Agent skill

Offensive Z Wave

by SnailSploit in SnailSploit/Claude-Red

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

MITAuto-check passedDevOps & Cloud

Install Offensive Z Wave

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-z-wave -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-z-wave --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-z-wave .claude/skills/offensive-z-wave && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-z-wave
GitHub stars
7.3k
Token cost
~1.3k tokens
SKILL.md length
501 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

  • Works in 4 steps: Identify region (US 908 MHz / EU 868… → Sniff inclusion (commissioning) traffic… → Determine S0 vs S2 from frame format → …
  • Targeting Z-Wave smart home devices (door locks
  • SKILL.md covers Quick Workflow, Hardware, Sniffing and S0 Security Flaw, plus 8 more sections
  • Calls git; reaches github.com

What it does

Offensive Z Wave is an agent skill from SnailSploit/Claude-Red. Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting Z-Wave smart home devices (door locks, sensors, garage controllers) — common in mid-2010s smart home deployments still in production.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • Targeting Z-Wave smart home devices (door locks
  • Garage controllers) — common in mid-2010s smart home deployments still in production

Example prompts

  • “/offensive-z-wave”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify region (US 908 MHz / EU 868 MHz) — adapter frequency must match
  2. Sniff inclusion (commissioning) traffic — that's where keys are exchanged
  3. Determine S0 vs S2 from frame format
  4. For S0: derive/replay; for S2: analyze ECDH and look for implementation flaws

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Z Wave loads about 1.3k tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 501 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 501 words, ~1,342 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-z-wave/SKILL.md (or your agent's skills folder).
name
offensive-z-wave
description
Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting Z-Wave smart home devices (door locks, sensors, garage controllers) — common in mid-2010s smart home deployments still in production.

Z-Wave Attacks

Z-Wave runs in the 800/900 MHz ISM band (US: 908 MHz, EU: 868 MHz). Older networks used the S0 security scheme with a fixed-derivation network key — long-known to be flawed. S2 (mandatory for Z-Wave Plus v2 since 2017) uses ECDH commissioning and is significantly stronger.

Quick Workflow

  1. Identify region (US 908 MHz / EU 868 MHz) — adapter frequency must match
  2. Sniff inclusion (commissioning) traffic — that's where keys are exchanged
  3. Determine S0 vs S2 from frame format
  4. For S0: derive/replay; for S2: analyze ECDH and look for implementation flaws

Hardware

AdapterUse
Z-Force (legacy, hard to find)Original research tool
EZ-Wave (custom HackRF firmware)Modern, full transceiver
Aeotec Z-StickCommercial controller, useful as legitimate node
HackRF + open Z-Wave firmwareMulti-band SDR approach
RTL-SDR + ZniffMobile (passive only)Cheap sniffer

Sniffing

bash
# EZ-Wave (HackRF firmware-based)
git clone https://github.com/cureHsu/EZ-Wave
ezwave-sniff -f 908.4MHz -o capture.pcap

# Wireshark with the Z-Wave dissector parses captured frames
wireshark capture.pcap

Look for the inclusion phase (controller adding new device) — that's where the network key is exchanged.

S0 Security Flaw

S0 derives the network key from a fixed all-zero PSK during the inclusion of the first device. That fixed material is well-known — any S0 network you sniff during inclusion can be decrypted offline.

S0 commissioning:
  1. New node joins → controller sends key with zero-PSK encryption
  2. Attacker sniffs commissioning frame → derives session key
  3. All future S0 traffic on that network is decryptable

If you can:

  • Trigger inclusion (factory-reset a node, or wait for legitimate inclusion)
  • Sniff during the ~2-second key-exchange window

You own the network key for that mesh.

S2 (Z-Wave Plus / S2 Authenticated)

S2 fixes S0 by using ECDH for commissioning:

  • Each device has a Curve25519 keypair
  • Inclusion uses DSK (Device Specific Key) verified out-of-band (sticker/QR)
  • Network key never traverses the air in plaintext

S2 attack surface is mostly implementation:

  • Inclusion-mode-always-open (controller misconfig)
  • Firmware bugs in S2 verification
  • Side-channel on ECDH on resource-constrained chips
  • DSK printed on a sticker → physical access yields it

Replay / Injection on Unauthenticated Nodes

Many low-end Z-Wave devices (older sensors, basic switches) don't enforce S0 or S2 — they accept commands in cleartext.

python
# scapy-zwave (community fork) for crafted frames
from scapy.contrib.zwave import *
frame = ZWave(home_id=0x12345678)/ZWaveBasic(set_value=0xff)
sendp(frame, iface='ezwave0')

This unlocks doors / switches lights / unarms sensors when the target lacks authentication.

Show full SKILL.md (189 more words)Show less

Key Brute-Force

For old test deployments using default home IDs / network keys:

bash
# Try default home IDs
for hid in 0x00000000 0x12345678 ...; do
  ezwave-test --home-id $hid --target-node 1
done

Hit rate on production is low; useful only for default-config IoT lab gear.

Hub Pivots

Z-Wave devices are typically controlled by a hub (SmartThings, Hubitat, Vera, Home Assistant, Z-Wave JS UI). The hub is a Linux device with the Z-Wave PSK in plaintext storage:

  • SmartThings Hub: previously cloud-only credentials; modern v3 stores network key locally
  • Home Assistant: ~/.homeassistant/zwave_js.json typically contains keys
  • Hubitat: web UI with default password on older versions

Compromise the hub → walk away with the Z-Wave PSK + every paired device's command authority. See offensive-iot for hub firmware extraction.

Engagement Cheatsheet

bash
# 1. Identify region + frequency
# US: 908.4 MHz; EU: 868.4 MHz; CN: 868.4 MHz

# 2. Sniff
ezwave-sniff -f 908.4MHz -o cap.pcap
wireshark cap.pcap   # filter zwave

# 3. Identify S0 vs S2 from frame format

# 4. For S0: capture inclusion → derive key → decrypt history + control devices

# 5. For S2: focus on hub compromise / DSK theft / implementation bugs

# 6. Test unauthenticated cleartext devices with crafted frames

Detection

  • Most Z-Wave deployments have no IDS comparable to Wi-Fi/Zigbee monitoring
  • Hub may log unexpected commands but UI rarely surfaces these to users
  • Inclusion-mode-open is visible in hub UI but ignored by inattentive admins

Reporting

  • Identify chipset / firmware revision per device (ZW0500 series, ZW7000 series)
  • Map S0 vs S2 per node — note any S0 left on a network with S2-capable nodes
  • Document hub compromise paths separately

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-z-wave of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Z Wave next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Z Wave compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Z Wave this skillSnailSploit/Claude-Red7.3k—~1.3kAutomated safety check: PassMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion62k—~1.2kAutomated safety check: PassCustom licence
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    62k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.3k GitHub stars~1.1k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 18 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.3k GitHub stars~1.7k tokensUpdated 18 days ago
    Auto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 18 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.3k GitHub stars~2.8k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.3k GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check: notes

Categories

Questions about Offensive Z Wave

What does Offensive Z Wave do?

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…. Offensive Z Wave is an agent skill from SnailSploit/Claude-Red. Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots.

When should I use Offensive Z Wave?

Offensive Z Wave fits situations like: targeting Z-Wave smart home devices (door locks; garage controllers) — common in mid-2010s smart home deployments still in production.

How do I install Offensive Z Wave in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-z-wave -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-z-wave in SnailSploit/Claude-Red) into .claude/skills/offensive-z-wave in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Z Wave in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-z-wave -a codex`. Or copy the skill folder (Skills/wireless/offensive-z-wave in SnailSploit/Claude-Red) into .agents/skills/offensive-z-wave in your project. Codex loads it when a task matches its description.

Can I use Offensive Z Wave in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-z-wave -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-z-wave, .gemini/skills/offensive-z-wave, .github/skills/offensive-z-wave and .opencode/skills/offensive-z-wave in your project.

What does Offensive Z Wave need to run?

Going by SKILL.md and its folder, Offensive Z Wave needs the command-line tools its instructions call (git). Our summary lists: Python 3.

Does Offensive Z Wave access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Offensive Z Wave safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Offensive Z Wave use?

Offensive Z Wave is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Z Wave use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Z Wave?

Skills that share tags, products or a category with Offensive Z Wave: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars) and Vercel (remotion-dev/remotion, 62k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Z Wave?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,340 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.