How to Use Claude.ai with Claude-Red Skills Manually: A Step-by-Step Guide

To use Claude.ai with Claude-Red skills manually, copy the entire contents of a SKILL.md file from the repository and paste it into the system prompt field of your Claude.ai chat session, allowing Claude to adopt the specialized red-team methodology for that conversation.

The SnailSploit/Claude-Red repository provides a curated collection of offensive security skill files that extend Claude's capabilities with domain-specific red-team procedures. When you need to test a single technique or lack access to the automated Claude Skills System, learning how to use Claude.ai with Claude-Red skills manually gives you immediate access to expert penetration testing methodologies without complex setup.

Understanding the Manual Skill Injection Method

Claude-Red organizes its knowledge base into self-contained markdown documents called SKILL.md files, each located in technique-specific directories like Skills/web/offensive-sqli/SKILL.md. These files contain structured red-team procedures including detection techniques, automation scripts, exploitation steps, and remediation guidance.

When you use Claude.ai with Claude-Red skills manually, you leverage Claude's system prompt as immutable context. By injecting the raw markdown content directly into this system prompt, you transform Claude into a specialist for that specific offensive technique for the duration of your conversation. This method treats the SKILL.md content as persistent instructions that guide every subsequent response.

Step-by-Step Guide to Manual Skill Loading

Follow these precise steps to inject a Claude-Red skill into the Claude.ai web interface:

  1. Navigate to the desired skill file in your local clone of the SnailSploit/Claude-Red repository (e.g., Skills/web/offensive-sqli/SKILL.md).

  2. Copy the entire file contents to your clipboard, ensuring you include the front-matter metadata at the top of the document.

  3. Open https://claude.ai in your browser and start a new chat session.

  4. Locate and click the "Add system prompt" option in the chat interface.

  5. Paste the complete SKILL.md content into the system prompt field and submit.

  6. Begin your conversation. Claude will now reference the embedded methodology—including specific payloads, detection commands, and exploitation workflows—without requiring external file access.

Loading Skills via Claude Code CLI

For users with the Claude Code command-line interface installed, you can achieve the same result programmatically without copy-pasting. This approach pipes the skill file directly into Claude's context using the --system-file flag:

cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

This command streams the SKILL.md content into the CLI as a system file, immediately preparing Claude Code with the specialized knowledge contained in the repository's offensive SQL injection skill.

Repository Structure and Key Files

Understanding the file layout helps you locate the correct skills for manual injection. The SnailSploit/Claude-Red repository contains several critical components:

  • README.md – Located at the repository root, this file provides the official quick-start instructions and outlines all three loading methods (Skills System, Claude Code, and manual injection).

  • install.sh – An interactive bash script that automates the installation of the entire skill library or specific categories into Claude's skill directory for automatic loading.

  • convert_skills.py – A utility script for migrating legacy skill formats to the current SKILL.md schema, ensuring compatibility with the manual injection workflow.

  • claude-skills.json – The JSON manifest file that the Claude Skills System uses for automatic skill discovery and loading; while not required for manual usage, it documents the available skill categories.

  • Skills/ directory – Contains categorized subdirectories (e.g., web/, network/) where individual SKILL.md files reside for specific offensive techniques.

Manual Injection vs. Automated Skills System

Choose the manual method when you need precise control over which specific skill loads into your conversation. The automated Claude Skills System—which clones the repository into Claude's skill directory—dynamically loads skills based on conversational triggers, but requires full repository access and configuration.

Manual injection excels in three scenarios:

  • On-the-fly testing of a single technique without installing the entire repository
  • Quick demonstrations where you want to guarantee a specific skill is active
  • Restricted environments where you cannot modify Claude's skill directory but can modify individual chat system prompts

Summary

  • Manual injection requires copying the complete SKILL.md file contents and pasting them into Claude.ai's system prompt field.
  • The method works because Claude treats system prompt content as immutable context that guides all subsequent responses.
  • File paths like Skills/web/offensive-sqli/SKILL.md contain the executable red-team methodologies used during manual loading.
  • Claude Code users can pipe skills directly using cat ... | claude --system-file - instead of copy-pasting.
  • This approach is ideal for testing individual skills when the automated Claude Skills System is unavailable or unnecessary.

Frequently Asked Questions

What is the difference between manual injection and the Claude Skills System?

Manual injection requires you to copy and paste individual SKILL.md files into the system prompt for each conversation, while the Claude Skills System automatically loads relevant skills from the ~/.claude/skills directory based on conversational triggers. The automated system requires running install.sh to clone the repository locally, whereas manual injection works immediately with just the web interface.

Can I load multiple SKILL.md files manually in one conversation?

Yes, you can concatenate multiple skill files before pasting them into the system prompt. Copy the contents of several SKILL.md files (such as one from Skills/web/offensive-sqli/SKILL.md and another from Skills/network/enum-smb/SKILL.md) and combine them in the system prompt field. Claude will treat the combined content as unified context, though token limits may apply for extremely large skill collections.

Where are the SKILL.md files located in the repository?

Individual skill files follow the pattern Skills/<category>/<technique-name>/SKILL.md within the SnailSploit/Claude-Red repository. For example, web application skills reside in Skills/web/, while network enumeration skills are in Skills/network/. Each subdirectory contains a SKILL.md file with front-matter describing the technique's metadata and procedural content.

Is manual skill injection available on all Claude.ai plans?

Manual skill injection via the system prompt is available on Claude.ai plans that support custom system prompts, which includes Pro and Team plans. Free-tier users may have limited or no access to the system prompt editor; in those cases, you can prepend the SKILL.md content to your first user message as a workaround, though this provides less persistent context than the dedicated system prompt field.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →