' step), though the multi-week workflow lacks explicit validate-before-proceeding feedback loops.

4 / 5

Progressive Disclosure

Has a TOC, clear section headers, and signaled one-level references to `references/attack-path-methodology.md`, but that file and `scripts/engagement_planner.py` do not exist in the bundle, so the signaled deep-dive targets are missing and extensive reference tables are inlined in SKILL.md.

3 / 5

Total

15

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that clearly states both purpose and trigger conditions with concrete, domain-specific actions. Minor room to add a few more natural synonyms and tighten distinctiveness from pen-testing.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting' — plus 'attack path analysis' and 'offensive security simulations', giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both: what it does ('Covers MITRE ATT&CK kill-chain planning, technique scoring...') and when to use it ('Use when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations').

5 / 5

Trigger Term Quality

Includes natural phrases a user would say ('red team engagements', 'attack path analysis', 'offensive security simulations', 'MITRE ATT&CK') but misses some common variations like 'adversary simulation', 'assumed breach', or 'purple team'.

4 / 5

Distinctiveness Conflict Risk

'Red team engagements' and 'attack path analysis' carve a clear niche with distinct triggers, but 'offensive security simulations' is broad enough to create minor overlap risk with the closely related security-pen-testing skill.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 suspicious

Warning

referenced_paths_exist

Referenced path issues: 10 missing

Warning

Total

14

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.