claude-red
A library of offensive security skills for the Claude Skills system: red team methodology across dozens of areas
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Guides offensive actions against systems
- Use without the target owner's authorization is illegal
- Assumes a trained professional
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/claude-redDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add snailsploit/claude-red --skill offensive-active-directory offensive-ai-security offensive-api-abuse offensive-api-security offensive-jwt offensive-oauth offensive-cicd-pipeline offensive-cicd-secrets offensive-cloud offensive-container-escape offensive-k8s-attacks offensive-crypto-attacks offensive-tls-attacks offensive-basic-exploitation offensive-crash-analysis offensive-exploit-dev-course offensive-exploit-development offensive-mitigations offensive-toctou offensive-anti-forensics offensive-c2-frameworks offensive-bug-identification offensive-fuzzing-course offensive-fuzzing offensive-vuln-classes offensive-advanced-redteam offensive-edr-evasion offensive-initial-access offensive-keylogger-arch offensive-shellcode offensive-windows-boundaries offensive-windows-mitigations offensive-iot offensive-mobile offensive-network-attacks offensive-data-exfiltration offensive-lateral-movement offensive-persistence offensive-linux-privesc offensive-windows-privesc offensive-osint-methodology offensive-osint offensive-phishing offensive-social-engineering offensive-dependency-confusion offensive-supply-chain offensive-wifi offensive-wifi-recon offensive-wpa2-psk offensive-wpa3-sae offensive-wpa-enterprise offensive-wps offensive-evil-twin offensive-krack-fragattacks offensive-deauth-disassoc offensive-bluetooth-ble offensive-bluetooth-classic offensive-zigbee-thread-matter offensive-z-wave offensive-lorawan-sub-ghz offensive-fast-checking offensive-reporting offensive-sqli offensive-xss offensive-ssrf offensive-ssti offensive-xxe offensive-idor offensive-file-upload offensive-rce offensive-deserialization offensive-race-condition offensive-request-smuggling offensive-open-redirect offensive-parameter-pollution offensive-graphql offensive-waf-bypass offensive-business-logic -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Clone the repository into the skills directory: git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red. Install specific categories with ./install.sh --category web.
Other ways from the author
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-redSkills load on conversational triggers. Use sparse checkout for specific areas.
This is third-party code. Review the repository files before installing.
What it does
claude-red is a set of structured SKILL.md files, each priming the agent with expert methodology for one offensive security area: web vulnerabilities, Active Directory, cloud, containers and Kubernetes, exploit development, fuzzing, EDR evasion, C2 work and more. Skills load on conversational triggers, so context is spent only on the topic in use. The authors frame it for authorized red team engagements, bug bounty triage, security research, CTF preparation and operator training. The skills carry methodology and tooling guidance rather than ready-made malware.
Who it is for. For offensive security professionals and bug bounty participants working within authorized engagements.
Good fit when
- You need expert methodology for a specific attack surface in an authorized engagement
- You are preparing for a CTF or training operators
- You want to triage bug bounty findings methodically
Not a fit when
- You have no authorization from the system owner to test
- You need defense and hardening rather than attack methodology
Example request
Help me plan an SQL injection assessment of a web app within an authorized testLimitations
The skills provide methodology and guidance but do not run attacks themselves and do not replace authorization to test. Using the techniques against systems you do not own without the owner's consent is illegal. The material is in English and assumes a trained professional.
How to disable. Remove the claude-red folder from the skills directory, for example ~/.claude/skills/claude-red.
Security check
- Guides offensive actions against systems
- Use without the target owner's authorization is illegal
- Assumes a trained professional
README in short
The README describes claude-red as a curated library of offensive security skills for the Claude Skills system. Each skill is a SKILL.md file that sets methodology for one attack surface and loads on conversational triggers. It names use cases: authorized red team engagements, bug bounty, research, CTF and training. Setup: clone into the skills directory, sparse-checkout specific categories, the install.sh script or pasting the content into a system prompt. MIT licensed.
FAQ
Do the skills run attacks themselves?
No. They are SKILL.md files with methodology and tooling guidance; a professional performs the actions within an authorized engagement.
How do I install only part?
Use sparse checkout or install.sh with a category flag to install only the areas you choose.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents