Physical assessment
SkillSecurityRun an authorized physical social-engineering assessment, tailgating, pretext entry, badge/RFID cloning checks, and media-drop tests, to measure physical and human access controls safely. Load after social-eng-methodology when the objective is on-site. Signals: "physical pentest", "test our building access", "tailgating", "badge cloning", "USB drop", "can we get into the office/data center". Requires a carried authorization letter.
Use Physical assessment in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Physical assessment and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Physical assessment skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/social-eng/social-eng-physical/SKILL.md and read by Ahel’s review.
When it applies
The engagement authorizes on-site testing (cleared via social-eng-methodology) with a defined
objective — reach a floor/room, plug into the network, or drop test media — to measure physical
access controls and staff response. Physical work has the highest real-world risk (police, injury,
genuine alarm), so the guardrails are non-negotiable.
Why it works
Physical security leans on people extending courtesy (holding a door), trusting a uniform or a confident manner, and following habit over procedure. A tester with a plausible pretext and a hi-vis vest often walks past controls that are technically sound — the finding is the procedural/behavioral gap, captured with minimum intrusion.
Method
- Carry authorization. A signed get-out-of-jail letter on you at all times, plus a live emergency contact (client-side) reachable to confirm the test instantly to security or police. No letter → no entry.
- Objective and stop-line, agreed in writing. Reach the target and prove it (a photo of a defined marker, a benign network beacon) — then stop. No damage, no real data theft, no accessing others' belongings.
- Recon the site (public, non-intrusive): entry points, badge readers, delivery/smoking doors, shift changes, dress code — enough for a credible pretext.
- Choose the least-intrusive technique for the objective:
- Tailgating / pretext entry — follow a group or present as delivery/contractor/new-hire to test door and reception controls.
- Badge/RFID exposure check — assess whether badges are clonable at a realistic distance and whether readers accept a cloned/observed credential (demonstrate the exposure; don't build a persistent illicit credential).
- Media drop — leave tracked, benign test USBs/QR flyers to measure plug-in/scan rate; the payload only phones home a token, it does nothing to the host.
- Prove and withdraw. Capture the agreed proof at the stop-line and leave; do not push further "because it's working".
- Debrief and restore. Recover any dropped media where feasible, disable beacons, and report.
Gotchas
- Present the letter the instant you're challenged — never bluff past a security guard or police; disclose and let the emergency contact confirm.
- Two-person rule for higher-risk entries where the RoE allows, for safety and witnessing.
- Benign media only — a test USB beacons a token; it must not deploy real malware or alter the host. The metric is "someone plugged it in".
- Respect people and property — no searching desks/bags, no coercion, no entering genuinely restricted safety areas beyond scope.
- Reversible and clean — leave the site as found; account for every dropped item.
Verify success
The agreed proof-of-access (marker photo or benign beacon) or a media-drop plug-in metric, obtained at the stop-line with authorization carried, nothing damaged or taken, and all test artifacts accounted for — feeding a physical-controls report and remediation.
References
MITRE ATT&CK T1091 (Replication Through Removable Media), T1200 (Hardware Additions), T1566.004; standard physical-pentest RoE and safety practice.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
social-eng-physical- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent