CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wpa-enterprise

WPA/WPA2/WPA3-Enterprise (802.1X / EAP) attack methodology — EAP method identification (PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, EAP-GTC, EAP-PWD, EAP-FAST), evil-twin RADIUS attacks with eaphammer for credential capture, MSCHAPv2 challenge-response cracking, EAP-TLS client certificate theft paths (DPAPI, NDES, AD CS auto-enrollment), supplicant validation bypass (missing server cert validation, missing CN pinning, BYOD misconfigurations), and post-capture pivots into AD via cracked domain credentials. Use for corporate Wi-Fi engagements where the network is 802.1X authenticated.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concrete, executable attack runbook with a clear workflow and validation checkpoint. Main gaps are a redundant cheatsheet inflating length and the absence of failure-recovery loops and optional reference-file split-out.

DimensionReasoningScore

Conciseness

Largely lean and command-driven with little basic-concept padding, but the Engagement Cheatsheet repeats commands already shown in the sectioned body, which could be trimmed. Not a 5 because of that redundancy; not a 3 because the rest is efficient.

4 / 5

Actionability

Provides fully executable, copy-paste-ready commands across the common cases (tshark, airodump-ng, eaphammer, asleap, hashcat -m 5500, sscep enroll, nxc smb, bloodhound-python) with realistic flags and placeholders.

5 / 5

Workflow Clarity

A clear 5–6 step sequence (identify → evil-twin → capture → crack → validate → spray/enum → handoff) with an explicit 'Validate against AD' checkpoint before the subnet spray. Not a 5 because there is no error-recovery/feedback loop when validation or cracking fails.

4 / 5

Progressive Disclosure

Well-organized into clearly headed sections with one-level cross-skill references (offensive-active-directory, offensive-network, offensive-mobile) and no nested file chains; no bundle files exist to split further. Not a 5 because the ~200-line body is monolithic where some subtopics (EAP-TLS targets, detection) could live in reference files.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-triggered description that clearly conveys both capability and activation conditions for a narrow offensive-Wi-Fi domain. Minor synonym breadth keeps trigger_term_quality just short of perfect.

DimensionReasoningScore

Specificity

Lists multiple concrete attack actions — 'EAP method identification', 'evil-twin RADIUS attacks with eaphammer for credential capture', 'MSCHAPv2 challenge-response cracking', 'EAP-TLS client certificate theft paths (DPAPI, NDES, AD CS auto-enrollment)', 'supplicant validation bypass', and 'post-capture pivots into AD' — giving comprehensive coverage of the niche.

5 / 5

Completeness

Explicitly answers both 'what' (the enumerated attack methodology) and 'when' via the concrete trigger clause 'Use for corporate Wi-Fi engagements where the network is 802.1X authenticated.'

5 / 5

Trigger Term Quality

Includes natural terms a user would say ('corporate Wi-Fi engagements', '802.1X authenticated', 'WPA-Enterprise', 'RADIUS') with good coverage, but lacks common synonyms like 'enterprise Wi-Fi' and has no file-extension-style triggers (none apply here). Not a 5 because synonym coverage is incomplete.

4 / 5

Distinctiveness Conflict Risk

Targets a tightly defined 802.1X/EAP enterprise Wi-Fi niche with distinct triggers, making conflict with other skills minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.