Agent skill

Offensive Krack Fragattacks

by SnailSploit in SnailSploit/Claude-Red

KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

MITAuto-check: notesSecurity

Install Offensive Krack Fragattacks

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .claude/skills/offensive-krack-fragattacks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-krack-fragattacks
GitHub stars
7.3k
Token cost
~1.1k tokens
SKILL.md length
398 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

  • Works in 4 steps: Identify the in-scope client (MAC, OS,… → Estimate patch likelihood — if modern… → Run the test suite from a controlled AP… → …
  • Assessing legacy supplicants
  • SKILL.md covers When These Apply, KRACK — Key Reinstallation, FragAttacks — Frame Splicing and Targeting Workflow, plus 3 more sections
  • Calls git; reaches github.com

What it does

Offensive Krack Fragattacks is an agent skill from SnailSploit/Claude-Red. KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when assessing legacy supplicants, embedded clients, or vendors with poor patch cadence.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • Assessing legacy supplicants
  • Embedded clients
  • Vendors with poor patch cadence

Example prompts

  • “/offensive-krack-fragattacks”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the in-scope client (MAC, OS, vendor)
  2. Estimate patch likelihood — if modern OS, likely patched; if embedded, likely vulnerable
  3. Run the test suite from a controlled AP setup
  4. Report each vulnerable variant separately with the matching CVE

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Krack Fragattacks loads about 1.1k tokens when it runs. Until then it costs about 128 tokens; SKILL.md has 398 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:33
    sudo ./krack-test-client.py --interface wlan0
  • NoteRuns commands with sudoSKILL.md:55
    sudo ./test-fragattacks.py wlan0 --interface wlan0
  • NoteRuns commands with sudoSKILL.md:82
    sudo hostapd-mana /tmp/krack_test_ap.conf
  • NoteRuns commands with sudoSKILL.md:85
    sudo aireplay-ng --deauth 5 -a <real-BSSID> -c <client-MAC> wlan0mon
  • NoteRuns commands with sudoSKILL.md:88
    sudo ./krack-test-client.py --interface wlan0

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 398 words, ~1,131 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-krack-fragattacks/SKILL.md (or your agent's skills folder).
name
offensive-krack-fragattacks
description
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when assessing legacy supplicants, embedded clients, or vendors with poor patch cadence.

KRACK & FragAttacks

Two attack families against WPA2 client implementations. Both well-disclosed (KRACK 2017, FragAttacks 2021) and largely patched on modern OSes — but the embedded/IoT long tail keeps them in scope for many engagements.

When These Apply

FamilyTargetPatch Status
KRACKWPA2 supplicants in 4-way handshake / GTK / FT / TDLSMajor OSes patched 2017–2018
FragAttacksFrame fragmentation/aggregation across WPA2/3Most stacks patched 2021–2022

Probability of success today is high only against:

  • Embedded OEM devices (cameras, sensors, point-of-sale)
  • Old Android phones (<8 unpatched)
  • Industrial / SCADA Wi-Fi clients
  • Wi-Fi-enabled toys, smart bulbs, no-name IoT

Modern Win11 / iOS 16+ / Android 13+ / hostapd-2.10 are mitigated.

KRACK — Key Reinstallation

The 4-way handshake's M3 retransmission causes the supplicant to reinstall the same PTK with reset nonce/replay counters. Frames encrypted under the reused keystream become decryptable.

bash
# Vanhoef's official test scripts
git clone https://github.com/vanhoefm/krackattacks-scripts
cd krackattacks-scripts/krackattack
sudo ./krack-test-client.py --interface wlan0
# Tests the supplicant on a connected client

Output identifies which CVE variants the client is vulnerable to.

Practical Outcomes

When successful:

  • Decryption of WPA2-encrypted frames between client and AP
  • TKIP downgrade enables packet injection
  • Recovery of session keys for the duration of the affected key cycle

Not a PSK recovery — you don't get the wireless password from KRACK.

