Agent skill

Detecting Bluetooth Low Energy Attacks

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception.

Apache-2.0Auto-check passedSecurity

Install Detecting Bluetooth Low Energy Attacks

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-bluetooth-low-energy-attacks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-bluetooth-low-energy-attacks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-bluetooth-low-energy-attacks .claude/skills/detecting-bluetooth-low-energy-attacks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-bluetooth-low-energy-attacks
GitHub stars
34k
Token cost
~3.4k tokens
SKILL.md length
904 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception.

  • Works in 7 steps: BLE Environment Discovery and Device… → GATT Service and Characteristic… → BLE Packet Capture and Analysis → …
  • Assessing IoT device BLE security
  • SKILL.md covers Disclaimer, When to Use, Prerequisites and Workflow, plus 4 more sections
  • Runs Python scripts from its folder; calls python, pip and apt

What it does

Detecting Bluetooth Low Energy Attacks is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Security review and Penetration testing. It works with Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Assessing IoT device BLE security
  • Monitoring for BLE-based attacks on wireless infrastructure
  • Performing authorized BLE penetration testing

Example prompts

  • “Use the detecting-bluetooth-low-energy-attacks skill to detect and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay…”
  • “/detecting-bluetooth-low-energy-attacks”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. BLE Environment Discovery and Device Scanning
  2. GATT Service and Characteristic Enumeration
  3. BLE Packet Capture and Analysis
  4. BLE Encryption Analysis with Crackle
  5. Replay Attack Detection and Testing
  6. Man-in-the-Middle Detection
  7. Continuous BLE Security Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • pip
    • apt

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Bluetooth Low Energy Attacks loads about 3.4k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 158 tokens; SKILL.md has 904 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 904 words, ~3,398 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-bluetooth-low-energy-attacks/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-bluetooth-low-energy-attacks
description
Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
domain
cybersecurity
subdomain
wireless-security
author
mukul975
tags
ble, bluetooth, ubertooth, nrf-sniffer, gatt, wireless-security, iot-security, replay-attack
version
1.0.0
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03
mitre_attack
T1011.001, T1557, T1040, T1200

Detecting Bluetooth Low Energy Attacks

Disclaimer

This skill is intended for authorized security testing, penetration testing engagements, CTF competitions, and educational purposes only. Sniffing, intercepting, or manipulating Bluetooth communications without authorization may violate federal wiretapping laws and local regulations. Always obtain explicit written permission before conducting any wireless security assessment.

When to Use

Use this skill when:

  • Performing authorized BLE security assessments of IoT devices, medical devices, or smart locks
  • Monitoring a wireless environment for BLE-based replay attacks, spoofing, or unauthorized enumeration
  • Analyzing BLE packet captures to detect Man-in-the-Middle attacks or pairing exploitation
  • Enumerating GATT services and characteristics to identify insecure read/write permissions on BLE peripherals
  • Assessing BLE encryption strength and testing for crackable pairing exchanges
  • Building BLE intrusion detection capabilities for wireless security monitoring

Do not use for intercepting BLE communications without explicit authorization. Do not deploy BLE scanning tools in environments where wireless monitoring is prohibited.

Prerequisites

  • Ubertooth One hardware for passive BLE sniffing, or Nordic nRF52840 USB Dongle with nRF Sniffer firmware
  • Python 3.10+ with pip
  • bleak library: pip install bleak (cross-platform BLE GATT client)
  • Wireshark with BLE dissector plugins for packet analysis
  • crackle tool for BLE encryption analysis: built from source at github.com/mikeryan/crackle
  • ubertooth-btle CLI tools: apt install ubertooth (Linux) or build from source
  • Bluetooth 4.0+ adapter on the host system for bleak-based scanning
  • Linux recommended for full Ubertooth/nRF sniffer support

Workflow

Step 1: BLE Environment Discovery and Device Scanning

Scan the environment to identify BLE devices and their advertising data:

bash
# Scan for BLE devices using bleak (cross-platform)
python -c "
import asyncio
from bleak import BleakScanner

async def scan():
    devices = await BleakScanner.discover(timeout=10.0)
    for d in devices:
        print(f'{d.address} | RSSI: {d.rssi} | Name: {d.name or \"Unknown\"}')
        for uuid in d.metadata.get('uuids', []):
            print(f'  Service: {uuid}')

asyncio.run(scan())
"

# Passive BLE sniffing with Ubertooth One (promiscuous mode)
ubertooth-btle -p -r capture.pcapng

# Follow a specific BLE connection
ubertooth-btle -f -t AA:BB:CC:DD:EE:FF -r connection.pcapng

# Use nRF Sniffer with Wireshark (via extcap interface)
wireshark -i nRF_Sniffer -k
Step 2: GATT Service and Characteristic Enumeration

Connect to target BLE peripherals and enumerate their GATT profile:

bash
# Enumerate all services, characteristics, and descriptors
python -c "
import asyncio
from bleak import BleakClient

async def enum_gatt(address):
    async with BleakClient(address) as client:
        print(f'Connected: {client.is_connected}')
        for service in client.services:
            print(f'Service: {service.uuid} - {service.description}')
            for char in service.characteristics:
                props = ','.join(char.properties)
                print(f'  Char: {char.uuid} | Props: {props}')
                for desc in char.descriptors:
                    val = await client.read_gatt_descriptor(desc.handle)
                    print(f'    Desc: {desc.uuid} = {val}')

asyncio.run(enum_gatt('AA:BB:CC:DD:EE:FF'))
"

Security-relevant findings during GATT enumeration:

  • Characteristics with write-without-response or write without authentication
  • Readable characteristics exposing device configuration, credentials, or firmware versions
  • Missing Client Characteristic Configuration Descriptor (CCCD) protection on notification characteristics
Step 3: BLE Packet Capture and Analysis

Capture BLE traffic for offline analysis:

bash
# Capture with Ubertooth in PcapNG format (recommended)
ubertooth-btle -f -r capture.pcapng

# Capture in PCAP/PPI format for crackle compatibility
ubertooth-btle -f -c capture_ppi.pcap

# Analyze capture in Wireshark
wireshark capture.pcapng
# Apply display filter: btle
# Filter connection requests: btle.advertising_header.pdu_type == 0x05
# Filter data packets: btle.data_header

# Extract pairing information with tshark
tshark -r capture.pcapng -Y "btle.control_opcode == 0x01" -T fields \
  -e btle.master_bd_addr -e btle.slave_bd_addr
Step 4: BLE Encryption Analysis with Crackle

Analyze captured pairing exchanges to test encryption strength:

bash
# Crack BLE Legacy Pairing (Just Works / passkey)
crackle -i capture_ppi.pcap -o decrypted.pcap

# Crack with known Temporary Key (TK)
crackle -i capture_ppi.pcap -o decrypted.pcap -l 000000

# Analyze decrypted traffic
wireshark decrypted.pcap

BLE Legacy Pairing with Just Works mode uses a TK of all zeros, making it trivially crackable. Passkey entry uses a 6-digit PIN (000000-999999) that can be brute-forced in under a second. Only BLE Secure Connections (LE Secure Connections with ECDH) provides adequate protection against passive eavesdropping.

Step 5: Replay Attack Detection and Testing

Monitor for and test BLE replay attack susceptibility:

bash
# Capture characteristic write operations
# Record the raw bytes written to a target characteristic
# Then replay the exact same bytes to test if the device accepts stale commands

python -c "
import asyncio
from bleak import BleakClient

TARGET = 'AA:BB:CC:DD:EE:FF'
CHAR_UUID = '0000fff1-0000-1000-8000-00805f9b34fb'

async def replay_test():
    async with BleakClient(TARGET) as client:
        # Step 1: Read current state
        val = await client.read_gatt_char(CHAR_UUID)
        print(f'Current value: {val.hex()}')

        # Step 2: Write a command (captured from previous session)
        captured_command = bytes.fromhex('0102030405')
        await client.write_gatt_char(CHAR_UUID, captured_command)
        print('Replayed captured command')

        # Step 3: Verify if command was accepted
        new_val = await client.read_gatt_char(CHAR_UUID)
        print(f'New value: {new_val.hex()}')
        if new_val != val:
            print('VULNERABLE: Device accepted replayed command')

asyncio.run(replay_test())
"

Indicators of replay vulnerability:

  • Device accepts previously captured write commands without freshness validation
  • No sequence number, timestamp, or challenge-response mechanism in the protocol
  • Device state changes in response to replayed commands
Step 6: Man-in-the-Middle Detection

Detect BLE MITM attacks by monitoring for anomalous behavior:

bash
# Monitor for BLE address spoofing (device impersonation)
# Compare advertising data fingerprints over time

# Monitor for unexpected connection parameter changes
tshark -r capture.pcapng -Y "btle.control_opcode == 0x00" -T fields \
  -e btle.control.interval.min -e btle.control.interval.max

# Detect GATTacker/BTLEjuice MITM patterns:
# - Cloned advertising data with different BD_ADDR
# - Rapid connect/disconnect cycles on the same channel
# - Duplicate service UUIDs from different addresses

# Monitor for suspicious pairing requests
tshark -r capture.pcapng -Y "btl2cap.cid == 0x0006" -T fields \
  -e btsmp.opcode -e btsmp.io_capability -e btsmp.auth_req
Step 7: Continuous BLE Security Monitoring

Deploy ongoing BLE monitoring for threat detection:

bash
# Run the agent in monitoring mode
python agent.py --mode monitor --duration 3600 --output ble_alerts.json

# Combine with Ubertooth for passive monitoring
ubertooth-btle -p -r - | python agent.py --mode analyze --pcap-stdin

# Alert on specific threat indicators
python agent.py --mode monitor --alert-on replay,spoofing,weak-pairing

Key Concepts

TermDefinition
BLE (Bluetooth Low Energy)Low-power wireless protocol (Bluetooth 4.0+) optimized for IoT devices, operating on 2.4 GHz with 40 channels (3 advertising, 37 data)
GATT (Generic Attribute Profile)BLE data model organizing device capabilities into services, characteristics, and descriptors; the primary interface for reading/writing BLE device data
Ubertooth OneOpen-source 2.4 GHz wireless development platform capable of passive BLE and Bluetooth Classic sniffing across all BLE channels
nRF SnifferNordic Semiconductor firmware for nRF52840 USB dongle that enables BLE packet capture with Wireshark integration via extcap
Replay AttackAttack where previously captured BLE commands are retransmitted to a device to trigger unauthorized actions without knowledge of encryption keys
Just Works PairingBLE Legacy Pairing method using TK=0 with no user confirmation, providing zero protection against passive eavesdropping and MITM attacks
LE Secure ConnectionsBLE 4.2+ pairing mode using ECDH key exchange (P-256 curve) that provides protection against passive eavesdropping; recommended over Legacy Pairing
CrackleOpen-source tool that exploits weaknesses in BLE Legacy Pairing to recover the Long Term Key (LTK) and decrypt captured BLE traffic
GATTackerBLE MITM framework that clones a peripheral's GATT profile and advertising data, then relays traffic between the real device and the victim central
Show full SKILL.md (261 more words)Show less

Tools & Systems

  • Ubertooth One + ubertooth-btle: Hardware sniffer and CLI tool for passive BLE packet capture in pcapng/pcap format
  • nRF52840 USB Dongle + nRF Sniffer: Nordic Semiconductor BLE sniffer with native Wireshark extcap integration
  • bleak: Cross-platform Python asyncio BLE GATT client library for device scanning, connection, and characteristic read/write
  • crackle: BLE Legacy Pairing encryption cracker that recovers LTK from captured pairing exchanges
  • Wireshark: Network protocol analyzer with BLE/BTLE dissectors for packet-level inspection of captured traffic
  • GATTacker / BTLEjuice: BLE Man-in-the-Middle frameworks for intercepting and modifying BLE traffic between central and peripheral
  • tshark: Command-line Wireshark for scripted BLE packet extraction and field analysis

Common Pitfalls

  • Ubertooth channel hopping limitations: Ubertooth follows one connection at a time. If multiple BLE connections are active, you must target a specific device address with -t to follow its data channels.
  • BLE 5.0 extended advertising: Devices using BLE 5.0 extended advertising on secondary channels may not be captured by older Ubertooth firmware. Update to the latest firmware.
  • bleak platform differences: BLE scanning behavior varies across OS backends. On Linux, scanning requires root or appropriate capabilities. On macOS, device addresses are randomized UUIDs.
  • crackle requires Legacy Pairing: crackle only works against BLE Legacy Pairing (Bluetooth 4.0/4.1). LE Secure Connections (4.2+) use ECDH and cannot be cracked with this approach.
  • BLE address randomization: Many modern BLE devices use random resolvable private addresses (RPA) that rotate periodically, making device tracking and connection following more difficult.
  • Capture format matters: Use PCAP with PPI headers (-c flag) for crackle compatibility. PcapNG (-r flag) is recommended for Wireshark analysis but not supported by crackle.

