Claude-Red `claude-skills.json` Manifest File Structure Explained

The claude-skills.json file serves as the central manifest for the SnailSploit/Claude-Red repository, using a flat-list JSON schema with top-level metadata fields, a categorical index object, and a comprehensive skills array that maps internal identifiers to relative paths of detailed markdown documentation.

The claude-skills.json manifest functions as the authoritative index for every attack methodology shipped with the Claude-Red framework. Located at the repository root in SnailSploit/Claude-Red, this lightweight JSON file separates structural metadata from narrative documentation, enabling automated tooling to discover and load offensive security skills without parsing full markdown files.

Top-Level Metadata Fields

The manifest begins with four standard metadata fields that describe the entire collection. At lines 1-5 of claude-skills.json, you will find:

  • name – A human-readable identifier for the skill collection, typically "claude-red"
  • version – A semantic version string (e.g., "0.3.0") used by tooling to detect manifest updates
  • license – An SPDX-compatible license identifier (e.g., "MIT") governing the repository contents
  • homepage – The canonical URL pointing to the project’s main page, typically "https://github.com/SnailSploit/claude-red"

These fields provide immediate context for package managers and CI/CD pipelines parsing the repository structure.

Core Schema Components

Beyond metadata, the manifest defines two interlinked data structures that organize the actual attack methodologies.

The categories Object

The categories object (lines 6-31) functions as a categorical index mapping high-level domains to arrays of skill identifiers. Each key represents a domain such as active-directory, cloud, or web, while the value contains a list of slugs that exist within that domain.

{
  "active-directory": ["offensive-active-directory"],
  "cloud": ["offensive-cloud", "offensive-aws"],
  "web": ["offensive-sqli", "offensive-xss"]
}

This design allows for O(1) lookup when filtering skills by operational domain without scanning the entire skills array.

The skills Array

The skills array (starting at line 33) contains the definitive list of all attack methodologies as structured objects. Each entry adheres to a strict schema with four required fields:

  • name – The internal slug used by the CLI and documentation systems (e.g., "offensive-active-directory")
  • category – The parent category name, which must exist as a key in the categories object
  • path – A relative file path pointing to the skill's detailed markdown description (e.g., "Skills/active-directory/offensive-active-directory/SKILL.md")
  • description – A concise, human-readable summary of the attack methodology

This flat-list design decouples the lightweight index from heavy documentation. The path field directs consumers to the Skills/ directory hierarchy, where individual SKILL.md files contain full narrative explanations, allowing the manifest to remain under 50KB even with hundreds of attack definitions.

Working with the Manifest Programmatically

Security tools and automation scripts typically interact with claude-skills.json through three primary operations: loading the schema, filtering by operational category, and resolving documentation paths.

Loading and Parsing the JSON

Use Python’s standard library to load the manifest and extract global metadata:

import json
from pathlib import Path

manifest_path = Path(__file__).parent / "claude-skills.json"
with manifest_path.open() as f:
    data = json.load(f)

print(f"Package: {data['name']} (v{data['version']})")
print(f"Categories ({len(data['categories'])}): {list(data['categories'].keys())}")
print(f"Total skills: {len(data['skills'])}")

This snippet validates file accessibility and provides immediate inventory statistics for the collection.

Filtering by Category

To retrieve all skills belonging to a specific operational domain without manual iteration overhead:

def skills_by_category(cat: str):
    return [s for s in data["skills"] if s["category"] == cat]

web_skills = skills_by_category("web")
for s in web_skills:
    print(f"- {s['name']}: {s['description']}")

This approach leverages the denormalized category field within each skill object, avoiding the need to cross-reference the categories index for basic enumeration tasks.

Resolving Documentation Paths

Convert relative paths in the manifest to absolute filesystem locations for direct markdown access:

def skill_doc_path(skill_name: str) -> Path:
    skill = next(s for s in data["skills"] if s["name"] == skill_name)
    return Path(__file__).parent / skill["path"]

doc = skill_doc_path("offensive-cloud")
print(f"Documentation for offensive-cloud: {doc}")

This resolution mechanism supports dynamic documentation generators and IDE integrations that need to link directly to specific attack methodologies.

Summary

  • The claude-skills.json file resides at the root of SnailSploit/Claude-Red and uses a flat-list schema separating metadata from documentation.
  • Top-level fields include name, version, license, and homepage for package identification.
  • The categories object provides a fast lookup map from domain names (e.g., "web") to skill identifier arrays.
  • The skills array contains full metadata for each attack methodology, including a path field pointing to Skills/<category>/<skill-name>/SKILL.md.
  • Programmatic consumers can load the JSON, filter by the category property, and resolve markdown paths using standard filesystem operations.

Frequently Asked Questions

What is the primary purpose of the claude-skills.json file?

The manifest serves as a machine-readable index that describes every offensive security skill available in the Claude-Red repository. It enables automated tooling to inventory attack methodologies, categorize them by operational domain, and locate their detailed documentation without scanning the entire Skills/ directory tree.

How does the categories object relate to individual skill entries?

The categories object acts as a secondary index that groups skill name values under domain keys like "active-directory" or "cloud". Each skill object in the skills array must reference a valid category key via its category property, creating a bidirectional linkage between the categorical map and the flat skill list.

Where is the actual skill documentation stored relative to the manifest?

Full narrative documentation resides in separate markdown files under the Skills/ directory hierarchy. The path field in each skill object points to a relative location such as Skills/active-directory/offensive-active-directory/SKILL.md, allowing the manifest to maintain a small footprint while referencing arbitrarily large documentation files.

What license identifier format does the manifest use?

The license field uses SPDX-compatible identifiers such as "MIT" or "GPL-3.0". This standardization allows automated license compliance tools to parse the manifest without requiring full-text license analysis, facilitating integration into enterprise security toolchains with strict governance requirements.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →