github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
windows-driver-assessment packages/decepticon/decepticon/skills/standard/reverser/windows-internals/SKILL.md Defensive Windows internals and driver exposure assessment for owner-authorized systems and disposable research VMs. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a04f96b | |
wireless-overview packages/decepticon/decepticon/skills/standard/wireless/SKILL.md Top-level index for the Decepticon 802.11 wireless attack suite. Routes the WirelessOperator to the correct leaf skill based on the target AP's crypto column (PSK / SAE / MGT / WPS) and engagement posture. BLE, Zigbee, Z-Wave, LoRaWAN, and sub-GHz live under iot/ by design — link provided below to prevent duplication. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
wireless-security packages/decepticon/decepticon/skills/standard/recon/wireless-security/SKILL.md Wireless network security reconnaissance — WiFi analysis, Bluetooth assessment, RFID/NFC evaluation, signal capture, protocol analysis, encryption testing, rogue device detection. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
wpa2-psk packages/decepticon/decepticon/skills/standard/wireless/wpa2-psk/SKILL.md WPA/WPA2-PSK handshake capture via targeted deauth + PMKID (no deauth required) + offline hashcat cracking. The most common consumer/SMB encryption mode in 2026. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
wpa3-sae packages/decepticon/decepticon/skills/standard/wireless/wpa3-sae/SKILL.md WPA3-SAE transition-mode downgrade (DragonShift), SSID Confusion CVE-2023-52424, Dragonblood side-channels, and SAE captive-portal credential recovery against WPA3-Personal networks. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
wpa-enterprise-eap packages/decepticon/decepticon/skills/standard/wireless/wpa-enterprise-eap/SKILL.md WPA/WPA2/WPA3-Enterprise (802.1X/EAP) rogue-RADIUS evil-twin for MSCHAPv2 capture, GTC downgrade, and PEAP relay. MSCHAPv2 capture equals a NetNTLM hash — the primary wireless on-ramp to Active Directory. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
wps-pixie-dust packages/decepticon/decepticon/skills/standard/wireless/wps-pixie-dust/SKILL.md WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
xpath-xslt packages/decepticon/decepticon/skills/standard/exploit/web/xpath-xslt/SKILL.md XPath + XSLT injection — query manipulation in XML data stores, server-side XSLT RCE via document() / EXSLT extensions. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
xs-leaks packages/decepticon/decepticon/skills/standard/exploit/web/xs-leaks/SKILL.md XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
xss packages/decepticon/decepticon/skills/standard/exploit/web/xss/SKILL.md Cross-Site Scripting (XSS) — reflected, stored, DOM-based XSS exploitation. Covers filter bypass, CSP evasion, bot-triggered cookie exfiltration, admin page scraping, and headless browser flag extraction. Use for any challenge involving client-side JavaScript injection, Cross payloads, cookie theft, or browser-based exploitation. | 71 71 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
xxe packages/decepticon/decepticon/skills/standard/analyst/xxe/SKILL.md Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls. | 57 57 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
zigbee-touchlink packages/decepticon/decepticon/skills/standard/iot/zigbee-touchlink/SKILL.md Touchlink commissioning abuse on Zigbee Light Link (ZLL) devices using the well-known ZLL transport key, ZCL command injection (toggle/move/step), network key extraction, and factory reset via touchlink. Toolchain covers KillerBee, zbstumbler, zbreplay, and Sonoff Zigbee 3.0 Dongle E running Wireshark live capture. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
z-wave packages/decepticon/decepticon/skills/standard/iot/z-wave/SKILL.md Z-Wave S0 network-key derivation flaw exploitation, S2 ECDH/DSK analysis, replay attacks against unauthenticated Z-Wave nodes, traffic capture with RTL-SDR, and active fuzzing/replay with EZ-Wave and Z-Force. Covers 868.42 MHz (EU) and 908.42 MHz (US) bands. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b |