social-engineering

Simulate phishing, vishing, pretexting, and physical security tests for authorized assessments.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill social-engineering-leowsy-hashblue
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: social-engineering
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/social-engineering
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill social-engineering-leowsy-hashblue

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations struggle to assess and strengthen human-factor security against social-engineering attacks.

Core Features & Use Cases

  • Phishing - Email campaigns, spear phishing, credential harvesting
  • Pretexting - Scenario-based manipulation, impersonation
  • Vishing - Voice-based social engineering
  • Physical - Tailgating, badge cloning, dumpster diving

Quick Start

Define scope and authorization, then design and execute a controlled social-engineering campaign using predefined pretexts and tracking.

Frequently Asked Questions about social-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test my organization's resilience to phishing and vishing attacks?

To test resilience to phishing and vishing, you simulate email campaigns, credential harvesting, and voice-based manipulation. This evaluates human-factor security by identifying vulnerabilities in corporate environments without real malicious intent.

What is pretexting in social engineering security assessments?

Pretexting in social engineering is scenario-based manipulation and impersonation used during security assessments. It tests organizational defenses by creating fabricated situations to trick employees into revealing sensitive information or granting access.

Do I need explicit authorization to run a social engineering red-team engagement?

Yes, explicit authorization and written Rules of Engagement are required for social engineering red-team engagements. You must obtain documented consent before executing phishing, vishing, or physical security tests to ensure legal compliance.

Can I simulate physical security tests like tailgating and badge cloning?

Yes, you can simulate physical security tests including tailgating, badge cloning, and dumpster diving. These tests evaluate access-control vulnerabilities and in-person manipulation scenarios within corporate environments during red-team engagements.

How do I conduct a controlled social engineering campaign step by step?

To conduct a controlled social engineering campaign, define the scope and authorization first, then design and execute the simulation using predefined pretexts. Finally, track results, collect evidence, and perform a debriefing to strengthen defenses.

What are the limitations of social engineering security testing?

Limitations of social engineering security testing include the strict requirement for written Rules of Engagement and explicit consent. You should not use these simulations without proper authorization, as unauthorized phishing or physical tests violate compliance.