CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wifi-recon

Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and structured airspace data capture for downstream attacks. Use at the start of any wireless engagement to build the target map before active attacks; covers 2.4 GHz, 5 GHz, and 6 GHz (Wi-Fi 6E) bands and adapter compatibility for each.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, command-rich recon methodology with a clear sequenced workflow and built-in verification of monitor mode and injection. The main improvement would be adding an explicit capture-completeness check before transitioning to active attacks.

Suggestions

Add an explicit validation step after the passive sweep (e.g., confirm the pcap/csv is non-empty and the target BSSID appears) before drilling down or moving to active attacks.

Trim the opening narrative paragraph and the regdomain prose to the essential facts to lift conciseness toward a 5.

Consider extracting the per-target data-fields table into a short reference snippet or checklist to further separate overview from reference material.

DimensionReasoningScore

Conciseness

Mostly lean with tables and copy-paste commands, assuming Claude's competence; a few narrative sentences (e.g., the opening paragraph and 'Setting the right regdomain unlocks legitimate channels...') could be trimmed.

4 / 5

Actionability

Provides fully executable, copy-paste-ready commands (airmon-ng, airodump-ng, aireplay-ng, iw, kismet, kismetdb_dump_devices) with clearly marked placeholders, covering the common recon cases.

5 / 5

Workflow Clarity

A clear numbered Quick Workflow and matching Engagement Cheatsheet with an explicit validation checkpoint ('Verify monitor mode + injection' / aireplay-ng --test) and an authorization gate on deauth; lacks an explicit capture-validity feedback loop before the active phase.

4 / 5

Progressive Disclosure

Well-organized into single-purpose sections with a clearly signaled one-level-deep 'Key References' list (external specs/docs) and no nested references; no bundle files exist, so all content is appropriately inline with minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that concretely enumerates capabilities and provides explicit trigger guidance for when to use the skill. Slight room to broaden natural-language synonyms, but overall highly actionable and distinct.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'adapter selection', 'monitor mode and packet injection setup', 'regulatory domain handling', 'hidden SSID discovery', 'BSSID/ESSID/channel/PMF/encryption fingerprinting', 'client probe analysis', 'vendor OUI lookup', 'war-driving with Kismet/airodump-ng/Wigle' — giving comprehensive coverage rather than vague language.

5 / 5

Completeness

Explicitly answers both 'what' (the enumerated recon actions) and 'when' ('Use at the start of any wireless engagement to build the target map before active attacks').

5 / 5

Trigger Term Quality

Includes natural terms a user would say ('Wi-Fi', 'wireless engagement', 'war-driving', 'Kismet', 'airodump-ng', 'Wigle'), but misses some common synonyms like 'wireless pentest', '802.11', or 'site survey'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear, narrow niche (pre-attack Wi-Fi airspace mapping) with distinct triggers and minimal overlap with other skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.