SnailSploit/Claude-RedPublic

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.

Stars
3.3K
Forks
534
Watchers
32
Open issues
6
Open PRs
5
Contributors
~5
Commits
34
Branches
3

PythonMITCreated Mar 4, 2026Last push 13d agoLatest release v0.3.0

Star history

since Apr 19, 2026
01K2K3KApr 2026Jun 2026Jul 2026Sep 2026
3.3K stars as of Sep 12, 2026, tracked back to Apr 19, 2026. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 0 commits2026-03-04: 5 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 0 commits2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 0 commits2026-03-19: 0 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 2 commits2026-04-16: 0 commits2026-04-17: 1 commit2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 0 commits2026-04-23: 0 commits2026-04-24: 0 commits2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 2 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 0 commits2026-05-05: 0 commits2026-05-06: 7 commits2026-05-07: 0 commits2026-05-08: 1 commit2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 0 commits2026-05-20: 0 commits2026-05-21: 0 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 0 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 0 commits2026-06-09: 0 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 0 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 0 commits2026-06-17: 0 commits2026-06-18: 0 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 0 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 0 commits2026-07-01: 0 commits2026-07-02: 0 commits2026-07-03: 0 commits2026-07-04: 0 commits2026-07-05: 0 commits2026-07-06: 0 commits2026-07-07: 0 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 0 commits2026-07-15: 0 commits2026-07-16: 0 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 0 commits2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 0 commits2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 0 commits2026-07-29: 0 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 0 commits2026-08-03: 0 commits2026-08-04: 0 commits2026-08-05: 0 commits2026-08-06: 0 commits2026-08-07: 0 commits2026-08-08: 0 commits2026-08-09: 0 commits2026-08-10: 0 commits2026-08-11: 0 commits2026-08-12: 0 commits2026-08-13: 0 commits2026-08-14: 0 commits2026-08-15: 0 commits2026-08-16: 0 commits2026-08-17: 0 commits2026-08-18: 0 commits2026-08-19: 0 commits2026-08-20: 0 commits2026-08-21: 0 commits2026-08-22: 0 commits2026-08-23: 0 commits2026-08-24: 0 commits2026-08-25: 6 commits2026-08-26: 2 commits2026-08-27: 0 commits2026-08-28: 0 commits2026-08-29: 2 commits2026-08-30: 0 commits2026-08-31: 0 commits2026-09-01: 0 commits2026-09-02: 0 commits2026-09-03: 0 commits2026-09-04: 0 commits2026-09-05: 0 commits2026-09-06: 0 commits2026-09-07: 0 commits2026-09-08: 0 commits2026-09-09: 0 commits2026-09-10: 0 commits2026-09-11: 0 commits2026-09-12: 0 commits
28 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

README

main branch

claude-red banner

claude-red

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.

License: MIT Skills Categories Stars Forks

OverviewQuickstartCategoriesSkill IndexRoadmapContributing


Overview

claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQL injection to shellcode, EDR evasion to ADCS abuse.

Drop a skill into your Claude environment and it behaves like a domain specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.

Use cases: authorized red team engagements, bug bounty triage, security research, CTF preparation, operator training, and methodical attack surface exploration.


Quickstart

Claude Skills System (Recommended)

git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

Claude auto-loads matching skills based on conversational triggers (e.g., mentioning SQL injection loads offensive-sqli).

To install a single category:

git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

Claude Code

cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

cat Skills/active-directory/**/SKILL.md | claude --system-file -

Claude.ai (Manual)

Paste the contents of a SKILL.md into a Project's system prompt or prepend it to your conversation.

Install Script

./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # single category

Categories

Category Skills Focus
Web Application 16 OWASP Top 10, business logic, advanced web vulnerability classes
Auth & Identity 2 JWT exploitation, OAuth/OIDC abuse
Active Directory 1 On-prem AD attack methodology
Wireless 14 802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz
Cloud 1 AWS, Azure, GCP attack paths
Mobile 1 Android and iOS application testing
IoT & Embedded 1 Hardware, firmware, RTOS, ICS/OT
Infrastructure & Red Team 7 Initial access, EDR evasion, advanced red team operations, Windows internals
Exploit Development 6 Stack/heap corruption, ROP, mitigations, crash analysis, TOCTOU
Fuzzing & Vulnerability Research 4 libFuzzer, AFL++, coverage-guided fuzzing, vulnerability taxonomy
Reconnaissance 2 OSINT tooling and structured intelligence collection
API Security 2 REST/gRPC/WebSocket testing, business logic abuse
Container & Kubernetes 2 Container escape, Kubernetes cluster exploitation
CI/CD & Pipeline 2 Pipeline exploitation, secrets extraction
Cryptography 2 Cryptographic implementation attacks, TLS/SSL
Privilege Escalation 2 Linux and Windows privilege escalation
Post-Exploitation 3 Lateral movement, persistence mechanisms, data exfiltration
Forensics & C2 2 Anti-forensics tradecraft, C2 framework operations
Supply Chain 2 Supply chain attacks, dependency confusion
Social Engineering 2 Phishing campaigns, physical/vishing/smishing
Network Attacks 1 Layer 2/3 attacks, MITM, protocol poisoning
AI Security 1 Prompt injection, jailbreaking, RAG poisoning
Utility 2 Fast triage checklists, professional reporting

Skill Index

Web Application

Skills/web/

Skill Description
offensive-sqli SQL injection — error-based, blind, OOB, DB-specific payloads, ORM CVEs
offensive-xss Cross-site scripting — stored, reflected, DOM-based, mutation XSS
offensive-ssrf Server-side request forgery — cloud metadata pivots, filter bypass
offensive-ssti Server-side template injection — engine fingerprinting, RCE chains
offensive-xxe XML external entity — OOB exfiltration, blind XXE techniques
offensive-idor Insecure direct object references — enumeration, authorization bypass
offensive-file-upload File upload — extension bypass, polyglot files, webshell deployment
offensive-rce Remote code execution — command injection, deserialization chains
offensive-deserialization Insecure deserialization — Java, PHP, .NET gadget chains
offensive-race-condition Race conditions — TOCTOU, single-packet attacks, limit bypass
offensive-request-smuggling HTTP request smuggling — CL.TE, TE.CL, H2 desync
offensive-open-redirect Open redirect — OAuth token theft, phishing, SSRF pivots
offensive-parameter-pollution HTTP parameter pollution — WAF bypass, logic confusion
offensive-graphql GraphQL — introspection abuse, batching attacks, alias-based IDOR
offensive-waf-bypass WAF bypass — encoding tricks, chunked transfer, case mutation
offensive-business-logic Business logic — workflow bypass, pricing abuse, multi-step chains

Auth & Identity

Skills/auth/

Skill Description
offensive-jwt JWT attacks — alg:none, key confusion, secret cracking, claim tampering
offensive-oauth OAuth/OIDC — redirect URI abuse, token leakage, PKCE bypass

Active Directory

Skills/active-directory/

Skill Description
offensive-active-directory AD methodology — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, hybrid AAD

