CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wpa2-psk

WPA/WPA2-PSK attack methodology — four-way handshake capture via targeted deauthentication, PMKID attacks (no client required), hcxdumptool / hcxpcapngtool conversion to hashcat hc22000 format, GPU-accelerated cracking with dictionary, mask, and rule-based attacks, vendor default-PSK generators (UPC, Sky, BT, etc.), 802.11r FT key cracking, opportunistic key cache analysis, and signal-level optimization. Use when the in-scope network is WPA/WPA2 Personal — the most common consumer/SMB encryption mode.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly actionable offensive skill body built around executable commands and a clear workflow with validation feedback. It stays efficient and well-structured, with only minor room to tighten prose and to reconcile the duplicated cheatsheet against the main workflow.

Suggestions

Inline or explicitly cross-reference the 'Verifying the Capture' validation step within the Engagement Cheatsheet so the feedback loop is visible in the fast-path sequence.

Trim the opening paragraph and OKC explanatory prose to lean further on Claude's existing 802.11 knowledge.

Consider collapsing the Engagement Cheatsheet into the Quick Workflow (or moving it to a reference) to remove duplication and tighten the single source of truth.

DimensionReasoningScore

Conciseness

Largely lean, assuming Claude's competence with copy-paste commands and brief rationale ('Why one client at a time'); a few prose passages (intro paragraph, OKC explanation) add mild context that could be trimmed, but nothing is padded fluff.

4 / 5

Actionability

Fully executable, copy-paste-ready commands throughout — hcxdumptool sweeps, airodump-ng/aireplay-ng capture, hcxpcapngtool conversion, and hashcat invocations for dictionary, mask, and rule-based attacks covering the common cases.

5 / 5

Workflow Clarity

A numbered Quick Workflow and a 6-step Engagement Cheatsheet give a clear sequence, and a dedicated 'Verifying the Capture' section provides a validation checkpoint with a recapture feedback loop; the cheatsheet itself compresses the verify step rather than inlining it, a minor gap.

4 / 5

Progressive Disclosure

No bundle files exist, so all content is inline, but it is well-organized into clearly headed sections (PMKID, handshake, cracking, tuning, detection) with one-level-deep external URL references in a Key References block; the duplicated cheatsheet could arguably live separately, a minor organization gap.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-scoped description that pairs a comprehensive enumeration of concrete attack techniques with an explicit, concrete 'Use when' trigger in third-person voice. The only weakness is keyword coverage skewed toward technical jargon over natural user phrasings.

Suggestions

Add natural-language synonyms users actually say (e.g., 'crack Wi-Fi password', 'wireless password recovery') alongside the technical terms to improve trigger recall.

Consider a briefer lead clause; the long technique list is comprehensive but borders on dense for a description field.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'four-way handshake capture via targeted deauthentication', 'PMKID attacks', 'hcxdumptool / hcxpcapngtool conversion to hashcat hc22000 format', 'GPU-accelerated cracking with dictionary, mask, and rule-based attacks', 'vendor default-PSK generators', '802.11r FT key cracking' — giving comprehensive coverage of the domain.

5 / 5

Completeness

Explicitly answers both 'what' (a detailed attack methodology enumerating concrete techniques) and 'when' ('Use when the in-scope network is WPA/WPA2 Personal — the most common consumer/SMB encryption mode').

5 / 5

Trigger Term Quality

Strong technical keywords (WPA/WPA2-PSK, PMKID, four-way handshake) and an explicit 'Use when the in-scope network is WPA/WPA2 Personal' trigger, but lacks common lay synonyms a user might say ('crack Wi-Fi password', 'wifi password').

4 / 5

Distinctiveness Conflict Risk

Carves a clear niche scoped to WPA/WPA2 Personal/PSK, distinct from WPA-Enterprise or general Wi-Fi recon, with minimal conflict risk against sibling skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.