Agent skill

Conducting Wireless Network Penetration Test

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3…

Apache-2.0Auto-check passedSecurity

Install Conducting Wireless Network Penetration Test

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-wireless-network-penetration-test -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills conducting-wireless-network-penetration-test --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/conducting-wireless-network-penetration-test .claude/skills/conducting-wireless-network-penetration-test && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
conducting-wireless-network-penetration-test
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
1,071 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3…

  • Works in 5 steps: Wireless Reconnaissance → WPA2-Personal Handshake Capture and… → WPA2-Enterprise Attack → …
  • Tasks that involve Network security
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Conducting Wireless Network Penetration Test is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Activates for requests involving wireless pentest, WiFi security assessment, WPA2/WPA3 testing, or rogue access…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Network security and Penetration testing. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Network security
  • Tasks that involve Penetration testing

Example prompts

  • “Use the conducting-wireless-network-penetration-test skill to conduct authorized wireless network penetration tests to assess the security of WiFi…”
  • “/conducting-wireless-network-penetration-test”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Wireless Reconnaissance
  2. WPA2-Personal Handshake Capture and Cracking
  3. WPA2-Enterprise Attack
  4. Evil Twin Attack
  5. Post-Compromise Network Assessment

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Conducting Wireless Network Penetration Test loads about 2.8k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,071 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,071 words, ~2,783 tokens.

Download SKILL.mdSave it as .claude/skills/conducting-wireless-network-penetration-test/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
conducting-wireless-network-penetration-test
description
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks. The tester evaluates wireless authentication, network segmentation, and the effectiveness of wireless intrusion detection systems. Activates for requests involving wireless pentest, WiFi security assessment, WPA2/WPA3 testing, or rogue access point detection.
domain
cybersecurity
subdomain
penetration-testing
tags
wireless-pentest, WiFi-security, WPA2, WPA3, evil-twin
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-06, GV.OV-02, DE.AE-07
mitre_attack
T1557.004, T1040, T1110.002, T1557, T1669

Conducting Wireless Network Penetration Test

When to Use

  • Assessing the security of enterprise wireless networks including guest, corporate, and IoT WiFi segments
  • Testing whether attackers within physical proximity can compromise wireless authentication and access internal networks
  • Validating wireless intrusion detection/prevention system (WIDS/WIPS) capabilities against known attack techniques
  • Evaluating the effectiveness of WPA3 migration and transition mode configurations
  • Testing network segmentation between wireless and wired networks after a wireless network compromise

Do not use against wireless networks without written authorization from the network owner, for jamming or denial-of-service attacks against wireless infrastructure unless explicitly authorized, or in environments where wireless disruption could affect life-safety systems.

Prerequisites

  • Written authorization specifying target SSIDs, BSSIDs, and physical testing locations
  • External WiFi adapter supporting monitor mode and packet injection (Alfa AWUS036ACH, TP-Link TL-WN722N v1)
  • Kali Linux or equivalent with up-to-date wireless tools (aircrack-ng suite, hostapd, bettercap)
  • Physical access to the testing location during authorized testing hours
  • Knowledge of the target's wireless architecture (SSIDs, authentication types, RADIUS infrastructure)

Workflow

Step 1: Wireless Reconnaissance

Discover and map all wireless networks in the target environment:

  • Enable monitor mode: airmon-ng start wlan0
  • Capture wireless traffic: airodump-ng wlan0mon -w recon --output-format csv,pcap to discover all SSIDs, BSSIDs, channels, encryption types, and connected clients
  • Identify target networks from the authorized scope and note their security configurations (WEP, WPA2-Personal, WPA2-Enterprise, WPA3-SAE, WPA3-Transition)
  • Enumerate connected clients and their signal strengths to understand client distribution
  • Check for hidden SSIDs by capturing probe requests from clients: airodump-ng wlan0mon --essid-regex ".*" -c <channel>
  • Identify rogue access points by comparing discovered BSSIDs against the client's authorized AP inventory
Step 2: WPA2-Personal Handshake Capture and Cracking

For WPA2-PSK networks, capture the 4-way handshake and attempt offline cracking:

  • Target the specific AP: airodump-ng wlan0mon -c <channel> --bssid <bssid> -w capture
  • Deauthenticate a connected client to force re-authentication: aireplay-ng -0 5 -a <bssid> -c <client_mac> wlan0mon
  • Verify handshake capture in airodump-ng (WPA handshake indicator appears)
  • Crack the captured handshake:
    • Dictionary attack: aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.cap
    • GPU-accelerated: hashcat -m 22000 capture.hc22000 /usr/share/wordlists/rockyou.txt
    • Rule-based: hashcat -m 22000 capture.hc22000 wordlist.txt -r /usr/share/hashcat/rules/best64.rule
  • For PMKID capture (clientless): hcxdumptool -i wlan0mon --enable_status=1 -o pmkid.pcapng --filtermode=2 --filterlist_ap=<bssid>
Step 3: WPA2-Enterprise Attack

For 802.1X/EAP networks, attempt credential capture through rogue RADIUS:

  • Identify the EAP type in use (PEAP-MSCHAPv2, EAP-TLS, EAP-TTLS) by capturing association requests
  • Set up a rogue AP mimicking the enterprise SSID using hostapd-mana with a rogue RADIUS server
  • Configure hostapd-mana to accept all EAP authentication attempts and capture RADIUS handshakes
  • When clients connect to the rogue AP, capture MSCHAPv2 challenge-response pairs
  • Crack captured credentials with asleap or convert to hashcat format: hashcat -m 5500 captured_ntlm.txt wordlist.txt
  • If EAP-TLS is in use (certificate-based), document that credential capture is not feasible and the organization has implemented strong wireless authentication
Step 4: Evil Twin Attack

Deploy a rogue access point to intercept client connections:

  • Create an evil twin AP matching the target SSID: configure hostapd with the same SSID and channel
  • Set up a captive portal using dnsmasq for DHCP and DNS, and a web server presenting a fake login page
  • Deauthenticate clients from the legitimate AP to force reconnection to the evil twin
  • Capture credentials submitted through the captive portal
  • For WPA3-Transition mode networks: exploit the downgrade vulnerability by creating a WPA2-only evil twin that transition-mode clients will connect to
  • Document all captured credentials and the attack path from wireless access to internal network
Step 5: Post-Compromise Network Assessment

After gaining wireless network access, assess network segmentation:

  • Connect to the compromised wireless network using captured credentials
  • Scan the network segment for accessible hosts and services: nmap -sn <wireless_subnet>
  • Test if wireless clients can reach internal servers, databases, or management interfaces
  • Verify that VLAN segmentation properly isolates guest, corporate, and IoT wireless networks
  • Test if wireless-to-wired segmentation is enforced by attempting to access servers on the wired network
  • Document all accessible resources from the wireless network to demonstrate segmentation failures
Show full SKILL.md (430 more words)Show less

Key Concepts

TermDefinition
Evil TwinA rogue access point that mimics a legitimate SSID to trick clients into connecting, enabling man-in-the-middle attacks and credential capture
4-Way HandshakeThe WPA2 authentication exchange between client and AP that establishes encryption keys; captured handshakes can be cracked offline
WPA3-SAESimultaneous Authentication of Equals; WPA3's key exchange protocol that resists offline dictionary attacks and provides forward secrecy
Transition ModeWPA3 backward compatibility mode that supports both WPA2 and WPA3 clients, potentially vulnerable to downgrade attacks
PMKID AttackA clientless attack that captures the Pairwise Master Key Identifier from the AP's first EAPOL frame, allowing offline cracking without capturing a full handshake
802.1X/EAPEnterprise wireless authentication using RADIUS and Extensible Authentication Protocol, providing per-user credentials instead of a shared pre-shared key
Deauthentication AttackSending spoofed deauthentication frames to disconnect clients from an AP, forcing them to reconnect and enabling handshake capture or evil twin attacks

Tools & Systems

  • Aircrack-ng Suite: Comprehensive wireless auditing toolkit including airodump-ng (capture), aireplay-ng (injection), and aircrack-ng (cracking)
  • Hostapd-mana: Modified hostapd for creating rogue access points with EAP credential capture capability
  • Bettercap: Network attack framework with WiFi modules for deauthentication, handshake capture, and evil twin deployment
  • Hashcat: GPU-accelerated password cracking supporting WPA2 (mode 22000), MSCHAPv2 (mode 5500), and PMKID formats
  • Kismet: Wireless network detector, sniffer, and intrusion detection system for passive monitoring

Common Scenarios

Scenario: Wireless Security Assessment for a Corporate Office

Context: A financial services company has 3 SSIDs: CorpWiFi (WPA2-Enterprise for employees), GuestWiFi (captive portal), and IoT-Net (WPA2-PSK for printers and conferencing systems). The tester is authorized to test all three networks from the lobby and conference rooms.

Approach:

  1. Wireless reconnaissance identifies all 3 SSIDs across 12 access points with 87 connected clients
  2. IoT-Net WPA2-PSK handshake captured and cracked in 3 minutes (password: Company2024!)
  3. From IoT-Net, scan reveals the subnet can reach internal servers including the print server and file shares, demonstrating inadequate segmentation
  4. Evil twin attack against CorpWiFi captures 4 employee MSCHAPv2 hashes via hostapd-mana; 2 are cracked revealing passwords
  5. GuestWiFi captive portal bypass achieved using MAC address spoofing of an already-authenticated device
  6. Document that IoT-Net provides a direct path to the internal network bypassing WPA2-Enterprise authentication

Pitfalls:

  • Conducting deauthentication attacks during business hours without coordinating with the client, causing visible WiFi disruptions
  • Not testing WPA3 transition mode for downgrade vulnerabilities when the organization has begun WPA3 migration
  • Focusing only on password cracking and missing network segmentation issues that are often the higher-risk finding
  • Testing from a single location and missing rogue APs deployed in other areas of the facility

Output Format

## Finding: Weak WPA2-PSK on IoT Network with Inadequate Segmentation

**ID**: WIFI-001
**Severity**: Critical (CVSS 9.4)
**Affected SSID**: IoT-Net (BSSID: AA:BB:CC:DD:EE:FF)
**Encryption**: WPA2-Personal (PSK)

**Description**:
The IoT wireless network uses a weak pre-shared key that was cracked in 3 minutes
using a standard dictionary attack. Once connected to IoT-Net, the tester discovered
that the wireless VLAN is not properly segmented from the internal corporate network,
providing unrestricted access to file servers, the Active Directory domain controller,
and the internal database server.

**Proof of Concept**:
1. Captured WPA2 handshake: airodump-ng wlan0mon -c 6 --bssid AA:BB:CC:DD:EE:FF -w iot
2. Cracked PSK in 3 minutes: aircrack-ng -w rockyou.txt iot-01.cap -> Key: Company2024!
3. Connected to IoT-Net and scanned: nmap -sn 10.20.0.0/24
4. Accessible from IoT-Net: DC01 (10.20.0.5:445), FILESVR (10.20.0.10:445), DBSVR (10.20.0.15:3306)

**Impact**:
An attacker within wireless range (tested from the public lobby) can join the IoT
network and gain direct network access to the corporate infrastructure, bypassing
the WPA2-Enterprise authentication required for employee access.

**Remediation**:
1. Implement a complex 20+ character PSK for IoT-Net, rotated quarterly
2. Deploy VLAN segmentation to isolate IoT-Net from the corporate network
3. Implement firewall rules allowing IoT devices to reach only their required services
4. Migrate IoT devices to 802.1X authentication with device certificates where supported
5. Deploy WIDS to detect deauthentication attacks and rogue access points

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/conducting-wireless-network-penetration-test of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Conducting Wireless Network Penetration Test next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Conducting Wireless Network Penetration Test compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Conducting Wireless Network Penetration Test this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Nmap Network Scanautomateyournetwork/netclaw676—~1.3kAutomated safety check: PassApache-2.0
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Fix Strix Security Findingsusestrix/strix68k—~1.5kAutomated safety check: PassApache-2.0
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Nmap Network Scan

    automateyournetwork/netclaw

    Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.

    676 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Conducting Wireless Network Penetration Test

What does Conducting Wireless Network Penetration Test do?

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3…. Conducting Wireless Network Penetration Test is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3 handshake capture, rogue access point detection, and client-side attacks.

When should I use Conducting Wireless Network Penetration Test?

Conducting Wireless Network Penetration Test fits situations like: tasks that involve Network security; tasks that involve Penetration testing.

How do I install Conducting Wireless Network Penetration Test in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-wireless-network-penetration-test -a claude-code`. Or copy the skill folder (skills/conducting-wireless-network-penetration-test in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/conducting-wireless-network-penetration-test in your project. Claude Code loads it when a task matches its description.

How do I install Conducting Wireless Network Penetration Test in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-wireless-network-penetration-test -a codex`. Or copy the skill folder (skills/conducting-wireless-network-penetration-test in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/conducting-wireless-network-penetration-test in your project. Codex loads it when a task matches its description.

Can I use Conducting Wireless Network Penetration Test in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-wireless-network-penetration-test -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conducting-wireless-network-penetration-test, .gemini/skills/conducting-wireless-network-penetration-test, .github/skills/conducting-wireless-network-penetration-test and .opencode/skills/conducting-wireless-network-penetration-test in your project.

What does Conducting Wireless Network Penetration Test need to run?

Going by SKILL.md and its folder, Conducting Wireless Network Penetration Test needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Conducting Wireless Network Penetration Test access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Conducting Wireless Network Penetration Test safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Conducting Wireless Network Penetration Test use?

Conducting Wireless Network Penetration Test is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Conducting Wireless Network Penetration Test use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 573 tokens, read only when the agent opens those files.

What are the alternatives to Conducting Wireless Network Penetration Test?

Skills that share tags, products or a category with Conducting Wireless Network Penetration Test: Nmap Network Scan (automateyournetwork/netclaw, 676 stars), Strix Code Vulnerability Scan (usestrix/strix, 68k stars), Code Audit (3stoneBrother/code-audit, 892 stars) and Fix Strix Security Findings (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Conducting Wireless Network Penetration Test?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.