SkillAgentSearch skills...

offensive-social-engineering

Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements.

Install / Use

npx skills add SnailSploit/Claude-Red --skill offensive-social-engineering

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

96/100

Category

Security

Supported Platforms

Zed

Our assessment of offensive-social-engineering

offensive-social-engineering scores 96/100 on our quality scale, 127th of 653 Security skills we index (top 20%).

Its SKILL.md is 22 KB long, well organised into 59 sections with 20 code examples: a thorough specification that gives an agent plenty to work with.

With 6,850 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
16/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so offensive-social-engineering is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-09-26. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

offensive-social-engineering compared with similar skills

All 4 of these similar skills score higher than offensive-social-engineering; compare them before choosing.

SkillScoreStarsUpdatedFormat
offensive-social-engineering (this skill)by SnailSploit966.8k6d agoSKILL.md
LocalAIby mudler10049.3ktodayMCP Server
algorithmic-artby anthropics100177.9k4d agoSKILL.md
pptxby anthropics100177.9k4d agoSKILL.md
designby nextlevelbuilder100130.2k5d agoSKILL.md

Frequently asked questions

How do I install offensive-social-engineering?
Run npx skills add SnailSploit/Claude-Red --skill offensive-social-engineering. The install tabs above show the steps for each supported agent.
Which AI agents does offensive-social-engineering work with?
It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
Is offensive-social-engineering safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is offensive-social-engineering still maintained?
The repository was last updated 6 days ago, so offensive-social-engineering is actively maintained.

name: offensive-social-engineering description: "Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements. Covers pretexting methodology (persona creation, authority and urgency psychological triggers, rapport building), vishing (voice phishing via caller ID spoofing, IVR system exploitation, VoIP infrastructure setup with Twilio/Asterisk), smishing (SMS-based phishing, carrier gateway abuse, short code impersonation), physical social engineering (tailgating and piggybacking, RFID badge cloning with Proxmark3, lock picking and bypass, dumpster diving for sensitive documents), USB drop attacks (Rubber Ducky keystroke injection, Bash Bunny multi-vector payloads, O.MG cable covert implants, BadUSB firmware attacks), watering hole attack planning and execution, and OSINT-driven targeting (LinkedIn harvesting, organizational chart reconstruction, employee pattern analysis). Integrates with the Social Engineering Toolkit for attack automation, Proxmark3 for RFID/NFC cloning, USB Rubber Ducky and Bash Bunny for physical payload delivery, and BeEF for browser exploitation. Maps to MITRE ATT&CK T1598 (Phishing for Information), T1566 (Phishing), T1091 (Replication Through Removable Media), and T1189 (Drive-by Compromise). All techniques require explicit written authorization and defined rules of engagement."

Offensive Social Engineering

Social engineering exploits human trust, authority bias, and procedural gaps rather than technical vulnerabilities. While phishing is the most common vector, a comprehensive red team engagement tests the full spectrum: voice calls, text messages, physical access, and planted devices. You are simulating an adversary who combines OSINT, psychological manipulation, and physical access techniques to breach an organization's defenses at the human layer.

Every technique described here requires explicit written authorization. Physical social engineering carries additional legal considerations -- trespassing, impersonation of officials, and recording laws vary by jurisdiction. Confirm your scope covers each vector before execution.

Quick Workflow

  1. Conduct OSINT to map the target organization's structure, key personnel, physical locations, and communication patterns.
  2. Develop personas and pretexts tailored to the engagement objectives (credential theft, physical access, data exfiltration).
  3. Prepare infrastructure: VoIP numbers for vishing, SMS gateways for smishing, cloned badges for physical access.
  4. Execute attacks in phases -- start with remote vectors (vishing, smishing), escalate to physical if in scope.
  5. Document every interaction with timestamps, recordings (where legally permitted), and outcomes.
  6. Debrief with the client; provide actionable recommendations for security awareness and procedural improvements.

Pretexting and Psychological Manipulation

Pretexting is the foundation of all social engineering. You construct a believable scenario that gives you a reason to request information or access. The pretext must hold up under casual scrutiny and, for high-value targets, under deliberate verification.

Persona Development

Build a persona with enough depth to answer follow-up questions. A thin pretext collapses under the first challenge.

Persona Template:
  Name:           [Realistic for the region and industry]
  Role:           [IT support, vendor account manager, building inspector]
  Organization:   [Real vendor the target uses, or plausible third party]
  Contact Info:   [Burner phone, spoofed email, LinkedIn profile]
  Backstory:      [Why you are calling/visiting today]
  Verification:   [What to say if they try to verify your identity]
  Fallback:       [Graceful exit if the pretext fails]

Example -- IT Support Persona:
  Name:           Mark Chen
  Role:           Senior Support Engineer, Contoso IT Services
  Backstory:      Contoso manages the target's endpoint security.
                  Calling about a critical vulnerability patch that
                  requires the user to verify their credentials on
                  a portal to receive the update.
  Verification:   "You can check our contract reference CON-2024-0847
                  with your procurement team."
  Fallback:       "No problem, I will have your account manager
                  Sarah reach out to coordinate instead."

Psychological Triggers

Effective social engineering leverages cognitive biases. You apply these deliberately, not randomly.

Authority:
  - Impersonate someone with organizational power (CISO, VP, auditor)
  - Reference internal projects or systems by name
  - Use confident, directive language

Urgency / Scarcity:
  - "This must be resolved before end of business today"
  - "Your account will be locked if we cannot verify now"
  - Artificial deadlines compress the target's decision-making time

Social Proof:
  - "I have already confirmed this with your colleague [name]"
  - "Everyone in your department has completed this step"

Reciprocity:
  - Offer help before making a request ("I fixed that ticket for you")
  - Small favors create obligation

Commitment / Consistency:
  - Get the target to agree to small requests first
  - Escalate to the actual objective after initial compliance

Liking / Rapport:
  - Mirror the target's communication style
  - Find common ground (shared frustrations, industry knowledge)
  - Use their name; reference specifics from OSINT

Vishing (Voice Phishing)

Voice calls add a human element that email cannot replicate. The real-time interaction lets you adapt, overcome objections, and build trust dynamically.

VoIP Infrastructure Setup

Set up a dedicated voice infrastructure that supports caller ID spoofing and call recording.

# Option 1: Twilio for caller ID manipulation
# Register a Twilio account and purchase a local number

pip install twilio

python3 <<'PYEOF'
from twilio.rest import Client

account_sid = "ACXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
auth_token = "your_auth_token"
client = Client(account_sid, auth_token)

# Place a call with spoofed caller ID
call = client.calls.create(
    to="+1XXXXXXXXXX",        # Target number
    from_="+1XXXXXXXXXX",     # Your Twilio number (displayed)
    url="http://your-server.com/twiml/pretext.xml"  # TwiML script
)
print(f"Call SID: {call.sid}")
PYEOF

# TwiML script for IVR-style pretext
cat <<'XML' > pretext.xml
<?xml version="1.0" encoding="UTF-8"?>
<Response>
    <Say voice="alice">
        This is an automated message from your IT security team.
        A suspicious login was detected on your account.
        Press 1 to verify your identity and secure your account.
    </Say>
    <Gather numDigits="1" action="/handle-key" method="POST">
        <Say>Press 1 now.</Say>
    </Gather>
</Response>
XML
# Option 2: Asterisk PBX for full control
# Install Asterisk on a VPS
apt-get install asterisk

# Configure a SIP trunk with a VoIP provider that permits
# caller ID passthrough (check provider TOS for compliance)

# extensions.conf -- route outbound calls with custom CallerID
cat <<'CONF' >> /etc/asterisk/extensions.conf
[outbound-spoof]
exten => _X.,1,Set(CALLERID(num)=2125551234)
exten => _X.,n,Set(CALLERID(name)=TargetCorp IT)
exten => _X.,n,Dial(SIP/trunk/${EXTEN})
exten => _X.,n,Hangup()
CONF

asterisk -rx "dialplan reload"

Vishing Call Scripts

Prepare a script but deliver it conversationally. Reading from a script verbatim sounds robotic and raises suspicion.

