CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wifi

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC randomization defeat, BLE/Zigbee/IEEE 802.15.4 sidebands, and Wi-Fi 6/6E/7 considerations. Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-organized offensive Wi-Fi reference with executable commands across the full attack lifecycle. Its main gaps are progressive disclosure (all content inline, no bundle files) and the lack of an explicit validate-retry feedback loop in the engagement cheatsheet.

Suggestions

Move peripheral sections (Sidebands & Adjacent Wireless, Wi-Fi 6/6E/7 Considerations, Detection / Defender View, RADIUS Backend Pivots) into separate reference files under references/ linked from SKILL.md, keeping the body as an overview + core workflow.

Add an explicit validate->fix->retry feedback loop to the Engagement Cheatsheet (e.g. 'Verify handshake with hcxpcapngtool; if no EAPOL frames, re-deauth and re-capture' before cracking).

Trim minor explanatory asides that restate what the command does, since the commands are self-explanatory to a competent operator.

DimensionReasoningScore

Conciseness

The body is command-dense and mostly assumes domain competence, but contains minor explanatory asides ('Triggers heavy crypto on AP CPU; can DoS lower-end deployments', 'Most modern APs lock out after a few failures — slow and noisy') that could be trimmed; length reflects breadth of attack classes covered, not padding.

4 / 5

Actionability

Provides copy-paste-ready, executable commands throughout (airmon-ng, airodump-ng, aireplay-ng, hcxpcapngtool, hashcat, eaphammer, reaver, hostapd-mana, mdk4) plus concrete tool tables covering the common cases.

5 / 5

Workflow Clarity

A 'Quick Workflow' (5 steps) and a numbered 'Engagement Cheatsheet' (7 steps) give a clear sequence with some verification moments ('Verify monitor + injection', 'Verify the EAPOL frames are usable', 'Targeted capture if PMKID empty'), but the main cheatsheet lacks an explicit validate->fix->retry feedback loop. Validation is present rather than missing, so the destructive/batch cap does not apply; it sits just below 5.

4 / 5

Progressive Disclosure

The body is well-structured with clear section headers and tables, but everything is inlined into a single ~340-line SKILL.md with no separate reference files (none of references/, scripts/, assets/ exist), so peripheral topics that could be split out are inline. Good section organization prevents a 2; absence of any one-level-deep reference split keeps it at 3.

3 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, highly specific description that clearly states what the skill does and when to use it, with minimal conflict risk. Its only weak spot is trigger-term breadth, where a few natural synonyms a user might actually say are missing.

Suggestions

Add common natural synonyms users may say verbatim, e.g. 'WiFi hacking', 'rogue AP / evil twin', or 'wireless security testing', to broaden trigger coverage.

Consider trimming the long technique enumeration slightly so the description stays scannable without losing specificity.

DimensionReasoningScore

Specificity

Enumerates many concrete attack classes ('handshake capture and PMKID attacks', 'SAE downgrade and Dragonblood', 'MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS', 'WPS Pixie Dust', 'rogue AP construction (hostapd-mana)') rather than vague language, giving comprehensive coverage.

5 / 5

Completeness

It explicitly answers both 'what' (the full attack methodology and technique list) and 'when' ('Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation') with concrete trigger phrases.

5 / 5

Trigger Term Quality

The trigger clause 'Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation' plus 'red team engagements' gives good natural keyword coverage, but a few common synonyms users might say (e.g. 'WiFi hacking', 'rogue AP', 'evil twin') are not present.

4 / 5

Distinctiveness Conflict Risk

It carves a clear niche (offensive 802.11 / wireless attacks) with distinct triggers that are unlikely to fire for unrelated skills, keeping conflict risk minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.