// Skill profile
Claude-Red is a collection of 78 structured SKILL.md files across 23 offensive security categories, designed to prime Claude with expert-level methodology for specific attack surfaces. Each skill loads on demand based on conversational triggers, so you don't pay context tokens for skills you aren't using. Categories span web application security (16 skills), wireless attacks (14 skills), infrastructure and red team operations (7 skills), exploit development (6 skills), fuzzing (4 skills), post-exploitation (3 skills), reconnaissance, API security, container/Kubernetes, CI/CD, cryptography, privilege escalation, forensics, supply chain, social engineering, network attacks, AI security, and more. Install via git clone to your Claude skills directory or pipe individual SKILL.md files via CLI. MIT-licensed. 4.3K GitHub stars.
Claude-Red is a curated library of offensive security skills that transform Claude into a domain-specialized red team operator. Each skill is a structured SKILL.md file that encodes expert-level methodology for a specific attack surface — the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers, meaning you only pay context tokens for the methodology you’re actively using.
78 skills across 23 categories: The library covers the breadth of modern offensive security — web application attacks (SQLi, XSS, SSRF, IDOR, CORS, deserialization, GraphQL, and more), wireless security (Wi-Fi, Bluetooth, Zigbee, LoRa, NFC), Active Directory exploitation, cloud security, mobile and IoT testing, exploit development (binary, kernel, browser, ROP/JOP, shellcode, heap), fuzzing (AFL, libFuzzer, grammar-based, differential), infrastructure red teaming, post-exploitation, reconnaissance, and emerging areas like AI/ML security and supply chain attacks.
Structured methodology: Each SKILL.md follows a consistent format that primes Claude with the full attack lifecycle for its domain — from initial enumeration through exploitation to reporting. Skills reference specific tools, commands, common misconfigurations, and escalation paths rather than generic security advice.
On-demand loading: Skills activate based on conversational context. When you start discussing SQL injection, the SQLi skill loads automatically. When you shift to privilege escalation, the relevant skill replaces it. This keeps the active context focused and token-efficient.
Multiple deployment methods: Clone the full library to ~/.claude/skills/claude-red for automatic loading, pipe individual skills via cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -, or paste specific skills into project CLAUDE.md files. An install script supports category filtering for targeted setups.
Claude-Red is designed for authorized red team engagements where testers want Claude to act as a knowledgeable methodology partner — suggesting next steps, recommending tools, and helping interpret results. Bug bounty hunters use it to systematically work through attack surfaces. Security researchers use it for CTF preparation and technique exploration. The skills also serve as operator training materials, encoding structured methodology that junior testers can follow.
Claude-Red is an offensive security toolkit. Using it against targets you do not own or have explicit written authorization to test is illegal and unethical. The skills encode attack methodology — they make Claude more effective at finding and exploiting vulnerabilities, which is powerful in authorized contexts and dangerous in unauthorized ones. The library targets Claude Code and Claude Desktop; compatibility with other agent harnesses is not guaranteed. Some advanced skills (exploit development, kernel exploitation) require deep security knowledge to use the output responsibly.
Professional penetration testers and red team operators who want Claude as a methodology partner during authorized engagements. Bug bounty hunters looking for structured, systematic approaches to common attack surfaces. Security researchers and CTF competitors who want expert-level technique guidance. Security teams building internal testing capabilities who need a structured methodology library.
AI agents that work well with Claude-Red.
817 structured cybersecurity skills for AI agents — mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.
Reverse engineering via MCP — AI agents can decompile, analyze, and understand binary code using Ghidra.
150+ cybersecurity tools accessible via MCP — pentesting, vulnerability scanning, OSINT, and more.