CtrlK
BlogDocsLog inGet started
Tessl Logo

krack-fragattacks

KRACK key-reinstallation (CVE-2017-13077..13082) and FragAttacks fragmentation/aggregation flaws (CVE-2020-24586..24588, CVE-2020-26139..26147) against legacy or embedded 802.11 supplicants with poor patch cadence.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/wireless/krack-fragattacks/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable operational playbook with concrete executable commands, clear pre/post-test checkpoints, and clean sectioning. Its main weaknesses are minor redundancy in patch-state info across sections and a long single-file layout that could offload some CVE/vendor detail to reference files.

Suggestions

De-duplicate patch-state information between the viability-gate blockquote and the per-vendor residual-exposure notes, or have one reference the other.

Consolidate the repeated `--bssid/--ssid/--psk` argument pattern in the fragattacks examples (e.g., define once, then show only the varying subcommand) to tighten token use.

Consider moving the per-vendor residual-exposure notes and full CVE maps into a bundled reference file, keeping SKILL.md as the overview plus quick-start commands.

DimensionReasoningScore

Conciseness

Largely lean operational prose with executable commands and tight tables; assumes Claude's competence without explaining basic Wi-Fi concepts. Minor redundancy between the viability-gate patch states and the per-vendor residual-exposure notes, and the version-number-heavy blocks could be slightly tightened, keeping it just below a 5.

4 / 5

Actionability

Copy-paste-ready, fully executable commands throughout — airodump-ng/tshark recon, git clone + pip + make build steps, and concrete `krack-test-client.py` and `fragattacks.py` invocations with named subcommands (ping-frag-plaintext, ping-amsdu, eapol-inject) mapped to specific CVEs covering the common cases.

5 / 5

Workflow Clarity

A clear pre-test 'Scope-viability assessment (run before any active test)' checkpoint and a post-test 'Confirming a successful attack' validation step (nonce-reuse detection, [SUCCESS]/[FAILED] output, pcap evidence) give good checkpoint structure. It is not a single end-to-end numbered sequence across both vulnerability families, leaving minor sequencing gaps versus a 5.

4 / 5

Progressive Disclosure

Well-organized into clear ## sections (viability gate, KRACK family, FragAttacks family, per-vendor notes, evidence, ZFP, OPSEC, references) with no nested references, and a clearly signaled References block. No bundle files exist, and the long inline CVE maps / per-vendor tables could plausibly be split into reference files, so it stops at good structure rather than ideal content splitting.

4 / 5

Total

17

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a precise, distinctive scope statement anchored by concrete CVE identifiers and a specific target class, but it omits any 'Use when...' trigger guidance and lists no explicit action verbs, which caps completeness and limits specificity.

Suggestions

Add an explicit trigger clause, e.g. 'Use when assessing unpatched legacy or embedded Wi-Fi supplicants for KRACK or FragAttacks exposure.'

Lead with concrete action verbs ('Tests for', 'Validates', 'Exploits') rather than a pure noun-phrase scope statement.

Include common-synonym trigger terms such as 'Wi-Fi', 'WPA2', and '802.11 supplicant testing' alongside the CVE numbers.

DimensionReasoningScore

Specificity

Names the domain with concrete CVE enumerations ('CVE-2017-13077..13082', 'CVE-2020-24586..24588, CVE-2020-26139..26147') and a specific target class ('legacy or embedded 802.11 supplicants with poor patch cadence'), but as a noun-phrase scope statement it lists no concrete action verbs, so it stops at naming the domain precisely without describing actions.

3 / 5

Completeness

Gives a clear 'what' (the two vulnerability families against legacy/embedded supplicants) but includes no 'Use when...' or equivalent explicit trigger clause; per the guidelines a missing explicit trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

Strong natural-domain keywords ('KRACK key-reinstallation', 'FragAttacks', 'fragmentation/aggregation flaws', explicit CVE numbers) that a wireless tester would actually say; missing broader synonyms like 'Wi-Fi' or 'WPA2' that users might also invoke, so just short of comprehensive.

4 / 5

Distinctiveness Conflict Risk

A clear niche defined by named CVE families and a narrow target class (legacy/embedded 802.11 supplicants with poor patch cadence), making it highly distinguishable with minimal risk of triggering for the wrong skill.

5 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.