# How to Pipe a Single Skill File to Claude Code: A Complete Guide for Claude‑Red

> Learn to pipe Claude Red skill files into Claude Code using STDIN and the --system-file - flag. This guide explains how to load skills as temporary system prompts for your session.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: how-to-guide
- Published: 2026-09-14

---

**You can pipe any Claude‑Red skill file directly into Claude Code by streaming the [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) contents through STDIN using the `--system-file -` flag, which loads the skill as a temporary system prompt for your current session.**

The Claude‑Red repository by SnailSploit distributes offensive-security capabilities as standalone Markdown files. Instead of permanently installing these skills, you can stream them ad‑hoc into Claude Code, allowing you to leverage specialized penetration-testing methodologies without bloating your permanent context.

## Locating Skill Files in the Repository

All skills in the SnailSploit/Claude‑Red repository live under the `Skills/<category>/` directory hierarchy. Each skill is a self‑contained [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file that includes YAML front‑matter defining triggers, descriptions, and the instruction body.

For example, the SQL injection skill resides at:

```bash
Skills/web/offensive-sqli/SKILL.md

```

According to the repository’s [`README.md`](https://github.com/SnailSploit/Claude-Red/blob/main/README.md) (lines 51‑53), this structure is mirrored across categories such as `active-directory/`, `web/`, and `cloud/`, making it easy to target specific capabilities via file paths.

## Piping a Single Skill File to Claude Code

To load one skill ad‑hoc, use a shell pipeline to stream the file contents into Claude Code’s standard input. The `--system-file -` argument tells the CLI to read the system prompt from STDIN rather than a disk path.

```bash
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

```

When you run this command:
1. **cat** streams the raw Markdown and YAML front‑matter of [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) into the pipeline.
2. **claude --system-file -** ingests the text as the session’s system prompt.
3. Claude parses the skill’s trigger phrases and methodology, activating it immediately for your conversation.

This approach avoids copying the skill into Claude’s permanent configuration; the skill context exists only for the current session and disappears when you exit.

## Advanced Piping Techniques

Once you understand the basic STDIN mechanism, you can combine it with shell utilities to load multiple skills or remote resources.

### Load an Entire Category

Use glob patterns to concatenate all skills within a category. This merges every [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file under `Skills/active-directory/` into a single system prompt:

```bash
cat Skills/active-directory/**/SKILL.md | claude --system-file -

```

### Stream from a Remote URL

You can fetch skills directly from the main branch without cloning the repository by piping `curl` output:

```bash
curl -s https://raw.githubusercontent.com/SnailSploit/Claude-Red/main/Skills/web/offensive-sqli/SKILL.md | claude --system-file -

```

The `-s` flag ensures silent operation, sending only the file content to Claude Code.

### Combine with an Initial User Prompt

For shells supporting process substitution (Bash, Zsh), you can preload the skill while simultaneously sending a first question:

```bash
echo "How can I exploit a blind SQL injection?" | claude --system-file - <(cat Skills/web/offensive-sqli/SKILL.md)

```

Here, `<(...)` creates a temporary file descriptor containing the skill content, allowing both the system prompt and user input to flow into Claude in a single command.

## How System File Ingestion Works

The `--system-file` flag in Claude Code treats the supplied text as **privileged system context**. When you pass the hyphen (`-`), the CLI enters a mode where it reads the entire STDIN stream until EOF, then injects that text as the system prompt for the LLM session.

Claude‑Red skill files rely on this behavior:
- Each [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) begins with YAML front‑matter (parsed by Claude for metadata like `name`, `description`, and `triggers`).
- The remaining Markdown body contains the detailed methodology and constraints.
- Because system prompts receive higher token priority, trigger phrases mentioned in the skill activate the described behavior without requiring you to paste the full text into the chat window.

This architecture keeps your local Claude Code installation lean while still granting on‑demand access to the repository’s offensive‑security expertise.

## Summary

- **Skill location**: Individual capabilities reside at `Skills/<category>/<skill-name>/SKILL.md` within the SnailSploit/Claude‑Red repository.
- **Core syntax**: Pipe the file via `cat` into `claude --system-file -` to load it as a temporary system prompt.
- **Bulk loading**: Use shell globs (`**/SKILL.md`) to concatenate multiple skills into one session.
- **Remote usage**: Stream raw files from GitHub via `curl` without cloning the repository.
- **Implementation detail**: The [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py) script in the repository generates the YAML‑wrapped format that Claude parses when ingesting these files.

## Frequently Asked Questions

### Can I pipe multiple skill files at once without merging them manually?

Yes. The `cat` command accepts multiple file arguments or glob patterns, concatenating them sequentially. Claude Code receives the combined text as a single system prompt containing all methodologies. For example: `cat Skills/web/**/SKILL.md | claude --system-file -`.

### Does piping a skill incur additional token costs compared to permanent installation?

No. The token cost is identical regardless of how the system prompt is loaded. Piping simply changes the delivery mechanism (STDIN versus disk file); the LLM still processes the same character count. The benefit is logistical—you avoid cluttering your permanent Claude Code configuration with skills you only need temporarily.

### What happens if the skill file contains malformed YAML front‑matter?

Claude Code treats the entire piped stream as raw text. While the [`convert_skills.py`](https://github.com/SnailSploit/Claude-Red/blob/main/convert_skills.py) utility in Claude‑Red ensures standard formatting, manually edited files with syntax errors will still load, but the metadata (triggers, descriptions) may not be parsed correctly. The body instructions remain accessible, though trigger-based activation might fail.

### Is there a way to verify which skills are currently active in my session?

Claude Code does not display an active skill list in the standard CLI interface. However, because the skill content lives in the system prompt, you can query Claude directly by asking, "What offensive security triggers do you recognize?" or similar. Claude will reference the trigger phrases defined in the piped [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files, confirming ingestion.