FragAttacks — Frame Splicing

FragAttacks abuse 802.11 fragmentation and aggregation to inject frames that mix encrypted and plaintext fragments, or to splice attacker-controlled fragments into legitimate frames.

bash
git clone https://github.com/vanhoefm/fragattacks
cd fragattacks
sudo ./test-fragattacks.py wlan0 --interface wlan0
# Suite of ~12 tests covering each variant
CVEMechanism
CVE-2020-24588A-MSDU spoofing — inject crafted A-MSDU subframes
CVE-2020-24587Mixed-key fragment cache poisoning
CVE-2020-24586Decoupled fragment cache → reuse
CVE-2020-26139Forwarding plaintext frames before authentication
CVE-2020-26140Accepting plaintext frames in protected network
Show full SKILL.md (161 more words)Show less
Practical Outcomes
  • Inject malicious frames that the client treats as legitimate (HTTP redirect, DNS poison)
  • Read decrypted fragments from cached state
  • Cross-protect data exfil via crafted A-MSDU

Targeting Workflow

  1. Identify the in-scope client (MAC, OS, vendor)
  2. Estimate patch likelihood — if modern OS, likely patched; if embedded, likely vulnerable
  3. Run the test suite from a controlled AP setup
  4. Report each vulnerable variant separately with the matching CVE
bash
# Rogue AP that drives the test
sudo hostapd-mana /tmp/krack_test_ap.conf

# Force client to associate (deauth from real AP, or social-engineer)
sudo aireplay-ng --deauth 5 -a <real-BSSID> -c <client-MAC> wlan0mon

# Run test once associated
sudo ./krack-test-client.py --interface wlan0

Detection

  • WIPS may flag deauth-driven roams to attacker AP
  • Test scripts generate distinctive frame patterns; modern WIPS recognizes Vanhoef's tooling
  • Successful exploitation is essentially silent at protocol level

Reporting

For each vulnerable CVE:

  • Client model + firmware version (be specific)
  • Variant tested + result (vulnerable / patched / partial)
  • Practical impact in the engagement context (decryption only, or injection viable?)
  • Remediation: vendor patch URL, mitigation (WPA3 + PMF blocks most)

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-krack-fragattacks of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Krack Fragattacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Krack Fragattacks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Krack Fragattacks this skillSnailSploit/Claude-Red7.3k—~1.1kAutomated safety check: NotesMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 17 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.3k GitHub stars~1.7k tokensUpdated 17 days ago
    Auto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 17 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.3k GitHub stars~2.8k tokensUpdated 17 days ago
    Auto-check: notes
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.3k GitHub stars~1.5k tokensUpdated 17 days ago
    Auto-check: notes
  • Offensive Z Wave

    SnailSploit/Claude-Red

    Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

    7.3k GitHub stars~1.3k tokensUpdated 17 days ago
    Auto-check passed

Categories

Questions about Offensive Krack Fragattacks

What does Offensive Krack Fragattacks do?

KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Offensive Krack Fragattacks is an agent skill from SnailSploit/Claude-Red.588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

When should I use Offensive Krack Fragattacks?

Offensive Krack Fragattacks fits situations like: assessing legacy supplicants; embedded clients; vendors with poor patch cadence.

How do I install Offensive Krack Fragattacks in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-krack-fragattacks in SnailSploit/Claude-Red) into .claude/skills/offensive-krack-fragattacks in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Krack Fragattacks in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a codex`. Or copy the skill folder (Skills/wireless/offensive-krack-fragattacks in SnailSploit/Claude-Red) into .agents/skills/offensive-krack-fragattacks in your project. Codex loads it when a task matches its description.

Can I use Offensive Krack Fragattacks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-krack-fragattacks, .gemini/skills/offensive-krack-fragattacks, .github/skills/offensive-krack-fragattacks and .opencode/skills/offensive-krack-fragattacks in your project.

What does Offensive Krack Fragattacks need to run?

Going by SKILL.md and its folder, Offensive Krack Fragattacks needs the command-line tools its instructions call (git).

Does Offensive Krack Fragattacks access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Offensive Krack Fragattacks safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Offensive Krack Fragattacks use?

Offensive Krack Fragattacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Krack Fragattacks use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Krack Fragattacks?

Skills that share tags, products or a category with Offensive Krack Fragattacks: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Krack Fragattacks?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.