Claude-Red Skill Naming Convention: How to Structure offensive-<identifier> Skills

Claude-Red enforces a strict offensive-<bug-class-or-domain> naming pattern for all skills, requiring the front-matter name field and containing folder to match exactly.

The SnailSploit/Claude-Red repository organizes offensive security capabilities into modular, self-contained skills. Understanding the precise naming convention for skills is essential for contributors building new capabilities and users navigating the library. Every skill must follow a predictable offensive-<identifier> pattern that ensures compatibility with Claude's trigger-matching system and the repository's validation tools.

The Two-Part Naming Convention

Claude-Red skills are governed by two mandatory rules that work together to create predictable, searchable identifiers.

Front-Matter name Field Requirement

Each skill is defined by a SKILL.md file that begins with YAML front matter. According to the Skill Format section in CONTRIBUTING.md, the name field must be written as:

name: offensive-<bug-class-or-domain>

The offensive- prefix signals the skill's offensive security purpose, while the suffix uniquely describes the technique, technology, or attack surface (for example, offensive-xss, offensive-wifi, or offensive-linux-privesc).

Directory Name Enforcement

The folder containing SKILL.md must exactly match the name value from the front matter. The repository layout follows this pattern:


Skills/<category>/offensive-<bug-class-or-domain>/SKILL.md

As implemented in SnailSploit/Claude-Red, this strict equivalence enables automated tooling like ./tools/build_manifest.py to generate the claude-skills.json manifest without ambiguity.

Required File Structure and Path Pattern

Valid skills reside within category directories under the Skills/ root. For example, the cross-site scripting skill follows this structure:


Skills/web/offensive-xss/SKILL.md

In this case, the folder name offensive-xss matches the front-matter name: offensive-xss, satisfying both validation rules enforced by the repository's linting system.

Practical Examples

Correct Skill Implementation

Create a compliant skill by establishing the directory and SKILL.md file with matching names:

mkdir -p Skills/web/offensive-sql-injection

cat > Skills/web/offensive-sql-injection/SKILL.md <<'EOF'
---
name: offensive-sql-injection
description: |
  SQL injection testing checklist and exploitation vectors...
---

# SKILL: SQL Injection

## Objectives

...
EOF

Validate your implementation using the repository's linter:

./tools/check-skill.sh Skills/web/offensive-sql-injection/SKILL.md

# → Passed

Common Naming Mistakes to Avoid

Incorrect front matter causes validation failures even when the content is valid. Avoid omitting the required prefix:

---
name: xss-skill                 # ❌ Missing offensive- prefix

description: |
  Cross-site scripting guide...
---

This violates the convention defined in CONTRIBUTING.md and will be flagged by ./tools/check-skill.sh, regardless of the folder name.

Key Files Enforcing the Convention

Several critical files in SnailSploit/Claude-Red maintain naming consistency across the skill library:

  • CONTRIBUTING.md (Skill Format section): Defines the required front-matter name pattern and mandates folder-name equivalence.
  • tools/check-skill.sh: Validates that the name field and parent directory match exactly.
  • tools/build_manifest.py: Generates the skill manifest using the name fields, relying on strict naming compliance to map skills correctly.
  • Skills/web/offensive-xss/SKILL.md: Demonstrates a correctly named skill and directory structure in practice.

Summary

  • All Claude-Red skills must use the offensive-<bug-class-or-domain> naming pattern in the front-matter name field.
  • The containing folder name must exactly match the name value from the skill's metadata.
  • Skills follow the standardized path structure Skills/<category>/<name>/SKILL.md.
  • Run ./tools/check-skill.sh to validate naming compliance before submitting contributions.

Frequently Asked Questions

What prefix must all Claude-Red skill names use?

All skill names must begin with the offensive- prefix followed by a bug class or domain identifier. This prefix identifies the capability as an offensive security skill and ensures proper integration with Claude's trigger-matching system.

Does the folder name need to match the skill's name field exactly?

Yes. The directory containing SKILL.md must exactly match the name value specified in the file's YAML front matter. The validation script ./tools/check-skill.sh enforces this requirement to prevent manifest generation errors in ./tools/build_manifest.py.

Where is the skill naming convention formally documented?

The specification resides in the Skill Format section of CONTRIBUTING.md. Additional context and live examples appear in the Skill Index section of README.md, which demonstrates the naming convention through the repository's actual skill listings.

How do I validate my skill name before submitting a pull request?

Execute the ./tools/check-skill.sh script against your SKILL.md file. This tool verifies that your front-matter name field follows the offensive-<identifier> pattern and confirms that the parent directory name matches exactly, ensuring compliance with SnailSploit/Claude-Red standards.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →