# What Is Claude-Red? A Complete Guide to the Offensive Security Skills Library

> Discover Claude-Red, the offensive security skills library that turns Claude into a context-aware red team assistant. Load domain-specific expertise and enhance your security assessments.

- Repository: [SnailSploit | Kai Aizen/Claude-Red](https://github.com/SnailSploit/Claude-Red)
- Tags: getting-started
- Published: 2026-09-14

---

**Claude-Red is a curated library of offensive-security "skills" designed to transform Claude into a context-aware red-team assistant by loading domain-specific expertise only when triggered by relevant conversation keywords.**

Claude-Red is an open-source repository maintained by SnailSploit that provides pre-built attack methodologies for the Claude Skills system. This library contains over 78 offensive techniques spanning 23 categories including web application security, wireless networks, cloud infrastructure, and Active Directory. By installing these skills into Claude's skill directory, security practitioners can convert the general-purpose LLM into a specialized red-team operator without manually crafting complex system prompts.

## How Claude-Red Works

The Claude-Red architecture relies on **SKILL.md** files that pre-load Claude with detailed, domain-specific methodology, tooling recommendations, and exploitation steps for particular attack surfaces. Each skill resides in the `Skills/` directory and follows a strict front-matter template that the Claude runtime parses to expose the skill's name, description, and trigger keywords.

When placed in Claude's `~/.claude/skills` directory, Claude **auto-discovers** these capabilities and activates them on demand. Activation occurs when conversation mentions relevant triggers such as "SQLi", "Kerberoasting", or "Kubernetes". Because skills load dynamically based on context, they **do not consume extra prompt tokens** for unrelated topics, yet supply the depth of a specialist operator when needed.

## Repository Structure and Key Components

According to the SnailSploit/Claude-Red source code, the repository organizes offensive security knowledge through three primary layers:

### The Skills Directory

The `Skills/` directory contains hierarchical folders (e.g., `web/`, `wireless/`, `cloud/`, `privesc/`) each housing one or more [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files. These markdown files contain complete attack methodologies for specific vectors:

- [`Skills/web/offensive-sqli/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/web/offensive-sqli/SKILL.md) – SQL injection techniques
- [`Skills/wireless/offensive-wpa2-psk/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/wireless/offensive-wpa2-psk/SKILL.md) – WPA2-PSK attacks  
- [`Skills/cloud/offensive-cloud/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/cloud/offensive-cloud/SKILL.md) – AWS/Azure/GCP exploitation
- [`Skills/container/offensive-k8s-attacks/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/container/offensive-k8s-attacks/SKILL.md) – Kubernetes attacks
- [`Skills/privesc/offensive-windows-privesc/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/privesc/offensive-windows-privesc/SKILL.md) – Windows privilege escalation
- [`Skills/utility/offensive-reporting/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/utility/offensive-reporting/SKILL.md) – Report writing methodology

### The Claude-Skills Manifest

The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) file serves as a machine-readable manifest that enumerates every skill, its category, path, and description. Claude uses this JSON to index the library and present a searchable catalog to users, enabling quick discovery of relevant capabilities across the 23+ categories.

### The Installation Script

The [`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh) Bash script automates deployment by copying selected skills to a target directory (default `~/.claude/skills/claude-red`). The script supports sparse checkouts, dry-runs for validation, and category filtering to install only relevant skill sets.

## Installing Claude-Red Skills

You can deploy Claude-Red using the interactive installer or manually clone the repository. The installation process supports full library deployment or selective category installation.

### Full Library Installation

To install the complete collection of 78+ offensive security skills:

```bash
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red
./install.sh

```

The script prompts for the target directory and copies all [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files into Claude's skill path.

### Category-Specific Installation

For targeted deployments, install only specific categories to minimize overhead. First, perform a dry-run to preview the installation:

```bash
./install.sh --category web --dry-run

```

After verifying the output shows the correct [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) files, execute the actual copy:

```bash
./install.sh --category web

```

This approach copies only `Skills/web/` content, reducing clutter while maintaining expertise in your target domain.

## Using Claude-Red in Practice

Once installed, Claude-Red skills integrate seamlessly into both CLI and GUI workflows.

### Command-Line Usage

Feed a skill directly as a system prompt using the Claude CLI:

```bash
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

```

This command loads the SQL injection expertise immediately, enabling Claude to answer questions with specialist-level detail regarding exploitation techniques and bypass methodologies.

### GUI Integration

To manually load a skill in the Claude.ai web interface:

1. Open a Claude project.
2. Navigate to the desired [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) file (e.g., [`Skills/network/offensive-network-attacks/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/network/offensive-network-attacks/SKILL.md)).
3. Copy the contents and paste them into the **System Prompt** box.

Claude treats the session as if it possesses native knowledge of network-layer attacks, providing methodology-specific guidance without additional context window consumption.

## Summary

- **Claude-Red** is a curated library of 78+ offensive security skills for the Claude Skills system maintained by SnailSploit.
- **SKILL.md** files in the `Skills/` directory contain domain-specific attack methodologies that auto-activate when conversation triggers match predefined keywords.
- The [`claude-skills.json`](https://github.com/SnailSploit/Claude-Red/blob/main/claude-skills.json) manifest indexes all capabilities across 23 categories including web, cloud, AD, and IoT security.
- The [`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh) script supports full or category-specific deployments with dry-run validation.
- Skills load on-demand to preserve context window efficiency while delivering specialist operator depth when needed.

## Frequently Asked Questions

### What file format does Claude-Red use for skill definitions?

Claude-Red uses **SKILL.md** files—Markdown documents with strict front-matter templates that Claude parses to extract the skill name, description, and trigger keywords. These files reside in category-specific subdirectories under `Skills/` (e.g., [`Skills/web/offensive-sqli/SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/Skills/web/offensive-sqli/SKILL.md)).

### How does Claude-Red avoid consuming prompt tokens for unrelated conversations?

Claude-Red leverages the **Claude Skills system** auto-discovery mechanism. Skills remain dormant until the conversation mentions specific trigger keywords (e.g., "SQLi", "Kerberoasting"). This on-demand activation ensures skills do not occupy context window space during unrelated discussions, yet provide immediate expertise when relevant topics arise.

### Can I install only specific categories of offensive security skills?

Yes. The [`install.sh`](https://github.com/SnailSploit/Claude-Red/blob/main/install.sh) script supports category filtering via the `--category` flag. You can preview installations using `--dry-run` before executing. For example, `./install.sh --category cloud` copies only cloud-security skills from `Skills/cloud/` rather than the entire 78+ technique library.

### What is the difference between using Claude-Red via CLI versus the web interface?

The CLI method pipes skill content directly into Claude using `cat Skills/category/skill/SKILL.md | claude --system-file -`, suitable for single-session expertise. The web interface requires manually copying [`SKILL.md`](https://github.com/SnailSploit/Claude-Red/blob/main/SKILL.md) contents into the System Prompt box of a Claude project, creating a persistent specialist configuration for that specific project workspace.