CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-zigbee-thread-matter

Zigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, KillerBee toolkit, Touchlink commissioning abuse with the well-known transport key, replay/injection attacks, Zigbee Cluster Library command abuse for door locks and bulbs, Thread network credential theft, Matter commissioning chain analysis, and 6LoWPAN/IPv6 routing exploitation. Use when targeting smart-home or commercial mesh deployments, Zigbee-based door locks, lighting, or sensor networks.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concrete, command-rich attack cheatsheet with good sectioning, but it duplicates content in a cheatsheet section and — critically for a destructive offensive skill — omits validation/verification checkpoints in its workflows, capping workflow clarity.

Suggestions

Add validation/verification steps to the destructive workflow (e.g., confirm a factory_reset_request succeeded via a follow-up zbdump/zbid probe, and verify a stolen device joined the attacker network before issuing further commands) — this is required to lift workflow_clarity above 3 for destructive operations.

Remove the duplication between 'Quick Workflow' and the 'Engagement Cheatsheet', or explicitly label the cheatsheet as a condensed quick-reference so the repetition is intentional rather than padding.

Flesh out the ZCL injection scapy example with real field values (or point to a reference script) so the actionability example is fully copy-paste executable instead of using '...' placeholders.

DimensionReasoningScore

Conciseness

Mostly lean and command-driven, but the opening paragraph re-explains what Zigbee/Thread/Matter are and the 'Engagement Cheatsheet' duplicates commands already shown in earlier sections. Not a 5 due to this redundancy; not a 3 because the bulk is efficient.

4 / 5

Actionability

Provides concrete, mostly copy-paste-ready commands (zbstumbler, zbdump, z3sec, scapy-dot15d4 sniff), but the ZCL injection frame uses 'ZigbeeNWK(...)/ZigbeeAppDataPayload(...)/ZCLDoorLock(...)' placeholder ellipses, leaving a minor gap from fully executable.

4 / 5

Workflow Clarity

A clear numbered sequence exists (Quick Workflow + Engagement Cheatsheet), but destructive/batch operations — 'factory_reset_request', 'join_network' device stealing, frame injection — have no validation or verification checkpoints. Per rubric guidance this caps workflow_clarity at 3.

3 / 5

Progressive Disclosure

No bundle files exist, but the body is well-organized into clearly headed sections and external links are collected in a 'Key References' section. Not a 5 because the file is a fairly long monolith (~155 lines) where Thread/Matter specifics could live in separate reference files; not a 3 because structure and navigation are solid.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-triggered description that clearly states both capabilities and invocation conditions for a narrow offensive mesh-protocol domain. Minor keyword-variation gaps keep trigger quality just below perfect.

DimensionReasoningScore

Specificity

Lists multiple concrete attack actions — 'IEEE 802.15.4 sniffing', 'Touchlink commissioning abuse with the well-known transport key', 'replay/injection attacks', 'Zigbee Cluster Library command abuse for door locks and bulbs', 'Thread network credential theft', '6LoWPAN/IPv6 routing exploitation' — giving comprehensive coverage rather than vague language.

5 / 5

Completeness

Explicitly answers both what (the enumerated attack methodology) and when ('Use when targeting smart-home or commercial mesh deployments, Zigbee-based door locks, lighting, or sensor networks.') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural user terms ('Zigbee', 'Thread', 'Matter', 'door locks', 'lighting', 'sensor networks', 'smart-home') with a clear trigger clause, but misses common variations like 'IoT', 'smart home' unhyphenated, or specific device brands. Not a 5 because synonym/variation coverage is good but not exhaustive.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (802.15.4 mesh-protocol attacks) with distinct triggers, and even offloads Bluetooth LE to a separate skill, minimizing overlap risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.