CtrlK
BlogDocsLog inGet started
Tessl Logo

building-red-team-c2-infrastructure-with-havoc

Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure for authorized red team operations. Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary emulation engagement.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-red-team-c2-infrastructure-with-havoc/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers strong operational detail — real build commands, a complete teamserver profile, and a working redirector config — but the workflow lacks validation checkpoints, and progressive disclosure is the weakest area: the skill ships three reference files plus scripts and assets that are never linked from SKILL.md while their content is partially duplicated inline. Tightening the padded overview/when-to-use sections would also improve token efficiency.

Suggestions

Replace the inline MITRE ATT&CK table and the multi-week deployment timeline details with clearly signaled one-level-deep links to references/standards.md and references/workflows.md (e.g., '## MITRE ATT&CK mapping: See [standards.md](references/standards.md)'), and add a navigation section listing references/api-reference.md, scripts/, and assets/template.md so the existing bundle is discoverable.

Add validation checkpoints after each risky step: verify the build with a version/teamserver startup check, confirm the listener with a curl to the redirector URI expecting the C2 response vs. the 301 fallback, and include expected output for Step 4 like the one already present in Step 3.

Trim the Overview paragraph (Havoc/Cobalt Strike background Claude already knows) and the four generic 'When to Use' boilerplate bullets down to the one bullet that is specific to this skill.

DimensionReasoningScore

Conciseness

The bulk is lean config and commands, but there is padding that could be trimmed: the Overview paragraph explains what Havoc is ('a modern, open-source post-exploitation command and control framework... similar to Cobalt Strike') which Claude already knows, the 'When to Use' section is four generic boilerplate bullets ('When establishing security controls aligned to compliance requirements'), and the MITRE ATT&CK table duplicates content already in references/standards.md. This fits 'Mostly efficient but includes some unnecessary explanation or could be tightened' — below level 4 because of the multiple padded sections, above level 2 because the operational steps themselves are not verbose.

3 / 5

Actionability

The content is largely copy-paste ready: complete apt install and make build commands, a full havoc.yaotl profile, a complete nginx redirector config, and concrete Demon command examples. It falls short of the top anchor only in minor gaps — Step 5 is GUI instructions rendered as comments rather than executable commands, and some Demon examples carry unfilled placeholders ('token steal <PID>', 'TEAMSERVER_IP').

4 / 5

Workflow Clarity

Steps 1–6 give a clear install → configure → start → redirector → payload → post-exploitation sequence, but validation is mostly absent: only Step 3 shows expected output, and there are no checkpoints for verifying the build succeeded, the listener is reachable, or the redirector forwards correctly, nor any fix-and-retry guidance. This matches 'Steps listed but validation gaps; sequence present but checkpoints missing or implicit'.

3 / 5

Progressive Disclosure

The bundle contains references/api-reference.md, references/standards.md, references/workflows.md, scripts/, and assets/, but the body never references any of them (grep confirms zero mentions of references/, scripts/, or assets/). Worse, the body inlines content that duplicates the bundle — the MITRE ATT&CK mapping table restates references/standards.md and the step-by-step deployment restates references/workflows.md — so content that clearly belongs in separate files is inlined and the existing references are undiscoverable. This fits 'Minimal structure; content that clearly belongs in separate files is inlined; or references are buried'; it does not reach level 3 because there are no signaled references at all, despite the body's own section headers being reasonable.

2 / 5

Total

12

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names concrete components and actions, gives an explicit 'Use when' trigger clause tied to authorized engagements, and occupies a distinct niche (Havoc specifically). The only minor improvement is adding a few more natural synonym phrases users might say, such as 'command and control server' or 'C2 infrastructure'.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions and components — 'Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure' — which is comprehensive coverage of the skill's capabilities. It matches the anchor 'Lists multiple specific concrete actions; comprehensive coverage' and does not fall below since nothing important to the skill's scope is omitted.

5 / 5

Completeness

It explicitly answers both questions: the 'what' is the full deploy/configure capability list, and the 'when' is the concrete trigger clause 'Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary emulation engagement'. This matches the top anchor with explicit trigger phrases and is clearly above the level-4 anchor where the 'when' is less specific.

5 / 5

Trigger Term Quality

Natural trigger terms are strong: 'Havoc C2', 'red team operations', 'adversary emulation', 'standing up or hardening Havoc C2 infrastructure'. A few natural phrasings a user might say are missing (e.g., 'command and control server', 'C2 infrastructure', 'redirector setup'), so it sits at 'Good keyword coverage; a few natural terms missing' rather than the comprehensive-synonyms anchor above.

4 / 5

Distinctiveness Conflict Risk

The description names a specific framework (Havoc, Demon agent) and a specific engagement type (written, authorized adversary emulation), giving it a clear niche with distinct triggers and minimal overlap with generic red-team or infrastructure skills. It clearly fits the 'Clear niche with distinct triggers; minimal conflict risk' anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.