set

Automate spear-phishing, credential harvesting, and payload delivery for penetration testing.

15|1|Updated Feb 12, 2026
One-click install
npx skills add https://github.com/AeonDave/malskill --skill set
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: set
Source: https://github.com/AeonDave/malskill/tree/main/offensive-tools/social-engineering/set
Command: npx skills add https://github.com/AeonDave/malskill --skill set

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill automates complex social engineering tasks, streamlining phishing campaigns, credential harvesting, and payload delivery.

Core Features & Use Cases

  • Spear-Phishing: Create and send targeted phishing emails with malicious payloads.
  • Credential Harvesting: Clone websites to capture user credentials.
  • Payload Delivery: Automate the delivery of exploits and malicious payloads.
  • Use Case: You need to simulate a phishing attack to test your organization's security awareness. Use this Skill to clone a legitimate-looking login page and send a targeted email to employees, capturing any credentials they enter.

Quick Start

Use the set skill to clone the website https://example.com and capture credentials.

Frequently Asked Questions about set

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate phishing campaigns and credential harvesting for penetration testing?

You can automate phishing campaigns and credential harvesting by using this Skill to clone legitimate websites and capture user credentials entered on the cloned login pages. It streamlines social engineering attacks for security awareness training.

Can I clone a website to capture user credentials for a security awareness test?

Yes, you can clone a website to capture user credentials. The Skill automates website cloning to harvest credentials, allowing you to simulate real-world attack vectors and test your organization's security posture.

How do I automate payload delivery and send spear-phishing emails with malicious payloads?

You can automate payload delivery by using the spear-phishing feature to create and send targeted emails containing malicious payloads. This simulates real-world attack vectors for penetration testing purposes.

Do I need Python 3 to run social engineering toolkit automation?

Yes, you need Python 3 and specific system configurations to run this social engineering automation. The Skill requires this environment to properly execute spear-phishing, credential harvesting, and payload delivery tasks.

What is the best way to simulate social engineering attacks for security awareness training?

The best way to simulate social engineering attacks is to automate spear-phishing, website cloning for credential harvesting, and payload delivery. This allows you to test employee responses to real-world attack vectors effectively.

Are there limitations when using automated website cloning for credential harvesting?

Limitations include requiring specific system configurations and Python 3 to execute the automated website cloning and credential harvesting. You must ensure your environment matches these prerequisites before running the social engineering simulations.