Sep 12, 2026
Run Authorized Red Team Work with Claude-Red's 78 Offensive Skills
Install a 78-skill offensive security library that primes Claude with red team methodology for 23 attack surface categories.
Offensive security work needs methodology, not improvisation. Claude-Red is a curated library of 78 structured SKILL.md files that turn Claude into a context-aware red team operator across 23 categories, from SQL injection to Active Directory certificate services abuse.
Why This Skill Matters
A generic prompt produces a generic checklist. Each Claude-Red skill is a SKILL.md file that primes Claude with expert-level methodology for one attack surface — the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers, so you do not pay context for skills you are not using. The README scopes the use cases to authorized red team engagements, bug bounty triage, security research, CTF preparation, operator training, and methodical attack surface exploration. The repo sits at 3,164 stars on the SkillMap leaderboard.
Installation
Clone the full library into your Claude skills directory:
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red
For a single category, use a sparse checkout:
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory
An install.sh script is also available — run it interactively, with --target ~/.claude/skills, or with --category web for one category.
Real Workflow: Triage a SQL Injection Finding
- Install the library as above, then start a Claude session inside the engagement scope.
- Mention the vulnerability class in conversation. The README documents that conversational triggers auto-load matching skills — mentioning SQL injection loads
offensive-sqli. - Work the methodology. Per the skill index,
offensive-sqlicovers error-based, blind, and out-of-band injection, database-specific payloads, and ORM CVEs. - Branch into adjacent surfaces as the finding develops:
offensive-waf-bypassfor filter evasion, and the Auth & Identity category'soffensive-jwtwhen token handling is in scope.
A second workflow closes the engagement. Load offensive-reporting from the utility category and have Claude draft the finding write-up — the index describes this skill as covering CVSS scoring, evidence standards, and executive summaries.
Tips
- Start with
offensive-fast-checking, a triage skill of quick-win identification checklists, before diving into a deep class. - The two largest categories are Web Application (16 skills, OWASP Top 10 through business logic) and Wireless (14 skills, from WPA2/3 to Zigbee, Z-Wave, and sub-GHz).
- Claude Code users can pipe a single skill without installing the library:
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -. - The roadmap targets roughly 130 skills across 23+ categories;
CHANGELOG.mdtracks what shipped in each phase.
When Not to Use This
Authorized testing only — keep it inside engagements, bug bounty scope, labs, and CTFs. And know what the README documents: drop-in SKILL.md methodology files only — bring your own scanners, proxies, and exploits for execution.
See the leaderboard for more skills.