CtrlK
BlogDocsLog inGet started
Tessl Logo

red-team-engagement

Plan, scope, and execute an authorized red-team engagement — distinct from a penetration test. Covers engagement methodology, assumed-breach scenarios, ATT&CK emulation plans, rules of engagement, deconfliction with the blue team, post-engagement debriefs, and the program-level work that makes red teams actually improve defenses. Use when the user mentions 'red team,' 'red team engagement,' 'red teaming,' 'adversary emulation,' 'ATT&CK emulation,' 'assumed breach,' 'purple team exercise,' 'tabletop with technical execution,' 'red team scope,' 'rules of engagement,' 'red team RoE,' 'deconfliction,' 'red team debrief,' or wants to design or run a red-team engagement against systems with authorization.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable methodology skill with a clearly sequenced multi-phase lifecycle and strong validation checkpoints for a high-risk operation. Conciseness and progressive disclosure are good rather than excellent due to occasional meta-commentary and the absence of separate reference files for large inline templates.

Suggestions

Trim meta-commentary lines ('most dual-use skill in this catalog', 'most consequential boundaries section… Read it', 'A red team that finds the same problem twice…') to tighten the token budget.

Move the full report template and the Rules of Engagement table into separate reference files (e.g. references/report-template.md, references/roe-template.md) referenced one level deep from the body to improve progressive disclosure.

Add a brief concrete example or worked snippet for Phase 2 execution (e.g., a sample assumed-breach objective-to-technique mapping) to lift actionability from mostly-executable to fully copy-paste ready.

DimensionReasoningScore

Conciseness

Mostly efficient, domain-specific operational guidance that assumes Claude's competence, with only minor meta-commentary ('most dual-use skill in this catalog', 'most consequential boundaries section… Read it', the closing aphorism) that could be trimmed; not a 5 because a few lines do not strictly earn their tokens.

4 / 5

Actionability

Provides a concrete 7-item authorization checklist, scoping field list, RoE table, and a copy-paste report template with named emulation-plan sources and URLs; falls just short of 5 because the execution phase (Phase 2) delegates concrete technique to other skills rather than giving executable steps itself.

4 / 5

Workflow Clarity

Phases 0–4 are clearly sequenced with timeframes, deliverables, and explicit validation checkpoints (the mandatory authorization gate, stop/pause conditions, deconfliction feedback loops, and checklists) — the destructive-operation cap does not apply because validation is prominent throughout.

5 / 5

Progressive Disclosure

Well-organized single-file structure with clear section headers, tables, and a clearly signaled external References list; not a 5 because no bundle files exist and content such as the report template and RoE detail could be offloaded into separate reference files.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that comprehensively states capabilities, supplies abundant natural trigger terms with synonyms, and explicitly disambiguates the skill from adjacent pentest/threat-hunting skills. Both the 'what' and 'when' are clearly and concretely answered.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — plan, scope, execute, assumed-breach scenarios, ATT&CK emulation plans, rules of engagement, deconfliction, debriefs, and program-level improvement work — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both 'what' (plan, scope, and execute an authorized red-team engagement) and 'when' via a 'Use when the user mentions…' clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive set of natural trigger phrases with synonyms ('red team', 'red teaming', 'red team engagement', 'adversary emulation', 'ATT&CK emulation', 'assumed breach', 'purple team exercise', 'rules of engagement', 'red team RoE', 'deconfliction', 'red team debrief') that users would naturally say.

5 / 5

Distinctiveness Conflict Risk

Explicitly disambiguates from penetration testing ('distinct from a penetration test') and carves a clear niche with distinct triggers, minimizing conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.