Output Format

## Finding: BLE Smart Lock Accepts Replayed Unlock Commands

**ID**: BLE-001
**Severity**: Critical (CVSS 9.3)
**Device**: SmartLock-Pro (AA:BB:CC:DD:EE:FF)
**Attack Type**: Replay Attack

**Description**:
The BLE smart lock accepts previously captured GATT write commands
on characteristic 0000fff1-0000-1000-8000-00805f9b34fb without
any freshness validation. An attacker who captures a single unlock
command can replay it indefinitely to unlock the device.

**Proof of Concept**:
1. Capture unlock command: ubertooth-btle -f -t AA:BB:CC:DD:EE:FF -r capture.pcap
2. Extract write payload from characteristic fff1: 01 42 A3 7F 00
3. Replay via bleak: await client.write_gatt_char(CHAR_UUID, bytes.fromhex('0142a37f00'))
4. Lock disengages without re-authentication

**Impact**:
Any attacker within BLE range (~100m with directional antenna) who
captures a single unlock event can replay it to gain physical access
to the protected area indefinitely.

**Remediation**:
Implement challenge-response authentication with per-session nonces.
Each command should include a server-generated challenge that expires
after use. Use LE Secure Connections for pairing to prevent passive
capture of the pairing exchange.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/detecting-bluetooth-low-energy-attacks of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Bluetooth Low Energy Attacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Bluetooth Low Energy Attacks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Bluetooth Low Energy Attacks this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Add Community Skillsamugit83/redamon3k—~775Automated safety check: PassMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    3k GitHub stars~775 tokensUpdated yesterday
    SecurityAuto-check passed
  • Review Security

    pydantic/monty

    Official

    Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

    8.6k GitHub stars~852 tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Detecting Bluetooth Low Energy Attacks

What does Detecting Bluetooth Low Energy Attacks do?

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Detecting Bluetooth Low Energy Attacks is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception.

When should I use Detecting Bluetooth Low Energy Attacks?

Detecting Bluetooth Low Energy Attacks fits situations like: assessing IoT device BLE security; monitoring for BLE-based attacks on wireless infrastructure; performing authorized BLE penetration testing.

How do I install Detecting Bluetooth Low Energy Attacks in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-bluetooth-low-energy-attacks -a claude-code`. Or copy the skill folder (skills/detecting-bluetooth-low-energy-attacks in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-bluetooth-low-energy-attacks in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Bluetooth Low Energy Attacks in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-bluetooth-low-energy-attacks -a codex`. Or copy the skill folder (skills/detecting-bluetooth-low-energy-attacks in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-bluetooth-low-energy-attacks in your project. Codex loads it when a task matches its description.

Can I use Detecting Bluetooth Low Energy Attacks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-bluetooth-low-energy-attacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-bluetooth-low-energy-attacks, .gemini/skills/detecting-bluetooth-low-energy-attacks, .github/skills/detecting-bluetooth-low-energy-attacks and .opencode/skills/detecting-bluetooth-low-energy-attacks in your project.

What does Detecting Bluetooth Low Energy Attacks need to run?

Going by SKILL.md and its folder, Detecting Bluetooth Low Energy Attacks needs Python for the scripts in its folder and the command-line tools its instructions call (python, pip and apt). Our summary lists: Python 3.

Does Detecting Bluetooth Low Energy Attacks access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Detecting Bluetooth Low Energy Attacks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Bluetooth Low Energy Attacks use?

Detecting Bluetooth Low Energy Attacks is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Bluetooth Low Energy Attacks use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Bluetooth Low Energy Attacks?

Skills that share tags, products or a category with Detecting Bluetooth Low Energy Attacks: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 892 stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Bluetooth Low Energy Attacks?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.