Wireless

Skills/wireless/

Skill Description
offensive-wifi 802.11 overview — entrypoint for wireless assessments
offensive-wifi-recon Adapter configuration, monitor mode, multi-band airspace mapping
offensive-wpa2-psk WPA2-PSK — handshake capture, PMKID extraction, hashcat cracking
offensive-wpa3-sae WPA3-SAE — transition-mode downgrade, Dragonblood, side-channel attacks
offensive-wpa-enterprise 802.1X/EAP — credential relay, evil-twin RADIUS, certificate abuse
offensive-wps WPS — Pixie Dust offline attack, online PIN brute force, vendor PIN prediction
offensive-evil-twin Evil twin — KARMA, Mana, captive portal credential capture, MITM
offensive-krack-fragattacks KRACK and FragAttacks — supplicant vulnerability testing
offensive-deauth-disassoc Deauthentication — targeted/broadcast frames, PMF awareness
offensive-bluetooth-ble Bluetooth LE — GATT enumeration, pairing downgrade, sniffing, MITM
offensive-bluetooth-classic Bluetooth BR/EDR — SDP probing, KNOB attack, BlueBorne, HID spoofing
offensive-zigbee-thread-matter 802.15.4 mesh — KillerBee, Touchlink commissioning abuse, ZCL injection
offensive-z-wave Z-Wave — S0 key derivation, S2 commissioning attacks, hub pivots
offensive-lorawan-sub-ghz LoRaWAN and sub-GHz — ABP/OTAA attacks, KeeLoq, fixed-code replay, TPMS

Cloud

Skills/cloud/

Skill Description
offensive-cloud Multi-cloud — privilege escalation, IMDS abuse, cross-account pivots, CSPM evasion

Mobile

Skills/mobile/

Skill Description
offensive-mobile Android and iOS — Frida hooking, certificate pinning bypass, storage, biometric flaws

IoT & Embedded

Skills/iot/

Skill Description
offensive-iot IoT/OT — hardware interfaces, firmware extraction, RTOS, ICS protocols, MQTT/CoAP

Infrastructure & Red Team

Skills/infrastructure/

Skill Description
offensive-initial-access Initial access — phishing payloads, drive-by delivery, supply chain vectors (TA0001)
offensive-advanced-redteam Full kill chain — C2 infrastructure, OPSEC, lateral movement, persistence
offensive-edr-evasion EDR evasion — userland unhooking, indirect syscalls, PPID spoofing
offensive-shellcode Shellcode — writing, encoding, injection techniques, position-independent code
offensive-keylogger-arch Input capture — keylogger architecture, hooking mechanisms
offensive-windows-mitigations Windows mitigations — ACG, CIG, CFG, CET bypass techniques
offensive-windows-boundaries Windows boundary defeat — sandbox escape, integrity level bypass

Exploit Development

Skills/exploit-dev/

Skill Description
offensive-exploit-development Exploit development — stack/heap corruption, ROP chains, mitigation bypass
offensive-exploit-dev-course Structured exploit development curriculum
offensive-basic-exploitation Linux binary exploitation — beginner to intermediate, mitigations disabled
offensive-crash-analysis Crash triage — exploitability assessment, root-cause analysis
offensive-mitigations Modern mitigations — ASLR, CFG, CET, PAC analysis and bypass
offensive-toctou TOCTOU race conditions — binary, kernel, web, and container contexts

Fuzzing & Vulnerability Research

Skills/fuzzing/

Skill Description
offensive-fuzzing Fuzzing — libFuzzer, AFL++, coverage-guided strategies, mutation engines
offensive-fuzzing-course Vulnerability discovery through fuzzing — structured curriculum
offensive-bug-identification Bug identification — code review patterns, static analysis triggers
offensive-vuln-classes Vulnerability taxonomy — real-world examples, classification frameworks

Reconnaissance

Skills/recon/

Skill Description
offensive-osint OSINT tooling — recon-ng, theHarvester, Maltego, Spiderfoot
offensive-osint-methodology OSINT methodology — structured intelligence collection and analysis

API Security

Skills/api/

Skill Description
offensive-api-security API testing — OWASP API Top 10, BOLA, BFLA, mass assignment, rate limiting
offensive-api-abuse API business logic — endpoint chaining, batching abuse, webhook hijacking

Container & Kubernetes

Skills/container/

Skill Description
offensive-container-escape Container breakout — privileged mode, Docker socket, capabilities, runc CVEs
offensive-k8s-attacks Kubernetes attacks — RBAC abuse, etcd access, kubelet API, pod escape, CRD exploitation

