
Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and exploit development.

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.
Overview • Quickstart • Categories • Skill Index • Roadmap • Contributing
claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQL injection to shellcode, EDR evasion to ADCS abuse.
Drop a skill into your Claude environment and it behaves like a domain specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.
Use cases: authorized red team engagements, bug bounty triage, security research, CTF preparation, operator training, and methodical attack surface exploration.
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red
Claude auto-loads matching skills based on conversational triggers (e.g., mentioning SQL injection loads offensive-sqli).
To install a single category:
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -
cat Skills/active-directory/**/SKILL.md | claude --system-file -
Paste the contents of a SKILL.md into a Project's system prompt or prepend it to your conversation.
./install.sh # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web # single category
| Category | Skills | Focus |
|---|---|---|
| Web Application | 16 | OWASP Top 10, business logic, advanced web vulnerability classes |
| Auth & Identity | 2 | JWT exploitation, OAuth/OIDC abuse |
| Active Directory | 1 | On-prem AD attack methodology |
| Wireless | 14 | 802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz |
| Cloud | 1 | AWS, Azure, GCP attack paths |
| Mobile | 1 | Android and iOS application testing |
| IoT & Embedded | 1 | Hardware, firmware, RTOS, ICS/OT |
| Infrastructure & Red Team | 7 | Initial access, EDR evasion, advanced red team operations, Windows internals |
| Exploit Development | 6 | Stack/heap corruption, ROP, mitigations, crash analysis, TOCTOU |
| Fuzzing & Vulnerability Research | 4 | libFuzzer, AFL++, coverage-guided fuzzing, vulnerability taxonomy |
| Reconnaissance | 2 | OSINT tooling and structured intelligence collection |
| API Security | 2 | REST/gRPC/WebSocket testing, business logic abuse |
| Container & Kubernetes | 2 | Container escape, Kubernetes cluster exploitation |
| CI/CD & Pipeline | 2 | Pipeline exploitation, secrets extraction |
| Cryptography | 2 | Cryptographic implementation attacks, TLS/SSL |
| Privilege Escalation | 2 | Linux and Windows privilege escalation |
| Post-Exploitation | 3 | Lateral movement, persistence mechanisms, data exfiltration |
| Forensics & C2 | 2 | Anti-forensics tradecraft, C2 framework operations |
| Supply Chain | 2 | Supply chain attacks, dependency confusion |
| Social Engineering | 2 | Phishing campaigns, physical/vishing/smishing |
| Network Attacks | 1 | Layer 2/3 attacks, MITM, protocol poisoning |
| AI Security | 1 | Prompt injection, jailbreaking, RAG poisoning |
| Utility | 2 | Fast triage checklists, professional reporting |
Skills/web/