# Claude-Red Skill Categories: Complete Taxonomy of Offensive Security Capabilities

> Explore the Claude-Red skill categories, a comprehensive taxonomy of offensive security capabilities from Active Directory to wireless exploitation. Discover SnailSploit's structured knowledge base.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: api-reference
- Published: 2026-09-14

---

**Claude-Red organizes its offensive security knowledge base into 23 distinct skill categories—from Active Directory to wireless exploitation—structured as a flat hierarchy in the auto-generated [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) manifest.**

Claude-Red, the open-source offensive security framework maintained by SnailSploit, structures its extensive library of penetration testing techniques into clearly defined categories. Each **Claude-Red skill category** represents a specific domain of cybersecurity expertise, enabling both automated tooling and human practitioners to navigate the repository efficiently. This categorical taxonomy is materialized through a combination of filesystem organization and programmatic manifest generation.

## How Claude-Red Skill Categories Are Structured

The repository employs a flat categorization system where every skill exists at the same hierarchical level, grouped solely by its assigned category field.

### Filesystem Organization

Skills are physically organized under the `Skills/` directory following a strict three-tier pattern:

```text
Skills/<category>/<skill-name>/SKILL.md

```

For example, a skill focused on XSS attacks resides at [`Skills/web/offensive-xss/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/web/offensive-xss/SKILL.md). The parent folder name (`web`) serves as the canonical category identifier, while the subfolder (`offensive-xss`) represents the unique skill name. This design ensures that the filesystem structure directly reflects the categorical taxonomy without requiring nested sub-categories.

### The Generated Manifest

The definitive catalogue of all **Claude-Red skill categories** lives in **[`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json)** (lines 135–597). This JSON file is not maintained manually; instead, it is auto-generated by **[`tools/build_manifest.py`](https://github.com/SnailSploit/Claude-Red/blob/main/tools/build_manifest.py)** (lines 2–86). The Python script traverses the `Skills/` directory, parses YAML front-matter from each [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file, and emits structured entries containing the `category`, `name`, and filesystem path for every skill in the repository.

## The 23 Main Skill Categories in Claude-Red

According to the source code analysis of [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json), Claude-Red maintains exactly **23 top-level skill categories**. Each category encompasses a distinct offensive security domain:

- **active-directory** — Windows domain and Active Directory exploitation techniques
- **ai** — Attacks targeting large-language-model pipelines and AI systems
- **api** — API security testing, abuse patterns, and endpoint exploitation
- **auth** — Authentication mechanism attacks including OAuth and JWT vulnerabilities
- **cicd** — Continuous Integration/Continuous Deployment pipeline abuse and secret leakage
- **cloud** — Cloud-provider-specific attack vectors across AWS, Azure, GCP, and others
- **container** — Container runtime escapes and orchestrator (Kubernetes/Docker) attacks
- **crypto** — Cryptographic protocol weaknesses and implementation flaws
- **exploit-dev** — Proof-of-concept development, TOCTOU vulnerabilities, mitigations bypass, and crash analysis
- **forensics** — Command-and-control frameworks and anti-forensics techniques
- **fuzzing** — Vulnerability-class fuzzing and automated fuzzing methodologies
- **infrastructure** — Windows mitigations, shellcode development, keylogger architectures, and initial access techniques
- **iot** — Internet-of-Things device exploitation and embedded system attacks
- **mobile** — Mobile platform attacks targeting iOS and Android ecosystems
- **network** — Network-level offensive techniques and protocol manipulation
- **post-exploitation** — Persistence mechanisms, lateral movement strategies, and data exfiltration
- **privesc** — Privilege escalation techniques for both Windows and Linux environments
- **recon** — Open-source intelligence (OSINT) and reconnaissance methodologies
- **social-engineering** — Phishing campaigns and social engineering attack vectors
- **supply-chain** — Supply-chain attacks, dependency confusion, and third-party compromise
- **utility** — Reporting tools and fast-checking utilities for penetration testers
- **web** — Web application vulnerabilities including XSS, XXE, SSRF, and file-upload abuse
- **wireless** — Wi-Fi, Bluetooth, Zigbee/Thread/Matter attacks, WPA/WPA2/WPA3 exploitation, deauthentication, and evil-twin techniques

Because the taxonomy is flat (no nested sub-categories), downstream tools can filter the manifest by the `category` field to retrieve all skills within a specific domain without recursive traversal logic.

## Accessing Skill Categories Programmatically

You can interact with the Claude-Red skill taxonomy programmatically using the generated manifest. The following Python example extracts all unique categories from [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json):

```python
import json
from pathlib import Path

manifest_path = Path("claude-skills.json")
manifest = json.loads(manifest_path.read_text(encoding="utf-8"))

# Extract unique categories

categories = sorted({entry["category"] for entry in manifest["skills"]})
print("\n".join(categories))

```

To retrieve all skills belonging to a specific category (for example, "web"), use this filter function:

```python
def skills_by_category(cat: str):
    return [
        entry["name"]
        for entry in manifest["skills"]
        if entry["category"] == cat
    ]

print(skills_by_category("web"))

```

These patterns allow security automation pipelines and Claude-Red's UI components to dynamically present categorized skill libraries without hardcoding the taxonomy.

## Extending the Claude-Red Skill Taxonomy

Adding new capabilities to an existing **Claude-Red skill category** requires no modification to the JSON manifest. Instead, create a new directory under the appropriate category folder:

```bash
mkdir -p Skills/web/advanced-ssrf

```

Place a [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file containing valid YAML front-matter (including the `name` field) within this directory. Then regenerate the manifest by executing:

```bash
python -m tools.build_manifest

```

The [`build_manifest.py`](https://github.com/SnailSploit/Claude-Red/blob/main/build_manifest.py) script automatically detects the new directory, parses its front-matter, and updates [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) with the new entry preserving the correct `category` mapping.

## Summary

- Claude-Red implements **23 distinct skill categories** covering the full spectrum of offensive security operations
- Categories are maintained in a **flat hierarchy** within the [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) manifest (lines 135–597)
- The manifest is **auto-generated** by [`tools/build_manifest.py`](https://github.com/SnailSploit/Claude-Red/blob/main/tools/build_manifest.py) (lines 2–86) which parses `Skills/<category>/<skill-name>/SKILL.md` files
- Each skill entry contains a `category` field enabling simple programmatic filtering without nested traversal
- New skills are added by creating directories under existing category paths and rebuilding the manifest

## Frequently Asked Questions

### How many skill categories does Claude-Red support?

Claude-Red supports **23 distinct skill categories** ranging from traditional infrastructure and network attacks to emerging domains like AI exploitation and supply-chain security. This number is defined statically in the generated [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file and represents a comprehensive taxonomy of modern offensive security disciplines.

### Where are the Claude-Red skill categories defined?

The categories are defined in **[`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json)** at the repository root, specifically within lines 135–597 of the manifest. Each JSON entry includes a `category` field that associates the skill with one of the 23 top-level domains. This file is programmatically generated by [`tools/build_manifest.py`](https://github.com/SnailSploit/Claude-Red/blob/main/tools/build_manifest.py) based on the physical directory structure under `Skills/`.

### How do I add a new skill to an existing category in Claude-Red?

To add a new skill, create a folder under `Skills/<category>/<skill-name>/` containing a [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file with appropriate YAML front-matter (including the `name` field). After placing the files, run `python -m tools.build_manifest` to regenerate [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json). The build script automatically detects the new path and updates the manifest with the correct category assignment.

### Does Claude-Red support sub-categories or nested taxonomies?

No. Claude-Red intentionally uses a **flat hierarchy** with no nested sub-categories. The design decision keeps the manifest simple for both human readability and machine parsing. All skills exist as direct children of one of the 23 primary categories, identified solely by the `category` field in the JSON manifest.