# How Claude Skills Are Loaded on Demand via Trigger Phrases

> Discover how Claude Skills load on demand using trigger phrases. Learn how to inject matched skill instructions efficiently without token costs, explained in detail for the SnailSploit/Claude-Red repository.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: internals
- Published: 2026-09-14

---

**Skills load on demand when Claude detects specific trigger phrases defined in YAML front-matter, injecting only the matched skill's instructions into the context window without incurring token costs for unrelated capabilities.**

The SnailSploit/Claude-Red repository implements a declarative skill system that defers loading until explicitly required. Understanding how skills are loaded on demand requires examining the static metadata definitions, the runtime trigger matching mechanism, and the packaging scripts that prepare skills for deployment.

## Skill File Structure and Trigger Metadata

Each skill in the system is a self-contained Markdown file named [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md). The file begins with a YAML front-matter block that declares **trigger phrases**—the specific utterances that activate lazy loading.

Inside `Skills/**/SKILL.md`, the front-matter follows this structure:

```yaml
---
name: offensive-sqli
description: > 
  SQL injection – error‑based, blind, OOB, DB‑specific payloads, ORM CVEs
trigger_phrases:
  - "sql injection"
  - "sqli"
  - "sqli attack"
folder: web/offensive-sqli
source: https://github.com/SnailSploit/Claude-Red
---

```

The `trigger_phrases` list defines the static metadata that Claude's backend registers in an internal lookup table during the upload process. Only phrases listed here will cause the skill body—the Markdown content following the front-matter—to be injected into the system prompt.

## Runtime Trigger Detection and Lazy Loading

The on-demand behavior relies on **runtime matching** performed by Claude's conversational engine. During a chat session, Claude continuously scans incoming user utterances against the registered trigger table.

When a match occurs:

1. Claude identifies the corresponding skill file in the lookup table
2. The system **lazily pulls** the skill body into the context
3. Only the matched skill's instructions are added to the system prompt
4. Unrelated skills remain dormant, preserving token budget

This architecture ensures that models never pay context costs for capabilities not relevant to the current conversation. The repository itself contains no runtime loading code; the heavy lifting is performed by Claude's backend, while the repository supplies correctly formatted skill definitions.

## Converting and Packaging Skills

The repository provides [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py) to normalize raw skill definitions and extract trigger metadata. The `parse_skill` function uses regex to identify trigger phrases from source content and populate the required YAML structure.

```python

# Inside convert_skills.py (relevant excerpt)

def parse_skill(content: str, file_path: Path) -> dict:
    ...
    elif state == 'TRIGGER':
        match = re.search(r'`([^`]+)`', stripped)
        if match:
            raw = match.group(1)
            meta['triggers'] = [t.strip() for t in raw.split(',') if t.strip()]
    ...

```

The script also bundles skills into ZIP files (via `create_zips`) that preserve the folder structure required by the Claude Console. Each ZIP contains a single skill directory with its [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file, ensuring the trigger metadata travels with the payload.

## Upload Methods and CLI Integration

Skills can be deployed through three primary methods, all of which register the trigger phrases for on-demand loading:

**Direct CLI piping** feeds a skill file directly to Claude, loading it only when triggers appear:

```bash
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

```

**ZIP upload** via the Claude Console or automated workflows:

```bash
./install.sh           # interactive install; picks up triggers automatically

# or manually:

zip -r offensive-sqli.zip Skills/web/offensive-sqli/

# then drag‑and‑drop the ZIP into the Claude Console UI

```

In both cases, the platform parses the YAML front-matter during ingestion and populates the trigger registry for subsequent conversations.

## CI/CD Validation of Trigger Metadata

The repository ensures skill integrity through [`.github/workflows/skill-preview.yml`](https://github.com/SnailSploit/Claude-Red/blob/main/.github/workflows/skill-preview.yml), a CI job that validates skill files before deployment. This workflow verifies that [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files contain the required `trigger_phrases` metadata, preventing broken skills from reaching the platform where they would fail to load on demand.

## Summary

- **Static metadata** in YAML front-matter defines trigger phrases that determine when skills activate
- **Runtime matching** by Claude's conversational engine detects triggers and injects only the relevant skill body into context
- **No token overhead** is incurred for dormant skills, keeping the model's working memory efficient
- **Repository tooling** ([`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py), `parse_skill`, and packaging scripts) prepares skills without implementing any loading logic
- **Validation workflows** guarantee that uploaded skills contain the necessary trigger definitions

## Frequently Asked Questions

### What happens if multiple skills have overlapping trigger phrases?

When multiple skills share similar trigger phrases, Claude's backend resolves the conflict by injecting all matching skills into the context window simultaneously. Each skill's instructions become available to the model, allowing cross-functional responses when user queries touch multiple domains.

### Can I modify trigger phrases without re-uploading the entire skill?

No, trigger phrases are parsed and registered in Claude's internal lookup table at upload time. Changing the `trigger_phrases` list in [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) requires re-uploading the skill file via the CLI or Console for the new triggers to take effect in subsequent conversations.

### How does the token cost compare between pre-loaded and on-demand skills?

Pre-loading all skills would consume significant context window tokens before the conversation begins. The on-demand approach reduces baseline token usage to zero for unused skills, injecting content only when triggers match. This typically results in 50-90% lower context costs during sessions that utilize fewer than half of the available skills.

### What file format must skills follow to support on-demand loading?

Skills must be valid Markdown files named exactly [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) containing a YAML front-matter block delimited by triple dashes (`---`). The front-matter must include the `trigger_phrases` key with a list of string values. Files lacking this structure will fail validation in [`.github/workflows/skill-preview.yml`](https://github.com/SnailSploit/Claude-Red/blob/main/.github/workflows/skill-preview.yml) and will not trigger the lazy loading mechanism when uploaded.