What Is Claude-Red? A Complete Guide to the Offensive Security Skills Library
Claude-Red is a curated library of offensive-security "skills" designed to transform Claude into a context-aware red-team assistant by loading domain-specific expertise only when triggered by relevant conversation keywords.
Claude-Red is an open-source repository maintained by SnailSploit that provides pre-built attack methodologies for the Claude Skills system. This library contains over 78 offensive techniques spanning 23 categories including web application security, wireless networks, cloud infrastructure, and Active Directory. By installing these skills into Claude's skill directory, security practitioners can convert the general-purpose LLM into a specialized red-team operator without manually crafting complex system prompts.
How Claude-Red Works
The Claude-Red architecture relies on SKILL.md files that pre-load Claude with detailed, domain-specific methodology, tooling recommendations, and exploitation steps for particular attack surfaces. Each skill resides in the Skills/ directory and follows a strict front-matter template that the Claude runtime parses to expose the skill's name, description, and trigger keywords.
When placed in Claude's ~/.claude/skills directory, Claude auto-discovers these capabilities and activates them on demand. Activation occurs when conversation mentions relevant triggers such as "SQLi", "Kerberoasting", or "Kubernetes". Because skills load dynamically based on context, they do not consume extra prompt tokens for unrelated topics, yet supply the depth of a specialist operator when needed.
Repository Structure and Key Components
According to the SnailSploit/Claude-Red source code, the repository organizes offensive security knowledge through three primary layers:
The Skills Directory
The Skills/ directory contains hierarchical folders (e.g., web/, wireless/, cloud/, privesc/) each housing one or more SKILL.md files. These markdown files contain complete attack methodologies for specific vectors:
Skills/web/offensive-sqli/SKILL.md– SQL injection techniquesSkills/wireless/offensive-wpa2-psk/SKILL.md– WPA2-PSK attacksSkills/cloud/offensive-cloud/SKILL.md– AWS/Azure/GCP exploitationSkills/container/offensive-k8s-attacks/SKILL.md– Kubernetes attacksSkills/privesc/offensive-windows-privesc/SKILL.md– Windows privilege escalationSkills/utility/offensive-reporting/SKILL.md– Report writing methodology
The Claude-Skills Manifest
The claude-skills.json file serves as a machine-readable manifest that enumerates every skill, its category, path, and description. Claude uses this JSON to index the library and present a searchable catalog to users, enabling quick discovery of relevant capabilities across the 23+ categories.
The Installation Script
The install.sh Bash script automates deployment by copying selected skills to a target directory (default ~/.claude/skills/claude-red). The script supports sparse checkouts, dry-runs for validation, and category filtering to install only relevant skill sets.
Installing Claude-Red Skills
You can deploy Claude-Red using the interactive installer or manually clone the repository. The installation process supports full library deployment or selective category installation.
Full Library Installation
To install the complete collection of 78+ offensive security skills:
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red
./install.sh
The script prompts for the target directory and copies all SKILL.md files into Claude's skill path.
Category-Specific Installation
For targeted deployments, install only specific categories to minimize overhead. First, perform a dry-run to preview the installation:
./install.sh --category web --dry-run
After verifying the output shows the correct SKILL.md files, execute the actual copy:
./install.sh --category web
This approach copies only Skills/web/ content, reducing clutter while maintaining expertise in your target domain.
Using Claude-Red in Practice
Once installed, Claude-Red skills integrate seamlessly into both CLI and GUI workflows.
Command-Line Usage
Feed a skill directly as a system prompt using the Claude CLI:
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -
This command loads the SQL injection expertise immediately, enabling Claude to answer questions with specialist-level detail regarding exploitation techniques and bypass methodologies.
GUI Integration
To manually load a skill in the Claude.ai web interface:
- Open a Claude project.
- Navigate to the desired
SKILL.mdfile (e.g.,Skills/network/offensive-network-attacks/SKILL.md). - Copy the contents and paste them into the System Prompt box.
Claude treats the session as if it possesses native knowledge of network-layer attacks, providing methodology-specific guidance without additional context window consumption.
Summary
- Claude-Red is a curated library of 78+ offensive security skills for the Claude Skills system maintained by SnailSploit.
- SKILL.md files in the
Skills/directory contain domain-specific attack methodologies that auto-activate when conversation triggers match predefined keywords. - The
claude-skills.jsonmanifest indexes all capabilities across 23 categories including web, cloud, AD, and IoT security. - The
install.shscript supports full or category-specific deployments with dry-run validation. - Skills load on-demand to preserve context window efficiency while delivering specialist operator depth when needed.
Frequently Asked Questions
What file format does Claude-Red use for skill definitions?
Claude-Red uses SKILL.md files—Markdown documents with strict front-matter templates that Claude parses to extract the skill name, description, and trigger keywords. These files reside in category-specific subdirectories under Skills/ (e.g., Skills/web/offensive-sqli/SKILL.md).
How does Claude-Red avoid consuming prompt tokens for unrelated conversations?
Claude-Red leverages the Claude Skills system auto-discovery mechanism. Skills remain dormant until the conversation mentions specific trigger keywords (e.g., "SQLi", "Kerberoasting"). This on-demand activation ensures skills do not occupy context window space during unrelated discussions, yet provide immediate expertise when relevant topics arise.
Can I install only specific categories of offensive security skills?
Yes. The install.sh script supports category filtering via the --category flag. You can preview installations using --dry-run before executing. For example, ./install.sh --category cloud copies only cloud-security skills from Skills/cloud/ rather than the entire 78+ technique library.
What is the difference between using Claude-Red via CLI versus the web interface?
The CLI method pipes skill content directly into Claude using cat Skills/category/skill/SKILL.md | claude --system-file -, suitable for single-session expertise. The web interface requires manually copying SKILL.md contents into the System Prompt box of a Claude project, creating a persistent specialist configuration for that specific project workspace.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →