CtrlK
BlogDocsLog inGet started
Tessl Logo

red-team-tactics

Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.

54

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/red-team-tactics/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is a well-structured, terse reference of red-team principles organized by MITRE ATT&CK phases, but it reads as an encyclopedic listing of widely-known concepts rather than focused, executable, non-obvious guidance with validation checkpoints.

Suggestions

Replace restatements of standard ATT&CK phase definitions with non-obvious operational guidance Claude would not already know, and add concrete commands or tool examples for the checks listed.

Add an explicit multi-step engagement workflow with validation checkpoints (e.g., confirm scope before action, verify foothold before lateral movement, validate findings before reporting) to support the destructive/risky operations described.

Move the detailed per-technique tables into a separate reference file and keep SKILL.md as a concise overview that links out one level deep.

DimensionReasoningScore

Conciseness

The body is mostly lean tables with no padded prose, but it encyclopedically restates standard MITRE ATT&CK phase definitions and well-known privesc/evasion checks that Claude already knows, so not every token earns its place.

2 / 3

Actionability

Tables name concrete checks and opportunities (SeDebug, SUID binaries, Kerberoasting, LOLBins) but provide no executable commands, tooling, or step-by-step how-to, leaving guidance descriptive rather than instructive.

2 / 3

Workflow Clarity

An attack lifecycle diagram and a 4-step reporting narrative give a sequence, but there are no validation checkpoints or feedback loops for the risky operations (exploitation, lateral movement, exfiltration) the skill describes.

2 / 3

Progressive Disclosure

The content is organized into 10 clearly titled sections with no nested references, but at ~150 lines it is a single monolithic file with all material inline and no progressive split, exceeding the simple-skill threshold that would let structure alone earn a 3.

2 / 3

Total

8

/

12

Passed

Description

75%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The frontmatter is concise, third-person, and clearly scoped to a distinct red-team/MITRE ATT&CK niche with explicit when-to-use guidance. It is held back from top marks by category-level rather than concrete action wording and somewhat technical trigger phrasing.

Suggestions

Expand the description with concrete actions (e.g., 'Plan attack chains, select initial-access vectors, evade detection, and write findings reports') instead of category labels.

Add user-natural trigger phrasings such as 'pentest', 'adversary emulation', or 'security assessment' alongside the current technical terms.

DimensionReasoningScore

Specificity

The description names the domain and three action areas ('Attack phases, detection evasion, reporting') but these are category-level labels rather than the multiple concrete, granular actions the top anchor expects.

2 / 3

Completeness

The frontmatter answers both 'what' (description: red team tactics principles based on MITRE ATT&CK) and 'when' (when_to_use: 'When performing penetration testing, red team exercises...'), providing explicit trigger guidance.

3 / 3

Trigger Term Quality

The when_to_use field includes relevant natural terms ('penetration testing', 'red team exercises', 'MITRE ATT&CK') but leans technical ('evaluating attack surfaces') and misses common phrasings a user might actually say.

2 / 3

Distinctiveness Conflict Risk

The MITRE ATT&CK / red-team niche is specific with distinct triggers ('red team exercises', 'penetration testing'), making it unlikely to fire for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
vudovn/ag-kit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.