CI/CD & Pipeline

Skills/cicd/

Skill Description
offensive-cicd-pipeline CI/CD exploitation — GitHub Actions injection, Jenkins RCE, GitLab CI abuse
offensive-cicd-secrets CI/CD secrets — environment variable extraction, vault misconfigs, runner token abuse

Cryptography

Skills/crypto/

Skill Description
offensive-crypto-attacks Cryptographic attacks — padding oracle, ECB manipulation, hash extension, weak PRNG
offensive-tls-attacks TLS/SSL attacks — POODLE, DROWN, Heartbleed, pinning bypass, 0-RTT replay

Privilege Escalation

Skills/privesc/

Skill Description
offensive-linux-privesc Linux privilege escalation — SUID, capabilities, sudo, cron, kernel exploits
offensive-windows-privesc Windows privilege escalation — Potato family, service misconfigs, DLL hijacking, UAC bypass

Post-Exploitation

Skills/post-exploitation/

Skill Description
offensive-lateral-movement Lateral movement — PTH, PTT, NTLM relay, WMI/WinRM/DCOM, tunneling
offensive-persistence Persistence — registry, scheduled tasks, WMI subscriptions, ticket forgery, PAM backdoors
offensive-data-exfiltration Data exfiltration — DNS/HTTPS/ICMP tunneling, cloud staging, steganography

Forensics & C2

Skills/forensics/

Skill Description
offensive-anti-forensics Anti-forensics — log manipulation, timestomping, ADS abuse, memory cleanup
offensive-c2-frameworks C2 tradecraft — Cobalt Strike, Sliver, Mythic, Havoc, redirectors, domain fronting

Supply Chain

Skills/supply-chain/

Skill Description
offensive-supply-chain Supply chain attacks — dependency confusion, typosquatting, build system compromise
offensive-dependency-confusion Dependency confusion — npm/PyPI/NuGet/Maven namespace attacks, safe PoC methodology

Social Engineering

Skills/social-engineering/

Skill Description
offensive-phishing Phishing — GoPhish, EvilGinx2, payload delivery, email authentication bypass
offensive-social-engineering Social engineering — pretexting, vishing, smishing, physical SE, USB drops

Network Attacks

Skills/network/

Skill Description
offensive-network-attacks Network layer attacks — ARP spoofing, LLMNR/NBT-NS poisoning, VLAN hopping, MITM

AI Security

Skills/ai/

Skill Description
offensive-ai-security AI/ML security — prompt injection, jailbreaking, RAG poisoning, model extraction

Utility

Skills/utility/

Skill Description
offensive-fast-checking Fast triage — quick-win identification checklists
offensive-reporting Professional reporting — CVSS scoring, evidence standards, executive summaries

Roadmap

The library is being expanded across multiple phases. See CHANGELOG.md for release history.

Phase Focus Skills Status
1 Internal AD/Windows — split into focused skills +16 Planned
2 Cloud Identity — Entra, ADFS, Okta, M365 +10 Planned
3 Wireless — WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz +12 Complete
4 IoT — UART/JTAG, flash extraction, fault injection, RTOS, ICS +10 Planned
5 Web Fundamentals — recon, auth bypass, access control, CSRF, CORS +8 Planned
6 Web Advanced — proto pollution, SAML, OIDC, WebSocket, SSI/ESI +10 Planned
7 Documentation and tooling polish Complete
8 New categories — 10 new domains with 20 skills +20 Complete
9 Deep rewrites — deserialization, GraphQL, advanced red team, SSTI Complete

Target: ~130 skills across 23+ categories.


Contributing

Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.

License

MIT — use freely, attribution appreciated.

Acknowledgements

  • Author: Kai Aizen (SnailSploit) — GenAI security research
  • Original Checklists: Sahar Shlichov — the offensive checklist collection that many of these skills build on
  • Community: Pull requests and feedback that keep the library aligned with the evolving threat landscape

Give Claude the right skill and it stops being a chatbot — it becomes an operator.

snailsploit.comGitHubResearchX

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Releases and announcements

2 total
  1. ## What's New Major expansion — claude-red goes from 37 skills in flat directories to **78 skills across 23 organized categories**. This release adds full-spectrum offensive coverage from container escapes to wireless protocol attacks. ### 20 New Skills Across 10 Categories - **container/** — Docker/containerd breakout, runc CVEs, K8s RBAC abuse, etcd, kubelet API, pod escape - - **cicd/** — GitHub Actions injection, Jenkins RCE, GitLab CI, secret extraction, OIDC federation - - **api/** — OWASP API Top 10, REST/gRPC/WebSocket, batching attacks, webhook hijacking - - **crypto/** — Padding oracle, ECB, hash extension, RSA, POODLE/DROWN/Heartbleed, pinning bypass - - **privesc/** — Linux SUID/capabilities/sudo/kernel + Windows Potato family, DLL hijacking, UAC bypass - - **post-exploitation/** — Lateral movement (PTH/PTT/NTLM relay), persistence (Golden/Silver tickets), data exfiltration (DNS/HTTPS/ICMP tunneling) - - **forensics/** — Anti-forensics (timestomping, ADS, anti-VM) + C2 frameworks (Cobalt Strike, Sliver, Mythic, Havoc) - - **supply-chain/** — Dependency confusion, typosquatting, build pipeline attacks - - **social-engineering/** — GoPhish, EvilGinx2, MFA

  2. Claude-Red-Skills V.2SnailMar 8, 2026

    **Full Changelog**: https://github.com/SnailSploit/Claude-Red/commits/Snail

Commits per week

last 52 weeks
100Week of 2025-09-13: 0 commitsWeek of 2025-09-20: 0 commitsWeek of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 5 commitsWeek of 2026-03-08: 0 commitsWeek of 2026-03-15: 0 commitsWeek of 2026-03-22: 0 commitsWeek of 2026-03-29: 0 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 3 commitsWeek of 2026-04-19: 0 commitsWeek of 2026-04-26: 2 commitsWeek of 2026-05-03: 8 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 0 commitsWeek of 2026-05-24: 0 commitsWeek of 2026-05-31: 0 commitsWeek of 2026-06-07: 0 commitsWeek of 2026-06-14: 0 commitsWeek of 2026-06-21: 0 commitsWeek of 2026-06-28: 0 commitsWeek of 2026-07-05: 0 commitsWeek of 2026-07-12: 0 commitsWeek of 2026-07-19: 0 commitsWeek of 2026-07-26: 0 commitsWeek of 2026-08-02: 0 commitsWeek of 2026-08-09: 0 commitsWeek of 2026-08-16: 0 commitsWeek of 2026-08-23: 10 commitsWeek of 2026-08-30: 0 commitsWeek of 2026-09-06: 0 commitsSep 13, 2025Sep 6, 2026
28 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 0 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 0 commitsSun 10:00 — 0 commitsSun 11:00 — 0 commitsSun 12:00 — 0 commitsSun 13:00 — 0 commitsSun 14:00 — 0 commitsSun 15:00 — 0 commitsSun 16:00 — 0 commitsSun 17:00 — 0 commitsSun 18:00 — 0 commitsSun 19:00 — 0 commitsSun 20:00 — 0 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 0 commitsMon 0:00 — 0 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 0 commitsMon 5:00 — 0 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 0 commitsMon 9:00 — 0 commitsMon 10:00 — 0 commitsMon 11:00 — 0 commitsMon 12:00 — 0 commitsMon 13:00 — 0 commitsMon 14:00 — 0 commitsMon 15:00 — 0 commitsMon 16:00 — 0 commitsMon 17:00 — 0 commitsMon 18:00 — 0 commitsMon 19:00 — 0 commitsMon 20:00 — 0 commitsMon 21:00 — 0 commitsMon 22:00 — 0 commitsMon 23:00 — 0 commitsTue 0:00 — 0 commitsTue 1:00 — 0 commitsTue 2:00 — 0 commitsTue 3:00 — 0 commitsTue 4:00 — 0 commitsTue 5:00 — 0 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 0 commitsTue 9:00 — 0 commitsTue 10:00 — 0 commitsTue 11:00 — 0 commitsTue 12:00 — 0 commitsTue 13:00 — 0 commitsTue 14:00 — 0 commitsTue 15:00 — 6 commitsTue 16:00 — 0 commitsTue 17:00 — 0 commitsTue 18:00 — 0 commitsTue 19:00 — 0 commitsTue 20:00 — 0 commitsTue 21:00 — 0 commitsTue 22:00 — 0 commitsTue 23:00 — 0 commitsWed 0:00 — 0 commitsWed 1:00 — 0 commitsWed 2:00 — 0 commitsWed 3:00 — 0 commitsWed 4:00 — 2 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 7 commitsWed 8:00 — 2 commitsWed 9:00 — 3 commitsWed 10:00 — 1 commitsWed 11:00 — 0 commitsWed 12:00 — 1 commitsWed 13:00 — 0 commitsWed 14:00 — 0 commitsWed 15:00 — 0 commitsWed 16:00 — 0 commitsWed 17:00 — 0 commitsWed 18:00 — 0 commitsWed 19:00 — 0 commitsWed 20:00 — 0 commitsWed 21:00 — 0 commitsWed 22:00 — 0 commitsWed 23:00 — 0 commitsThu 0:00 — 0 commitsThu 1:00 — 0 commitsThu 2:00 — 0 commitsThu 3:00 — 0 commitsThu 4:00 — 0 commitsThu 5:00 — 0 commitsThu 6:00 — 0 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 0 commitsThu 10:00 — 0 commitsThu 11:00 — 0 commitsThu 12:00 — 0 commitsThu 13:00 — 0 commitsThu 14:00 — 0 commitsThu 15:00 — 0 commitsThu 16:00 — 0 commitsThu 17:00 — 0 commitsThu 18:00 — 0 commitsThu 19:00 — 0 commitsThu 20:00 — 0 commitsThu 21:00 — 0 commitsThu 22:00 — 0 commitsThu 23:00 — 0 commitsFri 0:00 — 0 commitsFri 1:00 — 0 commitsFri 2:00 — 0 commitsFri 3:00 — 0 commitsFri 4:00 — 0 commitsFri 5:00 — 0 commitsFri 6:00 — 0 commitsFri 7:00 — 0 commitsFri 8:00 — 1 commitsFri 9:00 — 1 commitsFri 10:00 — 0 commitsFri 11:00 — 0 commitsFri 12:00 — 0 commitsFri 13:00 — 0 commitsFri 14:00 — 1 commitsFri 15:00 — 0 commitsFri 16:00 — 0 commitsFri 17:00 — 0 commitsFri 18:00 — 0 commitsFri 19:00 — 1 commitsFri 20:00 — 0 commitsFri 21:00 — 0 commitsFri 22:00 — 0 commitsFri 23:00 — 0 commitsSat 0:00 — 0 commitsSat 1:00 — 0 commitsSat 2:00 — 0 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 0 commitsSat 7:00 — 0 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 0 commitsSat 11:00 — 0 commitsSat 12:00 — 0 commitsSat 13:00 — 1 commitsSat 14:00 — 0 commitsSat 15:00 — 0 commitsSat 16:00 — 0 commitsSat 17:00 — 0 commitsSat 18:00 — 0 commitsSat 19:00 — 1 commitsSat 20:00 — 0 commitsSat 21:00 — 0 commitsSat 22:00 — 0 commitsSat 23:00 — 0 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.

Who is committing

last 52 weeks
Maintainer commits15 (44%)
Community commits19 (56%)

34 commits in total over the last year.

DateListRankStars gained
Sep 12, 2026daily#12+99