CtrlK
BlogDocsLog inGet started
Tessl Logo

building-c2-infrastructure-with-sliver-framework

Deploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulation framework) with multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard), redirectors, domain fronting, and multi-operator support for authorized red-team operations. Use when standing up resilient C2 for a red-team engagement or generating beacon/session implants that must survive blue-team detection.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/building-c2-infrastructure-with-sliver-framework/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

62%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands throughout and a clear phased workflow, but it is held back by inlined reference material that duplicates existing bundle files and by the absence of links to those references. Adding explicit navigation to the reference files and trimming redundant tables would raise both conciseness and progressive disclosure.

Suggestions

Replace the inlined MITRE ATT&CK, Tools, and Detection Signatures tables with one-line pointers to references/standards.md and references/api-reference.md so the body stays lean and navigation is explicit.

Link to references/workflows.md, scripts/agent.py, scripts/process.py, and assets/template.md from the relevant phases so the provided bundle is discoverable from SKILL.md.

Add inline validation checkpoints within each phase (e.g., verify listener is up before configuring redirectors) rather than only a final checklist, to make the destructive/batch infrastructure workflow self-correcting.

DimensionReasoningScore

Conciseness

The body is mostly efficient command-focused guidance, but sections like the Overview restate what Sliver is and the MITRE/tools/detection tables largely duplicate the frontmatter mappings and reference files, adding tokens Claude already knows.

3 / 5

Actionability

Provides concrete, copy-paste-ready bash and nginx snippets across all five phases (server install, listeners, redirectors, implant generation, post-exploitation), with only minor gaps such as placeholder IPs the operator must fill.

4 / 5

Workflow Clarity

Five clearly sequenced phases with an end-of-skill validation checklist; however, in-phase validation checkpoints are implicit (the checklist sits at the end rather than gating each phase) so it stops just short of explicit per-step validate-fix-retry loops.

4 / 5

Progressive Disclosure

Bundle files (references/api-reference.md, standards.md, workflows.md, scripts/, assets/template.md) exist but the SKILL.md body never links to or signals them, and substantial reference-style tables are inlined rather than offloaded to those files.

3 / 5

Total

14

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that answers both what the skill does and when to use it with concrete C2 terminology. It is comprehensive and clearly distinct from other skills, with only minor room for adding more everyday trigger synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Deploy and harden a Sliver C2 team server', 'multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard), redirectors, domain fronting, and multi-operator support', plus 'generating beacon/session implants' — giving comprehensive coverage.

5 / 5

Completeness

Clearly answers both 'what' (deploy/harden team server, listeners, redirectors, implants) and 'when' ('Use when standing up resilient C2 for a red-team engagement or generating beacon/session implants').

5 / 5

Trigger Term Quality

Includes strong natural phrases a user would say like 'standing up resilient C2', 'red-team engagement', and 'beacon/session implants', but leans on technical jargon over everyday synonyms and is missing common lay variations.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche — Sliver C2 infrastructure with specific protocols and redirectors — making it unlikely to trigger for unrelated skills, with minimal overlap risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.