CtrlK
BlogDocsLog inGet started
Tessl Logo

wpa2-psk

WPA/WPA2-PSK handshake capture via targeted deauth + PMKID (no deauth required) + offline hashcat cracking. The most common consumer/SMB encryption mode in 2026.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/wireless/wpa2-psk/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is exemplary in conciseness and actionability with strong workflow sequencing and validation gates (ZFP, PMKID fallback, PMF handling), but the progressive disclosure score is pulled down because both referenced files in the References section are missing from the bundle, breaking the signaled navigation.

Suggestions

Add the referenced bundle files references/vendor-generators.md and references/wpa3-transition-mode-notes.md so the documented one-level-deep navigation actually resolves.

Add an inline validation checkpoint before the deauth send (e.g., confirm the engagement's permitted_actions explicitly allow targeted deauth and that a client MAC is associated) to close the destructive-step validation gap.

Make the broken-link risk explicit or inline the minimal vendor-generator install hints until the reference files exist, so the skill remains navigable without the missing references.

DimensionReasoningScore

Conciseness

The body is lean: every line is either a runnable command, a tool/flag, or a terse operational note, with no padding explaining what Wi-Fi, PMKID, or hashcat are; it assumes Claude's competence throughout.

5 / 5

Actionability

Both acquisition paths and the vendor-PSK table provide copy-paste-ready commands with exact flags and output paths, and the evidence section gives an executable kg_add_node snippet, fully covering the common cases.

5 / 5

Workflow Clarity

Each path is clearly numbered and sequenced with explicit checkpoints (PMKID empty -> fall back to Path B; confirm WPA handshake in airodump header; both-evidence ZFP gate), but the destructive deauth step relies on RoE context rather than an inline validate-before-send checkpoint, leaving a minor validation gap.

4 / 5

Progressive Disclosure

Structure is good with a tight overview and a one-level References section, but both referenced files (vendor-generators.md, wpa3-transition-mode-notes.md) do not exist in the bundle, so the signaled references are broken navigation rather than a usable split.

3 / 5

Total

17

/

20

Passed

Description

68%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and highly trigger-rich with strong distinctiveness, but it lacks an explicit 'Use when...' clause in the description text itself (trigger guidance is relegated to metadata), which caps completeness at 3.

Suggestions

Append an explicit 'Use when...' clause to the description text naming the natural trigger scenarios (e.g., 'Use when cracking WPA/WPA2-PSK networks, capturing four-way handshakes or PMKIDs, or running hashcat mode 22000').

Move at least one or two of the most common user-facing trigger phrases from the metadata when_to_use field into the description body itself so the trigger guidance is self-contained.

Consider trimming the editorial aside 'The most common consumer/SMB encryption mode in 2026.' as it is context-fluff that does not aid trigger matching.

DimensionReasoningScore

Specificity

The description lists several concrete actions ('handshake capture', 'targeted deauth', 'PMKID', 'offline hashcat cracking') but ties them to a single acquisition mode rather than enumerating broader capability variants, leaving minor coverage gaps.

4 / 5

Completeness

The 'what' is explicit (handshake capture and offline cracking), but there is no 'Use when...' clause and the trigger guidance lives only in frontmatter metadata rather than the description text, so per rubric guidance completeness is capped at 3.

3 / 5

Trigger Term Quality

Natural trigger terms appear densely ('WPA2-PSK', 'WPA-PSK', 'PMKID', 'PSK crack', 'four-way handshake', 'hashcat 22000', 'hcxdumptool'), covering the vocabulary a user would actually invoke when needing this skill.

5 / 5

Distinctiveness Conflict Risk

The niche is sharply defined (WPA/WPA2-PSK, PMKID, hashcat 22000) and explicitly distinguishes from WPA3-SAE, giving it clear triggers with minimal overlap risk against adjacent wireless skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

referenced_paths_exist

Referenced path issues: 2 missing

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.