CtrlK
BlogDocsLog inGet started
Tessl Logo

wireless-hardware-attack

无线/硬件:WiFi PMKID/WPS/Evil Twin,BLE,Zigbee,NFC,SDR,UART/JTAG/SPI,侧信道,故障注入。Use when attacking WiFi, BLE, RFID, SDR, or hardware interfaces.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/wireless-hardware-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

55%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An extremely token-efficient tool index that pairs each wireless/hardware attack technique with its canonical tooling, but it functions as a lookup table rather than actionable guidance. Executable command examples and even minimal step ordering with validation checkpoints would raise it substantially.

Suggestions

Add one concrete, executable command sequence per major attack (e.g., the hcxdumptool capture then hashcat crack workflow for PMKID, or an aircrack-ng handshake crack), since the body currently names tools without any runnable commands.

Provide minimal step ordering with validation checkpoints for the inherently multi-step attacks (capture → verify capture → crack), rather than compressing each into a single phrase.

Replace the single pipe-delimited code block with labeled sections (WiFi, BLE, Zigbee, NFC/RFID, SDR, hardware) so each attack family is scannable and extensible.

DimensionReasoningScore

Conciseness

Every line is a dense tool/technique pointer ('aircrack-ng/PMKID(hcxdumptool+hashcat)/WPS reaver', 'proxmark3克隆/MIFARE mfoc') with zero padding and no explanation of concepts Claude already knows.

5 / 5

Actionability

The body maps each attack category to tool names but provides no executable commands, flags, or usage examples — only 'binwalk -Me' is directly runnable — leaving the specific steps to execute missing.

2 / 5

Workflow Clarity

There is no sequence at all: inherently multi-step attacks like 'PMKID(hcxdumptool+hashcat)' (capture then crack) are compressed into a single phrase, and no validation or verification checkpoints appear anywhere.

2 / 5

Progressive Disclosure

The skill is under 50 lines with no bundle files, so a single self-contained file is appropriate, but everything is crammed into one pipe-delimited code block rather than organized, labeled sections.

4 / 5

Total

13

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A compact, specific description that clearly bounds the wireless/hardware attack domain and includes an explicit 'Use when' trigger clause. Its main limitation is keyword-list style capability naming rather than natural action phrases and a trigger list that omits common synonyms.

DimensionReasoningScore

Specificity

Lists many concrete techniques ('WiFi PMKID/WPS/Evil Twin', 'UART/JTAG/SPI', '侧信道,故障注入') with broad coverage, but they read as a keyword index rather than action statements, so it stops short of anchor 5.

4 / 5

Completeness

Both a what (the technique enumeration) and an explicit 'Use when...' clause are present; the when-statement stays at the domain level and could name concrete trigger phrases like PMKID, Evil Twin, or firmware extraction, keeping it below anchor 5.

4 / 5

Trigger Term Quality

'Use when attacking WiFi, BLE, RFID, SDR, or hardware interfaces' provides good natural keywords, but common variations like 'wireless', 'Bluetooth', 'IoT', or '802.11' are missing.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear wireless/hardware attack niche with distinct triggers, though WiFi attacks create minor overlap risk with a general network-penetration skill.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.