Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.
.claude/skills/cyberstrikeus-t1496-003-sms-pumping/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | -22% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 7% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 4% | 0% |
| case-19 | ✗→✓ | ▲ Improved | -13% | 0% |
| case-20 | ✓→✗ | ▼ Worse | 30% | 0% |
> Sub-technique of: T1496
Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability. SMS pumping is a type of telecommunications fraud whereby a threat actor first obtains a set of phone numbers from a telecommunications provider, then leverages a victim’s messaging infrastructure to send large amounts of SMS messages to numbers in that set. By generating SMS traffic to their phone number set, a threat actor may earn payments from the telecommunications provider.
Threat actors often use publicly available web forms, such as one-time password (OTP) or account verification fields, in order to generate SMS traffic. These fields may leverage services such as Twilio, AWS SNS, and Amazon Cognito in the background. In response to the large quantity of requests, SMS costs may increase and communication channels may become overwhelmed.
Platforms: SaaS
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Consider implementing CAPTCHA protection on forms that send messages via SMS.
| Finding | Severity | Impact | | -------------------------------- | -------- | ------ | | SMS Pumping technique applicable | Low | Impact |
| CWE ID | Title | | ------- | --------------------------------- | | CWE-400 | Uncontrolled Resource Consumption |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 30,672 | 34,928 | +14% | 1 | 1 | 0% | 4,069 | 5,361 | +32% | 0 | 0 | — |
case-02 | fail→fail | 27,147 | 37,641 | +39% | 1 | 1 | 0% | 3,520 | 5,969 | +70% | 0 | 0 | — |
case-03 | fail→pass | 20,682 | 11,625 | -44% | 1 | 1 | 0% | 2,287 | 1,777 | -22% | 0 | 0 | — |
case-04 | pass→pass | 18,046 | 12,517 | -31% | 1 | 1 | 0% | 2,267 | 1,814 | -20% | 0 | 0 | — |
case-05 | pass→pass | 18,223 | 15,903 | -13% | 1 | 1 | 0% | 2,045 | 2,599 | +27% | 0 | 0 | — |
case-11 | pass→pass | 18,990 | 8,221 | -57% | 1 | 1 | 0% | 1,889 | 1,226 | -35% | 0 | 0 | — |
case-06 | pass→pass | 17,796 | 12,226 | -31% | 1 | 1 | 0% | 2,010 | 1,828 | -9% | 0 | 0 | — |
case-07 | fail→pass | 16,025 | 9,929 | -38% | 1 | 1 | 0% | 1,457 | 1,562 | +7% | 0 | 0 | — |
case-08 | pass→pass | 15,425 | 11,848 | -23% | 1 | 1 | 0% | 2,304 | 1,758 | -24% | 0 | 0 | — |
case-09 | pass→pass | 14,568 | 8,728 | -40% | 1 | 1 | 0% | 2,064 | 1,089 | -47% | 0 | 0 | — |
case-10 | pass→pass | 21,210 | 3,749 | -82% | 1 | 1 | 0% | 2,329 | 1,330 | -43% | 0 | 0 | — |
case-12 | pass→pass | 13,118 | 2,970 | -77% | 1 | 1 | 0% | 1,769 | 1,250 | -29% | 0 | 0 | — |
case-13 | pass→pass | 18,971 | 19,608 | +3% | 1 | 1 | 0% | 2,166 | 3,048 | +41% | 0 | 0 | — |
case-14 | pass→pass | 14,638 | 12,734 | -13% | 1 | 1 | 0% | 1,465 | 1,830 | +25% | 0 | 0 | — |
case-15 | pass→pass | 7,594 | 11,490 | +51% | 1 | 1 | 0% | 1,259 | 1,809 | +44% | 0 | 0 | — |
case-16 | fail→pass | 9,203 | 10,898 | +18% | 1 | 1 | 0% | 1,517 | 1,572 | +4% | 0 | 0 | — |
case-17 | pass→pass | 10,929 | 8,468 | -23% | 1 | 1 | 0% | 868 | 1,149 | +32% | 0 | 0 | — |
case-18 | pass→pass | 6,918 | 7,277 | +5% | 1 | 1 | 0% | 1,263 | 1,128 | -11% | 0 | 0 | — |
case-19 | fail→pass | 15,609 | 4,430 | -72% | 1 | 1 | 0% | 1,690 | 1,472 | -13% | 0 | 0 | — |
case-20 | pass→fail | 23,976 | 19,518 | -19% | 1 | 1 | 0% | 3,049 | 3,967 | +30% | 0 | 0 | — |
case-21 | pass→pass | 18,057 | 20,209 | +12% | 1 | 1 | 0% | 2,789 | 3,907 | +40% | 0 | 0 | — |
case-22 | pass→pass | 16,532 | 17,935 | +8% | 1 | 1 | 0% | 2,143 | 2,786 | +30% | 0 | 0 | — |
case-23 | pass→pass | 11,952 | 11,534 | -3% | 1 | 1 | 0% | 1,993 | 2,819 | +41% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +13 percentage points is the difference between those two pass rates over the 23 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.