# How Is the Claude-Red Repository Organized?

> Explore the Claude-Red repository organization. Discover its modular structure, 78 offensive security methodologies, and 23 attack surface categories, all powered by automation.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: getting-started
- Published: 2026-09-14

---

**The Claude-Red repository follows a modular, category-driven architecture centered on the `Skills/` directory, containing 78 offensive security methodologies organized into 23 distinct attack surface categories, supported by automation scripts and CI pipelines.**

Claude-Red is an open-source library of offensive security "skills" designed for drop-in integration with Claude's system prompts. According to the SnailSploit/Claude-Red source code, the repository prioritizes discoverability and modularity, with each attack methodology stored as a standalone Markdown file within a hierarchical category structure.

## Top-Level Directory Architecture

The repository root contains eight critical components that manage installation, conversion, and documentation:

- **[`README.md`](https://github.com/SnailSploit/Claude-Red/blob/main/README.md)** — The human-readable entry point that provides quick-start instructions, category enumeration, and a searchable skill index linking directly to every [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file.
- **[`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh)** — An interactive Bash script that handles repository cloning, sparse checkouts of specific categories, and placement of skills into the Claude skill directory.
- **[`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py)** — A Python utility that parses each Markdown skill file and emits the JSON format required by Claude's Skills API.
- **[`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json)** — The generated JSON manifest produced by [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py), used by Claude's web UI and API for bulk skill import.
- **[`MINDMAP.md`](https://github.com/SnailSploit/Claude-Red/blob/main/MINDMAP.md)** — A Mermaid-based visualization file that mirrors the category hierarchy for rapid navigation.
- **`Skills/`** — The core content directory containing 23 category folders (e.g., `web/`, `wireless/`, `cloud/`) with 78 individual skill subdirectories.
- **`assets/`** — Visual assets including `banner.png` displayed in the README header.
- **`.github/workflows/`** — CI pipelines including [`python-publish.yml`](https://github.com/SnailSploit/Claude-Red/blob/main/python-publish.yml) that automate JSON generation, linting, and artifact publishing on every push to `main`.

## The Skills/ Directory Hierarchy

The `Skills/` directory implements a strict **category → skill** mapping. Each top-level subfolder represents an attack surface domain, containing individual skill directories that each house a single [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file.

For example, the `web` category contains 15 skills including:

```

Skills/
├─ web/
│   ├─ offensive-sqli/
│   │   └─ SKILL.md
│   ├─ offensive-xss/
│   │   └─ SKILL.md
│   └─ ...
├─ wireless/
│   ├─ offensive-wifi/
│   │   └─ SKILL.md
│   └─ offensive-wpa2-psk/
│       └─ SKILL.md
├─ cloud/
│   └─ offensive-cloud/
│       └─ SKILL.md
├─ infrastructure/
│   ├─ offensive-initial-access/
│   │   └─ SKILL.md
│   └─ ...

```

The repository includes 23 total categories covering **web**, **wireless**, **cloud**, **mobile**, **iot**, **infrastructure**, **exploit-dev**, **fuzzing**, **auth**, **active-directory**, and **AI** attack surfaces. Each [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file contains a concrete methodology description formatted for direct injection into Claude's system prompt.

## Supporting Automation Scripts

Two primary scripts manage the repository's operational workflow:

**[`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh)** provides three installation modes:

1. Interactive full-repository cloning and installation.
2. Sparse checkout of single categories (e.g., `--category web`).
3. Targeted placement into custom Claude skill directories (`--target ~/.claude/skills`).

**[`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py)** recursively traverses the `Skills/` directory, parsing each [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file to construct the [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) manifest. This transformation enables Claude's Skills loader to ingest the entire library as a structured JSON object rather than individual Markdown files.

## Continuous Integration Workflows

The [`.github/workflows/python-publish.yml`](https://github.com/SnailSploit/Claude-Red/blob/main/.github/workflows/python-publish.yml) pipeline automates repository maintenance by:

- Executing [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py) to regenerate [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) on every commit.
- Linting Markdown files for formatting consistency.
- Publishing the JSON artifact as a downloadable release asset.

This ensures the generated manifest remains synchronized with the source [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files in the ` Skills/` directory.

## Practical Usage Examples

### Install the Complete Library

```bash
./install.sh

```

This clones the repository and copies all 78 skills into the default Claude skill path.

### Install a Single Category

```bash
./install.sh --target ~/.claude/skills --category web

```

This performs a sparse checkout, transferring only the `Skills/web/` directory contents.

### Load a Skill Directly via CLI

```bash
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

```

This pipes the SQL injection methodology directly into Claude's system prompt without permanent installation.

### Regenerate the JSON Manifest

```bash
python convert_skills.py

```

This updates [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) to reflect any modifications to the underlying Markdown files.

## Summary

- The **Claude-Red** repository organizes 78 offensive security skills into 23 category folders under `Skills/`.
- Each skill resides in its own subdirectory containing a single [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file describing a specific attack methodology.
- **[`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh)** enables selective or full installation into Claude's skill directory.
- **[`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py)** transforms the Markdown source into **[`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json)** for API consumption.
- The **[`.github/workflows/python-publish.yml`](https://github.com/SnailSploit/Claude-Red/blob/main/.github/workflows/python-publish.yml)** pipeline ensures the JSON manifest remains synchronized with source files.
- **[`MINDMAP.md`](https://github.com/SnailSploit/Claude-Red/blob/main/MINDMAP.md)** provides visual navigation of the entire skill taxonomy.

## Frequently Asked Questions

### What is the purpose of the SKILL.md files?

Each [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file contains a complete offensive security methodology written in Markdown format. These files serve as the source of truth for Claude's system prompts, describing specific attack techniques, tools, and procedures that Claude can reference during security assessments.

### How does the install.sh script work?

The [`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh) script performs interactive installation with support for sparse checkouts. It can clone the entire repository or extract individual categories using Git's sparse-checkout functionality, then relocate the selected [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files to a user-specified Claude skill directory such as `~/.claude/skills`.

### What is the difference between the Markdown skills and claude-skills.json?

The Markdown files in `Skills/` are human-readable source documents. The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file is a machine-generated artifact produced by [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py) that structures these methodologies into JSON objects compliant with Claude's Skills API, enabling bulk import through the web interface or programmatic API calls.

### How are skills categorized within the repository?

Skills are organized hierarchically: the `Skills/` directory contains category folders (e.g., `web/`, `wireless/`, `cloud/`), each containing subdirectories for individual skills. For example, the SQL injection skill resides at [`Skills/web/offensive-sqli/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/web/offensive-sqli/SKILL.md), following a consistent naming convention that prefixes skill directories with `offensive-` to denote their attack-focused nature.