social-engineering

Assess human-factor security risks through authorized social engineering simulations.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill social-engineering
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: social-engineering
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/social-engineering
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill social-engineering

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Social engineering testing helps organizations identify human-factor weaknesses in security defenses and improve resilience against manipulation.

Core Features & Use Cases

  • Phishing, pretexting, vishing, and physical social engineering campaigns to evaluate user awareness
  • Evidence collection and reporting to guide training and policy improvements
  • Customizable scope and authorization workflows for compliant testing

Quick Start

Launch an authorized social engineering campaign to identify gaps and strengthen resilience.

Frequently Asked Questions about social-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is social engineering testing and how does it assess human-factor security risks?

Social engineering testing assesses human-factor security risks through controlled phishing, pretexting, vishing, and physical security simulations. These campaigns evaluate user awareness and identify manipulation vulnerabilities to guide training and policy improvements.

How do I run an authorized phishing or vishing campaign to strengthen security awareness?

Run authorized phishing or vishing campaigns by defining a clear scope, securing authorizations, executing the simulation, and capturing evidence. This process generates reports that identify gaps and enable targeted remediation for user awareness.

Do I need defined scope and authorizations before executing a social engineering simulation?

Yes, social engineering simulations require clearly defined scope and authorization workflows before execution. This ensures compliant testing while capturing evidence and generating reports to guide security remediation and policy improvements.

What's the best way to capture evidence during a pretexting or physical security test?

The best way to capture evidence during pretexting or physical security testing is through controlled campaign workflows. This evidence collection directly enables report generation to guide training and policy improvements for human-factor defenses.

When should I not use social engineering simulations for security testing?

Social engineering simulations should not be used without clearly defined scope, authorizations, and evidence capture workflows. Attempting security testing without these controlled prerequisites prevents compliant execution and limits actionable remediation reporting.