CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-wps

WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default even when WPS attacks have been known for over a decade.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Actionable and well-structured with executable commands throughout, but the destructive online brute-force workflow lacks explicit validation checkpoints, capping workflow clarity, and a little background explanation could be trimmed for token efficiency.

Suggestions

Add an explicit validation/verification step in the online brute-force and cheatsheet workflows — e.g., confirm the AP lockout state before each batch and verify a recovered PIN against the M7 exchange before claiming the PSK.

Trim background mechanics Claude already knows (M3/M4 exchange internals, the PBC 120-second window explanation) to tighten token efficiency.

Move the chipset vulnerability table and vendor PIN-default patterns to a separate reference file so the main body stays a lean overview.

DimensionReasoningScore

Conciseness

Largely efficient with concrete commands and minimal concept-padding, but a few sections restate background Claude already knows (e.g., the M3/M4 exchange mechanics, PBC window explanation) that could be trimmed.

4 / 5

Actionability

Provides fully executable, copy-paste-ready commands with real flags explained inline (reaver, bully, wash, wpspin), plus expected output and a complete end-to-end cheatsheet covering the common cases.

5 / 5

Workflow Clarity

The quick workflow and engagement cheatsheet give a clear sequence, but online brute-force is a destructive/batch operation with no validation checkpoint (e.g., confirm lockout state, verify PIN before deriving PSK), which caps the score per the destructive-operations rule.

3 / 5

Progressive Disclosure

Well-organized into clearly headed sections (Detection, Pixie Dust, Online Brute-Force, PBC, Cheatsheet) with external references grouped at the end; no bundle files exist so structure stands on its own with only minor content that could arguably live separately.

4 / 5

Total

16

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states both what the skill does and when to use it, with concrete actions and a distinct niche. Slightly technical in its trigger vocabulary, which keeps it just short of perfect keyword breadth.

DimensionReasoningScore

Specificity

Lists multiple concrete, distinct actions — Pixie Dust offline attack, online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, PBC windows, PIN-to-PSK derivation — with named chipsets, achieving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both 'what' (full attack methodology) and 'when' ('Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default'), with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Natural terms like 'WPS', 'PIN brute-force', 'Pixie Dust', 'router' are present and would be said by a user, but it leans technical and omits some plain-language synonyms a non-expert might use; a few natural phrasings missing.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (WPS PIN attacks on SOHO routers) with distinct triggers unlikely to collide with other skills; minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.