blacklanternsecurity/red-run

Offensive security toolkit for Claude Code

This repository also configures its own agents. See what red-run tells them →

267Stars on the repository
104Mods indexed here, across every type
5mo agoLast push, which is what freshness is scored on
GPL-3.0Licence, which decides whether bodies are shown

csrf

49

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.

not rated 267 +1 5mo ago C 20 tokens GPL-3.0

idor

54

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.

not rated 267 +1 5mo ago A 23 tokens GPL-3.0

jwt-attacks

55

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.

not rated 267 +1 5mo ago A 18 tokens GPL-3.0

ldap-injection

56

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit LDAP injection vulnerabilities during authorized penetration testing.

not rated 267 +1 5mo ago A 14 tokens GPL-3.0

lfi

57

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide Local File Inclusion (LFI) and Remote File Inclusion (RFI) exploitation during authorized penetration testing.

not rated 267 +1 5mo ago B 25 tokens GPL-3.0

oauth-attacks

59

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.

not rated 267 +1 5mo ago B 21 tokens GPL-3.0

php-code-injection

61

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit PHP code evaluation injection via eval(), assert(), pregreplace /e, createfunction(), calluserfunc(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluation of user input.

not rated 267 +1 5mo ago A 74 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit Python eval(), exec(), and compile() injection in web applications. Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct Python code evaluation of user input.

not rated 267 +1 5mo ago C 48 tokens GPL-3.0

race-condition

63

blacklanternsecurity/red-run

Skill Claude CodeCodex

Exploit race conditions and TOCTOU vulnerabilities in web applications during authorized penetration testing.

not rated 267 +1 5mo ago A 20 tokens GPL-3.0

smb-share-webshell

65

blacklanternsecurity/red-run

Skill Claude CodeCodex

Deploy webshells to IIS, Apache, or Tomcat web roots via SMB share write access. Use when a domain user has write access to a file share that maps to a web server's document root — write a webshell via smbclient/net use, then trigger it via HTTP for RCE. Covers PHP, ASPX, and JSP webshells, .NET impersonation for…

not rated 267 +1 5mo ago A 94 tokens GPL-3.0

source-code-review

66

blacklanternsecurity/red-run

Skill Claude CodeCodex

Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.

not rated 267 +1 5mo ago A 37 tokens GPL-3.0

sql-injection-blind

67

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide blind SQL injection exploitation (boolean-based, time-based, and out-of-band) during authorized penetration testing.

not rated 267 +1 5mo ago A 28 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide stacked query SQL injection and second-order injection exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 21 tokens GPL-3.0

ssrf

71

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide server-side request forgery (SSRF) exploitation during authorized penetration testing.

not rated 267 +1 5mo ago D 19 tokens GPL-3.0

ssti-freemarker

72

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide Freemarker/Java server-side template injection exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 22 tokens GPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: