CtrlK
BlogDocsLog inGet started
Tessl Logo

evil-twin-karma

Evil-twin rogue AP with KARMA/Mana PNL-probe response, captive-portal credential capture, and post-association MITM for PSK/open networks. Distinct from wpa-enterprise-eap which targets 802.1X.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/wireless/evil-twin-karma/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

83%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is exceptionally concise and actionable with strong command coverage, but as a destructive offensive operation it lacks explicit mid-workflow validation checkpoints and feedback loops, capping workflow clarity despite an otherwise excellent Step 1–6 structure.

Suggestions

Add explicit validation checkpoints between steps — e.g., after Step 2 confirm a client has associated to the rogue AP (check mana log / associated station) before issuing deauth or proceeding to portal capture.

Insert a feedback loop after portal/MITM capture: verify the credential was actually written (check mana_creds.txt / bettercap log) before recording evidence and tearing down.

Cross-link the deauth step more tightly to the deauth-pmf validation step (verify PMF state) as a precondition rather than a parenthetical note, to make the destructive-action gate explicit in-line.

DimensionReasoningScore

Conciseness

The body is lean and command-driven with no padding of concepts Claude already knows; every code block and comment (e.g., mana_loud semantics, portal-template list) earns its place.

5 / 5

Actionability

Provides copy-paste-ready hostapd-mana, dnsmasq, wifiphisher, and bettercap invocations with real flags and justified placeholders, covering the common open-AP, PSK-clone, portal, and MITM cases.

5 / 5

Workflow Clarity

Steps 1–6 are clearly sequenced and the top-level RoE gate is strong, but this destructive/offensive workflow lacks mid-process validation checkpoints and feedback loops (e.g., confirm client association before deauth, verify the portal was reached before declaring capture), which per the guidelines caps a destructive skill at 3.

3 / 5

Progressive Disclosure

Single-file skill with clear section headers and a one-level-deep References section pointing to sibling skills and external tools; no nested references and no bundle files to over-split, though some content (portal templates, MAC-randomization defeat) is inlined where a reference could be considered.

4 / 5

Total

17

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-distinguished from sibling skills, but it omits an explicit 'Use when...' trigger clause and pushes natural keywords into metadata rather than the description, capping completeness and trigger-term quality at the midpoint.

Suggestions

Add an explicit 'Use when...' clause to the description naming natural trigger phrases a user would say (e.g., 'Use when simulating an evil twin, standing up a rogue AP, or phishing Wi-Fi credentials via captive portal').

Surface a couple of user-facing synonyms in the description itself (e.g., 'rogue AP', 'Wi-Fi phishing', 'captive portal') rather than relegating all keywords to metadata.when_to_use.

Reconsider whether 'PNL' and 'Mana' belong in the lead description; consider a plainer phrasing that still signals the same capability to non-specialist users.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'PNL-probe response, captive-portal credential capture, and post-association MITM' — with comprehensive coverage of the evil-twin capability set, matching the top anchor.

5 / 5

Completeness

The 'what' is clear (evil-twin rogue AP plus its capabilities) but there is no explicit 'when/Use when' clause, which per the guidelines caps completeness at 3.

3 / 5

Trigger Term Quality

The description relies on technical jargon (KARMA, Mana, PNL) with no natural 'Use when...' phrasing; the natural user trigger terms are segregated into metadata.when_to_use rather than the description itself, leaving common variations unstated.

3 / 5

Distinctiveness Conflict Risk

Explicit disambiguation — 'Distinct from wpa-enterprise-eap which targets 802.1X' — carves a clear niche with minimal conflict risk against the closest sibling skill.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.