Opening:
  "Hi, this is Mark from IT support. Am I speaking with [target name]?
   Great -- I am calling because we detected some unusual activity
   on your account this morning and I need to verify a few things
   with you to get it resolved."

Credential Harvesting:
  "I have pulled up your account and I can see the flagged activity.
   To confirm your identity before I can make any changes, could you
   verify the email address on file? ... And the password you are
   currently using, so I can confirm it was not changed by the
   unauthorized party?"

Objection Handling:
  Target: "I should not give my password over the phone."
  Response: "Absolutely, I understand the concern. What I can do
   instead is send you a secure link to reset it. Can you confirm
   the email I should send that to? I will stay on the line while
   you complete it."
   [Send EvilGinx2 link via email during the call]

Escalation to Manager:
  "If you would prefer, I can have my supervisor call you back.
   Let me transfer you to our team lead."
   [Transfer to another operator playing the supervisor role]

IVR System Exploitation

Interactive Voice Response systems often have hidden administrative menus, default PINs, or DTMF-accessible functions.

Common IVR reconnaissance:
  - Dial the main number and explore all menu options
  - Try pressing 0, #, or * at any prompt for operator/admin access
  - Enter default PINs: 0000, 1234, 9999, the last four of the main number
  - Listen for system identification (Cisco Unity, Avaya, Mitel)
  - Check for voicemail systems accessible via external dial-in
  - Test for DTMF injection during hold music or transfer sequences

Smishing (SMS Phishing)

SMS messages have higher open rates than email and are harder for organizations to filter. Carrier-level protections are improving but remain inconsistent.

SMS Gateway Setup and Delivery

# Twilio SMS with link tracking
from twilio.rest import Client

client = Client("ACXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX", "auth_token")

targets = [
    ("+1XXXXXXXXXX", "John"),
    ("+1XXXXXXXXXX", "Sarah"),
]

for number, name in targets:
    message = client.messages.create(
        body=f"Hi {name}, your VPN certificate expires today. "
             f"Renew now to avoid losing access: "
             f"https://vpn-targetcorp.com/renew?u={name.lower()}",
        from_="+1XXXXXXXXXX",  # Your Twilio number
        to=number
    )
    print(f"Sent to {name}: {message.sid}")

Smishing Pretext Patterns

IT / Security:
  "TargetCorp Security Alert: Unusual login detected from
   [city]. Verify your identity: https://secure-targetcorp.com/verify"

HR / Benefits:
  "[TargetCorp] Open enrollment deadline extended to Friday.
   Review your benefits selections: https://benefits-portal.com/enroll"

Delivery / Package:
  "USPS: Your package requires address confirmation before
   delivery. Confirm here: https://usps-verify.com/confirm"

MFA Push Fatigue (combined with credential stuffing):
  Send repeated MFA push notifications, then SMS:
  "TargetCorp IT: We are seeing repeated MFA prompts on your
   account. If this is not you, approve the next prompt so we
   can reset and secure your account."

Physical Social Engineering

Physical penetration testing requires you to bypass guards, locks, badge readers, and human vigilance to access restricted areas.

Tailgating and Piggybacking

The simplest physical access technique. You follow an authorized person through a controlled entry point.

Tailgating Approaches:
  - Hands full: Carry boxes, a laptop bag, and coffee. People
    hold doors for someone whose hands are full.
  - Smoking area: Join employees at the smoking area and walk
    back in with them. No badge tap needed.
  - Delivery persona: Wear a delivery uniform, carry a package
    addressed to someone inside. "I just need to drop this off."
  - Timing: Enter during high-traffic periods (8:30-9:00 AM,
    lunch return at 1:00 PM) when door-holding is routine.

Physical Appearance:
  - Dress code matters. Match the environment.
  - Corporate office: Business casual, lanyard with a badge
    (even a blank one -- people see the lanyard, not the badge).
  - Data center: Polo shirt, cargo pants, tool belt.
  - Construction/maintenance: Hi-vis vest, hard hat, clipboard.

RFID Badge Cloning with Proxmark3

M

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars6.8k
CategorySecurity
Updated6d ago
Forks896

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions