How Is the Claude-Red Repository Organized?

The Claude-Red repository follows a modular, category-driven architecture centered on the Skills/ directory, containing 78 offensive security methodologies organized into 23 distinct attack surface categories, supported by automation scripts and CI pipelines.

Claude-Red is an open-source library of offensive security "skills" designed for drop-in integration with Claude's system prompts. According to the SnailSploit/Claude-Red source code, the repository prioritizes discoverability and modularity, with each attack methodology stored as a standalone Markdown file within a hierarchical category structure.

Top-Level Directory Architecture

The repository root contains eight critical components that manage installation, conversion, and documentation:

  • README.md — The human-readable entry point that provides quick-start instructions, category enumeration, and a searchable skill index linking directly to every SKILL.md file.
  • install.sh — An interactive Bash script that handles repository cloning, sparse checkouts of specific categories, and placement of skills into the Claude skill directory.
  • convert_skills.py — A Python utility that parses each Markdown skill file and emits the JSON format required by Claude's Skills API.
  • claude-skills.json — The generated JSON manifest produced by convert_skills.py, used by Claude's web UI and API for bulk skill import.
  • MINDMAP.md — A Mermaid-based visualization file that mirrors the category hierarchy for rapid navigation.
  • Skills/ — The core content directory containing 23 category folders (e.g., web/, wireless/, cloud/) with 78 individual skill subdirectories.
  • assets/ — Visual assets including banner.png displayed in the README header.
  • .github/workflows/ — CI pipelines including python-publish.yml that automate JSON generation, linting, and artifact publishing on every push to main.

The Skills/ Directory Hierarchy

The Skills/ directory implements a strict category → skill mapping. Each top-level subfolder represents an attack surface domain, containing individual skill directories that each house a single SKILL.md file.

For example, the web category contains 15 skills including:


Skills/
├─ web/
│   ├─ offensive-sqli/
│   │   └─ SKILL.md
│   ├─ offensive-xss/
│   │   └─ SKILL.md
│   └─ ...
├─ wireless/
│   ├─ offensive-wifi/
│   │   └─ SKILL.md
│   └─ offensive-wpa2-psk/
│       └─ SKILL.md
├─ cloud/
│   └─ offensive-cloud/
│       └─ SKILL.md
├─ infrastructure/
│   ├─ offensive-initial-access/
│   │   └─ SKILL.md
│   └─ ...

The repository includes 23 total categories covering web, wireless, cloud, mobile, iot, infrastructure, exploit-dev, fuzzing, auth, active-directory, and AI attack surfaces. Each SKILL.md file contains a concrete methodology description formatted for direct injection into Claude's system prompt.

Supporting Automation Scripts

Two primary scripts manage the repository's operational workflow:

install.sh provides three installation modes:

  1. Interactive full-repository cloning and installation.
  2. Sparse checkout of single categories (e.g., --category web).
  3. Targeted placement into custom Claude skill directories (--target ~/.claude/skills).

convert_skills.py recursively traverses the Skills/ directory, parsing each SKILL.md file to construct the claude-skills.json manifest. This transformation enables Claude's Skills loader to ingest the entire library as a structured JSON object rather than individual Markdown files.

Continuous Integration Workflows

The .github/workflows/python-publish.yml pipeline automates repository maintenance by:

  • Executing convert_skills.py to regenerate claude-skills.json on every commit.
  • Linting Markdown files for formatting consistency.
  • Publishing the JSON artifact as a downloadable release asset.

This ensures the generated manifest remains synchronized with the source SKILL.md files in the Skills/ directory.

Practical Usage Examples

Install the Complete Library

./install.sh

This clones the repository and copies all 78 skills into the default Claude skill path.

Install a Single Category

./install.sh --target ~/.claude/skills --category web

This performs a sparse checkout, transferring only the Skills/web/ directory contents.

Load a Skill Directly via CLI

cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

This pipes the SQL injection methodology directly into Claude's system prompt without permanent installation.

Regenerate the JSON Manifest

python convert_skills.py

This updates claude-skills.json to reflect any modifications to the underlying Markdown files.

Summary

  • The Claude-Red repository organizes 78 offensive security skills into 23 category folders under Skills/.
  • Each skill resides in its own subdirectory containing a single SKILL.md file describing a specific attack methodology.
  • install.sh enables selective or full installation into Claude's skill directory.
  • convert_skills.py transforms the Markdown source into claude-skills.json for API consumption.
  • The .github/workflows/python-publish.yml pipeline ensures the JSON manifest remains synchronized with source files.
  • MINDMAP.md provides visual navigation of the entire skill taxonomy.

Frequently Asked Questions

What is the purpose of the SKILL.md files?

Each SKILL.md file contains a complete offensive security methodology written in Markdown format. These files serve as the source of truth for Claude's system prompts, describing specific attack techniques, tools, and procedures that Claude can reference during security assessments.

How does the install.sh script work?

The install.sh script performs interactive installation with support for sparse checkouts. It can clone the entire repository or extract individual categories using Git's sparse-checkout functionality, then relocate the selected SKILL.md files to a user-specified Claude skill directory such as ~/.claude/skills.

What is the difference between the Markdown skills and claude-skills.json?

The Markdown files in Skills/ are human-readable source documents. The claude-skills.json file is a machine-generated artifact produced by convert_skills.py that structures these methodologies into JSON objects compliant with Claude's Skills API, enabling bulk import through the web interface or programmatic API calls.

How are skills categorized within the repository?

Skills are organized hierarchically: the Skills/ directory contains category folders (e.g., web/, wireless/, cloud/), each containing subdirectories for individual skills. For example, the SQL injection skill resides at Skills/web/offensive-sqli/SKILL.md, following a consistent naming convention that prefixes skill directories with offensive- to denote their attack-focused nature.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →