Sep 12, 2026

Run Authorized Red Team Work with Claude-Red's 78 Offensive Skills

Install a 78-skill offensive security library that primes Claude with red team methodology for 23 attack surface categories.

#tutorial#security

Offensive security work needs methodology, not improvisation. Claude-Red is a curated library of 78 structured SKILL.md files that turn Claude into a context-aware red team operator across 23 categories, from SQL injection to Active Directory certificate services abuse.

Why This Skill Matters

A generic prompt produces a generic checklist. Each Claude-Red skill is a SKILL.md file that primes Claude with expert-level methodology for one attack surface — the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers, so you do not pay context for skills you are not using. The README scopes the use cases to authorized red team engagements, bug bounty triage, security research, CTF preparation, operator training, and methodical attack surface exploration. The repo sits at 3,164 stars on the SkillMap leaderboard.

Installation

Clone the full library into your Claude skills directory:

git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

For a single category, use a sparse checkout:

git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

An install.sh script is also available — run it interactively, with --target ~/.claude/skills, or with --category web for one category.

Real Workflow: Triage a SQL Injection Finding

  1. Install the library as above, then start a Claude session inside the engagement scope.
  2. Mention the vulnerability class in conversation. The README documents that conversational triggers auto-load matching skills — mentioning SQL injection loads offensive-sqli.
  3. Work the methodology. Per the skill index, offensive-sqli covers error-based, blind, and out-of-band injection, database-specific payloads, and ORM CVEs.
  4. Branch into adjacent surfaces as the finding develops: offensive-waf-bypass for filter evasion, and the Auth & Identity category's offensive-jwt when token handling is in scope.

A second workflow closes the engagement. Load offensive-reporting from the utility category and have Claude draft the finding write-up — the index describes this skill as covering CVSS scoring, evidence standards, and executive summaries.

Tips

  • Start with offensive-fast-checking, a triage skill of quick-win identification checklists, before diving into a deep class.
  • The two largest categories are Web Application (16 skills, OWASP Top 10 through business logic) and Wireless (14 skills, from WPA2/3 to Zigbee, Z-Wave, and sub-GHz).
  • Claude Code users can pipe a single skill without installing the library: cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -.
  • The roadmap targets roughly 130 skills across 23+ categories; CHANGELOG.md tracks what shipped in each phase.

When Not to Use This

Authorized testing only — keep it inside engagements, bug bounty scope, labs, and CTFs. And know what the README documents: drop-in SKILL.md methodology files only — bring your own scanners, proxies, and exploits for execution.


See the leaderboard for more skills.