Claude-Red Skill Categories: Complete Taxonomy of Offensive Security Capabilities
Claude-Red organizes its offensive security knowledge base into 23 distinct skill categories—from Active Directory to wireless exploitation—structured as a flat hierarchy in the auto-generated claude-skills.json manifest.
Claude-Red, the open-source offensive security framework maintained by SnailSploit, structures its extensive library of penetration testing techniques into clearly defined categories. Each Claude-Red skill category represents a specific domain of cybersecurity expertise, enabling both automated tooling and human practitioners to navigate the repository efficiently. This categorical taxonomy is materialized through a combination of filesystem organization and programmatic manifest generation.
How Claude-Red Skill Categories Are Structured
The repository employs a flat categorization system where every skill exists at the same hierarchical level, grouped solely by its assigned category field.
Filesystem Organization
Skills are physically organized under the Skills/ directory following a strict three-tier pattern:
Skills/<category>/<skill-name>/SKILL.md
For example, a skill focused on XSS attacks resides at Skills/web/offensive-xss/SKILL.md. The parent folder name (web) serves as the canonical category identifier, while the subfolder (offensive-xss) represents the unique skill name. This design ensures that the filesystem structure directly reflects the categorical taxonomy without requiring nested sub-categories.
The Generated Manifest
The definitive catalogue of all Claude-Red skill categories lives in claude-skills.json (lines 135–597). This JSON file is not maintained manually; instead, it is auto-generated by tools/build_manifest.py (lines 2–86). The Python script traverses the Skills/ directory, parses YAML front-matter from each SKILL.md file, and emits structured entries containing the category, name, and filesystem path for every skill in the repository.
The 23 Main Skill Categories in Claude-Red
According to the source code analysis of claude-skills.json, Claude-Red maintains exactly 23 top-level skill categories. Each category encompasses a distinct offensive security domain:
- active-directory — Windows domain and Active Directory exploitation techniques
- ai — Attacks targeting large-language-model pipelines and AI systems
- api — API security testing, abuse patterns, and endpoint exploitation
- auth — Authentication mechanism attacks including OAuth and JWT vulnerabilities
- cicd — Continuous Integration/Continuous Deployment pipeline abuse and secret leakage
- cloud — Cloud-provider-specific attack vectors across AWS, Azure, GCP, and others
- container — Container runtime escapes and orchestrator (Kubernetes/Docker) attacks
- crypto — Cryptographic protocol weaknesses and implementation flaws
- exploit-dev — Proof-of-concept development, TOCTOU vulnerabilities, mitigations bypass, and crash analysis
- forensics — Command-and-control frameworks and anti-forensics techniques
- fuzzing — Vulnerability-class fuzzing and automated fuzzing methodologies
- infrastructure — Windows mitigations, shellcode development, keylogger architectures, and initial access techniques
- iot — Internet-of-Things device exploitation and embedded system attacks
- mobile — Mobile platform attacks targeting iOS and Android ecosystems
- network — Network-level offensive techniques and protocol manipulation
- post-exploitation — Persistence mechanisms, lateral movement strategies, and data exfiltration
- privesc — Privilege escalation techniques for both Windows and Linux environments
- recon — Open-source intelligence (OSINT) and reconnaissance methodologies
- social-engineering — Phishing campaigns and social engineering attack vectors
- supply-chain — Supply-chain attacks, dependency confusion, and third-party compromise
- utility — Reporting tools and fast-checking utilities for penetration testers
- web — Web application vulnerabilities including XSS, XXE, SSRF, and file-upload abuse
- wireless — Wi-Fi, Bluetooth, Zigbee/Thread/Matter attacks, WPA/WPA2/WPA3 exploitation, deauthentication, and evil-twin techniques
Because the taxonomy is flat (no nested sub-categories), downstream tools can filter the manifest by the category field to retrieve all skills within a specific domain without recursive traversal logic.
Accessing Skill Categories Programmatically
You can interact with the Claude-Red skill taxonomy programmatically using the generated manifest. The following Python example extracts all unique categories from claude-skills.json:
import json
from pathlib import Path
manifest_path = Path("claude-skills.json")
manifest = json.loads(manifest_path.read_text(encoding="utf-8"))
# Extract unique categories
categories = sorted({entry["category"] for entry in manifest["skills"]})
print("\n".join(categories))
To retrieve all skills belonging to a specific category (for example, "web"), use this filter function:
def skills_by_category(cat: str):
return [
entry["name"]
for entry in manifest["skills"]
if entry["category"] == cat
]
print(skills_by_category("web"))
These patterns allow security automation pipelines and Claude-Red's UI components to dynamically present categorized skill libraries without hardcoding the taxonomy.
Extending the Claude-Red Skill Taxonomy
Adding new capabilities to an existing Claude-Red skill category requires no modification to the JSON manifest. Instead, create a new directory under the appropriate category folder:
mkdir -p Skills/web/advanced-ssrf
Place a SKILL.md file containing valid YAML front-matter (including the name field) within this directory. Then regenerate the manifest by executing:
python -m tools.build_manifest
The build_manifest.py script automatically detects the new directory, parses its front-matter, and updates claude-skills.json with the new entry preserving the correct category mapping.
Summary
- Claude-Red implements 23 distinct skill categories covering the full spectrum of offensive security operations
- Categories are maintained in a flat hierarchy within the
claude-skills.jsonmanifest (lines 135–597) - The manifest is auto-generated by
tools/build_manifest.py(lines 2–86) which parsesSkills/<category>/<skill-name>/SKILL.mdfiles - Each skill entry contains a
categoryfield enabling simple programmatic filtering without nested traversal - New skills are added by creating directories under existing category paths and rebuilding the manifest
Frequently Asked Questions
How many skill categories does Claude-Red support?
Claude-Red supports 23 distinct skill categories ranging from traditional infrastructure and network attacks to emerging domains like AI exploitation and supply-chain security. This number is defined statically in the generated claude-skills.json file and represents a comprehensive taxonomy of modern offensive security disciplines.
Where are the Claude-Red skill categories defined?
The categories are defined in claude-skills.json at the repository root, specifically within lines 135–597 of the manifest. Each JSON entry includes a category field that associates the skill with one of the 23 top-level domains. This file is programmatically generated by tools/build_manifest.py based on the physical directory structure under Skills/.
How do I add a new skill to an existing category in Claude-Red?
To add a new skill, create a folder under Skills/<category>/<skill-name>/ containing a SKILL.md file with appropriate YAML front-matter (including the name field). After placing the files, run python -m tools.build_manifest to regenerate claude-skills.json. The build script automatically detects the new path and updates the manifest with the correct category assignment.
Does Claude-Red support sub-categories or nested taxonomies?
No. Claude-Red intentionally uses a flat hierarchy with no nested sub-categories. The design decision keeps the manifest simple for both human readability and machine parsing. All skills exist as direct children of one of the 23 primary categories, identified solely by the category field in the JSON manifest.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →