CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wpa3-sae

WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377, 13456), SAE auth flooding for AP CPU exhaustion, Hash-to-Element (H2E) timing analysis, group downgrade, and 6 GHz / Wi-Fi 6E spec implications (PMF mandatory, no transition mode allowed). Use when target advertises WPA3-SAE or WPA3-Personal/Enterprise, or operates in 6 GHz where WPA3 + PMF are required by spec.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable offensive methodology with concrete commands and a clear workflow, weakened mainly by missing validation checkpoints for its destructive DoS step and a few vague guidance spots. Organization is good but no bundle files exist to offload deeper detail.

Suggestions

Add an explicit validation/verification checkpoint before destructive steps — e.g. 'Before SAE flooding: confirm written authorization for DoS and target scope; abort if unchecked' — to lift workflow_clarity above the destructive-skill cap of 3.

Replace the vague hostapd fingerprinting guidance with a concrete command or filter (e.g. a specific tshark/wireshark display filter for RSNXE/IE order) so the actionability is fully executable.

Trim the opening paragraph's re-explanation of WPA3/SAE basics to tighten conciseness, or move it to a short 'Background' note.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete commands and tight rationale blocks ('Why this works', 'Mitigation defenders use'), but the opening paragraph re-explains that WPA3 replaces the 4-way handshake with SAE — context Claude largely already knows.

4 / 5

Actionability

Provides executable commands throughout (airodump-ng, airbase-ng, dragontime.py, dragondrain.py, mdk4, wireshark filters) with a copy-paste cheatsheet; minor gaps remain, e.g. 'fingerprint the AP's hostapd version' is described as passive IE-order analysis with no concrete command.

4 / 5

Workflow Clarity

A clear Quick Workflow and numbered Engagement Cheatsheet sequence the work, but because the skill includes destructive DoS (SAE auth flooding) there are no explicit validation/verification checkpoints (e.g. confirm authorization/scope before flooding), capping this at 3 per the destructive-operation rule.

3 / 5

Progressive Disclosure

Well-organized into focused sections with a clearly signaled Key References list and no nested references; content stays one level deep, though some inline detail (Dragonblood sub-commands, full cheatsheet) could be split into bundle files that are not provided.

4 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality description that concretely lists the attack techniques, supplies CVE identifiers, and gives an explicit, trigger-rich 'Use when' clause. It is third-person, concise, and distinct from sibling wireless skills.

DimensionReasoningScore

Specificity

Enumerates concrete attack methods — 'transition-mode (mixed WPA2/WPA3) downgrade', 'Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377, 13456)', 'SAE auth flooding for AP CPU exhaustion', 'H2E timing analysis', 'group downgrade' — giving comprehensive coverage rather than vague language.

5 / 5

Completeness

States both the 'what' (full attack methodology list) and an explicit 'when' — 'Use when target advertises WPA3-SAE or WPA3-Personal/Enterprise, or operates in 6 GHz where WPA3 + PMF are required by spec' — with concrete trigger phrases.

5 / 5

Trigger Term Quality

Covers the natural terms a user would say — WPA3, SAE, WPA3-Personal/Enterprise, 6 GHz, Wi-Fi 6E — including synonyms and the recognizable 'Dragonblood' name, matching the comprehensive-synonyms anchor.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (WPA3/SAE specifically) with distinct triggers anchored on AKM type and band, so it is unlikely to fire for adjacent skills like WPA2-PSK cracking.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.