How the Claude-Red `install.sh` Script Works: Internal Workings Explained

The install.sh script is a self-contained Bash installer that copies offensive-security SKILL.md files into Claude's skills directory, supporting flags for dry runs, category filtering, and custom targets while providing fallback mechanisms for maximum compatibility.

The internal workings of the install.sh script in the SnailSploit/Claude-Red repository provide a robust, user-friendly mechanism for deploying penetration testing skills to Claude Code. This Bash script automates the placement of categorized security documentation into the appropriate Claude configuration directory. Understanding its execution flow reveals a carefully structured approach to error handling, option parsing, and cross-platform compatibility.

Script Architecture and Initialization

The script begins with strict error handling at lines [17-20], utilizing set -euo pipefail to ensure execution halts on unhandled errors, undefined variables, or pipeline failures. This defensive programming approach prevents partial installations and ensures predictable behavior across different environments.

Immediately following the safety settings, the script establishes three critical path variables:

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
SKILLS_DIR="$SCRIPT_DIR/Skills"
DEFAULT_TARGET="${HOME}/.claude/skills/claude-red"

These variables define the source location (SKILLS_DIR pointing to the bundled Skills folder), the script's location (SCRIPT_DIR), and the default installation target (the Claude skills directory within the user's home folder).

Command-Line Interface and Option Parsing

The install.sh script implements a robust argument parser using a while loop with a case statement (lines [41-49]), enabling both interactive and automated deployment scenarios. Users can invoke the following flags:

  • --target <path> — Overrides the default installation destination
  • --category <name> — Restricts the copy operation to a single skill category
  • --dry-run — Previews actions without modifying the filesystem
  • --list — Displays available categories and file counts
  • -h or --help — Shows usage information

When invoked with --list, the list_categories function (lines [52-55]) enumerates each subdirectory under Skills, counts the contained SKILL.md files, and exits cleanly. This implementation allows the script to function in CI/CD pipelines (unattended mode with explicit flags) or interactive sessions (prompting for missing parameters).

Validation and Pre-Execution Checks

Before any file operations occur, the script performs comprehensive validation (lines [57-78]). First, it verifies that the Skills directory exists at the relative path, aborting with a descriptive error if the source bundle is missing.

When no --target flag is provided, the script engages interactive mode, prompting the user to confirm or modify the default target path. If a specific category is requested, the script validates the subdirectory's existence; if missing, it displays the available categories before exiting cleanly.

Installation Logic: From Source to Destination

The script determines source and destination paths dynamically based on the presence of a category filter (lines [80-83]). When operating in full installation mode, the entire Skills tree copies to the target:

SOURCE="$SKILLS_DIR"
DEST="$TARGET"

In category-specific mode, the script narrows the scope to the selected subfolder:

SOURCE="$SKILLS_DIR/$CATEGORY"
DEST="$TARGET/$CATEGORY"

This hierarchical approach preserves the directory structure, ensuring that Claude correctly organizes the security skills by domain (e.g., web, wireless, networking).

Safe Execution with Dry-Run Mode

When invoked with --dry-run, the script sets DRY_RUN=1 and executes a preview routine (lines [89-93]) that identifies all SKILL.md files that would be copied using the find command:

find "$SOURCE" -name "SKILL.md" -type f

This mode prints the source and target paths, lists every file that would be transferred, and exits without modifying the filesystem. This safety feature allows administrators to verify deployment scope before committing changes.

File Copying Mechanisms: rsync and cp Fallback

The actual installation (lines [95-103]) begins with mkdir -p "$DEST" to ensure the target hierarchy exists. The script then implements a capability-based fallback system for the copy operation:

Primary Method: rsync If rsync is available in the system PATH, the script executes:

rsync -a --info=stats1 "$SOURCE/" "$DEST/"

This provides archive-quality copying with progress statistics and differential transfer capabilities.

Fallback Method: cp If rsync is absent, the script falls back to:

cp -r "$SOURCE"/* "$DEST"/

Following the fallback copy, the script emits a recommendation to install rsync for enhanced output visibility, ensuring the installer remains functional on minimal systems while encouraging better tooling.

Post-Installation Summary

After completing the file operations (lines [105-108]), the script performs a final enumeration of installed SKILL.md files and prints a concise summary. This confirmation message includes the total count of deployed skills and a reminder that Claude will auto-discover the new capabilities on the next session start, completing the integration workflow.

Summary

  • The install.sh script in SnailSploit/Claude-Red employs set -euo pipefail for robust error handling during skill deployment.
  • It supports multiple operational modes including interactive prompts, category-specific installation, and dry-run previews.
  • The script validates source directory existence and category availability before executing any file operations.
  • It dynamically selects between rsync (with progress statistics) and standard cp based on system capabilities.
  • All SKILL.md files copy to ${HOME}/.claude/skills/claude-red by default, with Claude auto-discovering them on next launch.

Frequently Asked Questions

How do I preview what the install.sh script will copy before running it?

Use the --dry-run flag to execute a preview mode that lists every SKILL.md file that would be copied without modifying your filesystem. This mode displays the source and target paths, then exits cleanly after showing the complete file list.

Can I install only specific penetration testing categories using install.sh?

Yes, pass the --category flag followed by the category name (e.g., ./install.sh --category web). The script validates that the category exists in the Skills/ directory and copies only that subfolder to the target location while preserving the directory structure.

What happens if rsync is not installed on my system?

The script automatically detects rsync availability and falls back to the standard cp -r command if the tool is missing. While this ensures compatibility with minimal systems, the script will recommend installing rsync to enable progress statistics and enhanced output during future installations.

Where does install.sh place the Claude-Red skills by default?

The script targets ${HOME}/.claude/skills/claude-red by default, though it prompts for confirmation in interactive mode. You can override this path using the --target flag followed by your preferred directory path for unattended deployments.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →