CtrlK
BlogDocsLog inGet started
Tessl Logo

red-team-tactics

Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.

58

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/red-team-tactics/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, well-structured reference of red-team principles that respects token budget and assumes Claude's knowledge, but it is reference-oriented rather than execution-oriented: it lacks executable commands and validation-bearing engagement workflows. Adding concrete command examples and a validated engagement workflow would raise actionability and workflow clarity.

Suggestions

Add a short, sequenced engagement workflow with explicit validation/checkpoint steps (e.g. confirm scope -> execute phase -> verify detection gap -> document) to satisfy the destructive-operation feedback-loop requirement.

Sprinkle a few concrete, executable command examples for the highest-value checks (e.g. a BloodHound or Kerberoasting invocation) to move actionability toward copy-paste-ready.

Consider splitting the per-phase technique catalogs into a single one-level-deep reference file so SKILL.md can act as a tighter overview.

DimensionReasoningScore

Conciseness

The body is lean throughout — compact tables listing named techniques (LOLBins, Kerberoasting, SeDebug) with no padding and no explanation of what ATT&CK or red-teaming is, assuming Claude's competence so every token earns its place, matching anchor 5.

5 / 5

Actionability

As an instruction/principle skill it provides concrete, specific reference guidance (named checks, named attacks) rather than abstract direction, but it stops short of executable commands or how-to steps, leaving it just below the fully copy-paste-ready anchor 5.

4 / 5

Workflow Clarity

Section 8 lists a sequenced reporting narrative and detection-gap checklist, but for a destructive/batch-relevant domain there are no validation checkpoints or feedback loops in the engagement workflow, triggering the rubric's cap at 3.

3 / 5

Progressive Disclosure

Content is well-organized into ten clearly headed sections that are easy to navigate and self-contained with no nested references, though all detail is inlined rather than split into one-level-deep reference files, keeping it below anchor 5.

4 / 5

Total

16

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear niche and good trigger keywords but relies on topic labels rather than concrete actions and omits any 'Use when' trigger guidance from the description field itself. Adding explicit use-trigger phrasing and verb-based capabilities would lift completeness and specificity.

Suggestions

Rewrite the description with concrete actions ('Simulates adversary attack chains, maps detection gaps, reports findings') instead of topical noun phrases.

Add an explicit 'Use when...' clause directly in the description, e.g. 'Use when planning red team engagements or mapping techniques to MITRE ATT&CK.'

Include natural synonyms users say (pentest, ethical hacking, security assessment, adversary emulation) to broaden trigger coverage.

DimensionReasoningScore

Specificity

Quotes 'Red team tactics principles', 'Attack phases, detection evasion, reporting' name the domain and several topics, but these are topical buckets rather than concrete actions Claude performs, matching anchor 3 and falling short of the multiple specific actions needed for 4.

3 / 5

Completeness

A clear 'what' is present ('Red team tactics principles... phases, evasion, reporting') but the description has no 'Use when...' trigger clause — the when-guidance lives only in the separate when_to_use field — so per the rubric's cap it cannot exceed 3.

3 / 5

Trigger Term Quality

Natural terms a user would say appear ('red team tactics', 'MITRE ATT&CK', 'detection evasion'), giving good keyword coverage, but common synonyms like 'pentest' or 'ethical hacking' are missing, so it sits below the comprehensive anchor 5.

4 / 5

Distinctiveness Conflict Risk

The MITRE ATT&CK / red-team niche is clearly distinct with minimal conflict risk against unrelated skills, with only minor overlap against a general pentest/security skill, placing it above anchor 3 but not the pristine niche of 5.

4 / 5

Total

14

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
vudovn/ag-kit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.