CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-evil-twin

Evil Twin / KARMA / Mana access point methodology — rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe response, Mana selective probe response, captive portal phishing, deauth-driven client coercion to attacker AP, MAC randomization defeat via PNL leak analysis, post-association MITM (DNS, ARP, transparent proxy), credential capture for portal/web/SMB, and detection-evasion tactics. Use to coerce client devices onto an attacker-controlled AP, intercept their traffic, harvest credentials, or deliver payloads via captive portal.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable offensive-wireless skill body with strong code coverage across all attack variants. Its main weakness is workflow clarity: the engagement workflow lacks explicit validation checkpoints for destructive operations, which the rubric caps at 3.

Suggestions

Add explicit validation/verification checkpoints to the Engagement Cheatsheet (e.g. confirm a client associated to the rogue AP before running the portal, verify credential capture succeeded before teardown) to lift workflow_clarity above the destructive-operations cap of 3.

Tighten or move the descriptive prose paragraphs (intro, 'Most users skim…', 'Beacons attract spontaneous association…') so the body leans even more on commands and tables.

Consider splitting the per-variant config details into a reference file linked from a concise overview to push progressive_disclosure toward 5.

DimensionReasoningScore

Conciseness

Mostly lean — tables, configs, and commands dominate — with a few explanatory prose paragraphs ('The classic captive portal at the airport attack pattern', 'Most users skim, don't read URLs') that could be trimmed but mostly earn their place.

4 / 5

Actionability

Provides concrete, mostly copy-paste-ready commands and configs across every variant (hostapd/dnsmasq, wifiphisher, airgeddon, eaphammer, mitmproxy, bettercap, hcxdumptool); minor gaps remain via placeholders like '<legitimate-BSSID>' and example PSKs.

4 / 5

Workflow Clarity

A clear sequenced workflow exists (Quick Workflow + Engagement Cheatsheet), but for destructive/offensive operations (deauth, credential harvesting) there are no explicit validation/verification checkpoints, capping this dimension at 3 per the rubric.

3 / 5

Progressive Disclosure

Single-file skill with well-organized sections, a variants table, and a clearly signaled one-level 'Key References' list; no nested references. Not a 5 because all variant detail is inlined rather than split into reference files.

4 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: dense, specific, third-person, with both a comprehensive capability enumeration and an explicit 'Use to...' trigger clause. It reads like the rubric's good-overall examples scaled to a specialized domain.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'rogue AP construction', 'KARMA universal probe response', 'Mana selective probe response', 'captive portal phishing', 'deauth-driven client coercion', 'MAC randomization defeat via PNL leak analysis', 'post-association MITM', 'credential capture', 'detection-evasion tactics' — with comprehensive coverage.

5 / 5

Completeness

Explicitly answers both 'what' (the enumerated methodology and capabilities) and 'when' via 'Use to coerce client devices onto an attacker-controlled AP, intercept their traffic, harvest credentials, or deliver payloads via captive portal.'

5 / 5

Trigger Term Quality

Natural user-facing terms are well covered with synonyms/variants — 'Evil Twin', 'KARMA', 'Mana', 'rogue AP', 'captive portal', 'deauth', 'phishing', 'credentials' — plus tool names a practitioner would name.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear, narrow niche (evil twin / KARMA / Mana wireless attacks) with distinct triggers; minimal overlap risk with unrelated skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.