CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-cyber-kill-chain

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases. Activates for requests involving kill chain analysis, intrusion kill chain, attack phase mapping, or Lockheed Martin kill chain framework.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/analyzing-cyber-kill-chain/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured analytical workflow with concrete indicators and a clear five-step process, weakened by re-explaining concepts Claude already knows and by failing to surface the bundled reference and script files. Linking the bundle and trimming redundant definitions would lift the weaker dimensions.

Suggestions

Link the existing bundle files from the body (e.g., 'See [references/api-reference.md](references/api-reference.md) for the full phase/COA/ATT&CK tables' and 'See [scripts/agent.py](scripts/agent.py) for a working analysis agent') and move the duplicated phase-to-ATT&CK table out of the body to improve progressive_disclosure.

Trim the per-phase descriptive sentences and the Key Concepts table that restate common kill-chain knowledge Claude already has, keeping only the indicator lists and the COA/report structure, to improve conciseness.

Add explicit validation/feedback checkpoints to the workflow (e.g., 'After mapping, verify every observed artifact is assigned to exactly one phase; if a phase has no evidence, confirm it was not achieved rather than leaving it blank') to strengthen workflow_clarity.

DimensionReasoningScore

Conciseness

The body re-explains the seven kill chain phases and a Key Concepts table ('Kill Chain', 'Beaconing', 'Intelligence Gain/Loss') that Claude largely already knows; mostly efficient but includes unnecessary explanatory padding.

3 / 5

Actionability

Provides concrete per-phase indicators, an example phase matrix, ATT&CK tactic mappings, and a six-COA framework; actionable for an analytical skill but lacks copy-paste-ready code or commands.

4 / 5

Workflow Clarity

Five clearly sequenced steps (Map phases -> Identify completion/detection -> Map to ATT&CK -> COAs -> Report) with an example matrix; minor gaps in explicit validation checkpoints and feedback loops.

4 / 5

Progressive Disclosure

Body is sectioned, but the phase-to-ATT&CK table is duplicated inline and the existing bundle files (references/api-reference.md, scripts/agent.py) are never referenced or linked from the body, so references are not clearly signaled.

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and clearly scoped to the Cyber Kill Chain niche with explicit 'Use when...' trigger guidance and natural trigger terms. Minor room to expand the action list and add a few more synonyms for a perfect score.

DimensionReasoningScore

Specificity

Lists several concrete actions ('identify which phases an adversary has completed', 'where defenses succeeded or failed', 'what controls would have interrupted the attack at earlier phases'); not a 5 because the action list is not maximally comprehensive.

4 / 5

Completeness

Explicitly answers both 'what' (analyzes intrusion activity to identify completed phases and control gaps) and 'when' ('Use when conducting post-incident analysis...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural-term coverage ('kill chain analysis', 'intrusion kill chain', 'attack phase mapping', 'Lockheed Martin kill chain framework', 'post-incident analysis'); a few synonyms/extensions missing, so it sits above the midpoint rather than at 5.

4 / 5

Distinctiveness Conflict Risk

Clearly scoped to the Lockheed Martin Cyber Kill Chain niche with distinct triggers ('Lockheed Martin kill chain framework', 'attack phase mapping'), minimizing conflict with adjacent skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.