# Claude-Red `claude-skills.json` Manifest File Structure Explained

> Understand the claude-skills.json manifest structure for SnailSploit Claude-Red. Learn about its metadata, index, and skills array for easy documentation access.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: api-reference
- Published: 2026-09-14

---

**The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file serves as the central manifest for the SnailSploit/Claude-Red repository, using a flat-list JSON schema with top-level metadata fields, a categorical index object, and a comprehensive skills array that maps internal identifiers to relative paths of detailed markdown documentation.**

The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) manifest functions as the authoritative index for every attack methodology shipped with the Claude-Red framework. Located at the repository root in `SnailSploit/Claude-Red`, this lightweight JSON file separates structural metadata from narrative documentation, enabling automated tooling to discover and load offensive security skills without parsing full markdown files.

## Top-Level Metadata Fields

The manifest begins with four standard metadata fields that describe the entire collection. At lines 1-5 of [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json), you will find:

- **`name`** – A human-readable identifier for the skill collection, typically `"claude-red"`
- **`version`** – A **semantic version** string (e.g., `"0.3.0"`) used by tooling to detect manifest updates
- **`license`** – An **SPDX-compatible** license identifier (e.g., `"MIT"`) governing the repository contents
- **`homepage`** – The canonical URL pointing to the project’s main page, typically `"https://github.com/SnailSploit/claude-red"`

These fields provide immediate context for package managers and CI/CD pipelines parsing the repository structure.

## Core Schema Components

Beyond metadata, the manifest defines two interlinked data structures that organize the actual attack methodologies.

### The categories Object

The `categories` object (lines 6-31) functions as a categorical index mapping high-level domains to arrays of skill identifiers. Each key represents a domain such as **active-directory**, **cloud**, or **web**, while the value contains a list of slugs that exist within that domain.

```json
{
  "active-directory": ["offensive-active-directory"],
  "cloud": ["offensive-cloud", "offensive-aws"],
  "web": ["offensive-sqli", "offensive-xss"]
}

```

This design allows for **O(1) lookup** when filtering skills by operational domain without scanning the entire skills array.

### The skills Array

The `skills` array (starting at line 33) contains the definitive list of all attack methodologies as structured objects. Each entry adheres to a strict schema with four required fields:

- **`name`** – The internal slug used by the CLI and documentation systems (e.g., `"offensive-active-directory"`)
- **`category`** – The parent category name, which must exist as a key in the `categories` object
- **`path`** – A relative file path pointing to the skill's detailed markdown description (e.g., `"Skills/active-directory/offensive-active-directory/SKILL.md"`)
- **`description`** – A concise, human-readable summary of the attack methodology

This **flat-list design** decouples the lightweight index from heavy documentation. The `path` field directs consumers to the `Skills/` directory hierarchy, where individual [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files contain full narrative explanations, allowing the manifest to remain under 50KB even with hundreds of attack definitions.

## Working with the Manifest Programmatically

Security tools and automation scripts typically interact with [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) through three primary operations: loading the schema, filtering by operational category, and resolving documentation paths.

### Loading and Parsing the JSON

Use Python’s standard library to load the manifest and extract global metadata:

```python
import json
from pathlib import Path

manifest_path = Path(__file__).parent / "claude-skills.json"
with manifest_path.open() as f:
    data = json.load(f)

print(f"Package: {data['name']} (v{data['version']})")
print(f"Categories ({len(data['categories'])}): {list(data['categories'].keys())}")
print(f"Total skills: {len(data['skills'])}")

```

This snippet validates file accessibility and provides immediate inventory statistics for the collection.

### Filtering by Category

To retrieve all skills belonging to a specific operational domain without manual iteration overhead:

```python
def skills_by_category(cat: str):
    return [s for s in data["skills"] if s["category"] == cat]

web_skills = skills_by_category("web")
for s in web_skills:
    print(f"- {s['name']}: {s['description']}")

```

This approach leverages the denormalized `category` field within each skill object, avoiding the need to cross-reference the `categories` index for basic enumeration tasks.

### Resolving Documentation Paths

Convert relative paths in the manifest to absolute filesystem locations for direct markdown access:

```python
def skill_doc_path(skill_name: str) -> Path:
    skill = next(s for s in data["skills"] if s["name"] == skill_name)
    return Path(__file__).parent / skill["path"]

doc = skill_doc_path("offensive-cloud")
print(f"Documentation for offensive-cloud: {doc}")

```

This resolution mechanism supports dynamic documentation generators and IDE integrations that need to link directly to specific attack methodologies.

## Summary

- The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file resides at the root of `SnailSploit/Claude-Red` and uses a **flat-list schema** separating metadata from documentation.
- **Top-level fields** include `name`, `version`, `license`, and `homepage` for package identification.
- The **`categories` object** provides a fast lookup map from domain names (e.g., "web") to skill identifier arrays.
- The **`skills` array** contains full metadata for each attack methodology, including a `path` field pointing to `Skills/<category>/<skill-name>/SKILL.md`.
- Programmatic consumers can load the JSON, filter by the `category` property, and resolve markdown paths using standard filesystem operations.

## Frequently Asked Questions

### What is the primary purpose of the [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file?

The manifest serves as a machine-readable index that describes every offensive security skill available in the Claude-Red repository. It enables automated tooling to inventory attack methodologies, categorize them by operational domain, and locate their detailed documentation without scanning the entire `Skills/` directory tree.

### How does the `categories` object relate to individual skill entries?

The `categories` object acts as a secondary index that groups skill `name` values under domain keys like "active-directory" or "cloud". Each skill object in the `skills` array must reference a valid category key via its `category` property, creating a bidirectional linkage between the categorical map and the flat skill list.

### Where is the actual skill documentation stored relative to the manifest?

Full narrative documentation resides in separate markdown files under the `Skills/` directory hierarchy. The `path` field in each skill object points to a relative location such as [`Skills/active-directory/offensive-active-directory/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/active-directory/offensive-active-directory/SKILL.md), allowing the manifest to maintain a small footprint while referencing arbitrarily large documentation files.

### What license identifier format does the manifest use?

The `license` field uses **SPDX-compatible** identifiers such as `"MIT"` or `"GPL-3.0"`. This standardization allows automated license compliance tools to parse the manifest without requiring full-text license analysis, facilitating integration into enterprise security toolchains with strict governance requirements.