blacklanternsecurity/red-run

Offensive security toolkit for Claude Code

This repository also configures its own agents. See what red-run tells them →

267Stars on the repository
104Mods indexed here, across every type
5mo agoLast push, which is what freshness is scored on
GPL-3.0Licence, which decides whether bodies are shown

ssti-jinja2

73

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide Jinja2/Python server-side template injection exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 22 tokens GPL-3.0

ssti-twig

74

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide Twig/PHP server-side template injection exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 19 tokens GPL-3.0

blacklanternsecurity/red-run

Skill Claude CodeCodex

Deploy WAR files via Apache Tomcat Manager for remote code execution. Use when Tomcat Manager is accessible with valid credentials (manager-script or manager-gui role). Covers WAR generation, deployment via text API and HTML interface, reverse shell delivery, and cleanup. Common initial access vector after credential…

not rated 267 +1 5mo ago C 76 tokens GPL-3.0

web-discovery

76

blacklanternsecurity/red-run

Skill Claude CodeCodex

Discover web application injection points and route to the correct exploitation skill during authorized penetration testing.

not rated 267 +1 5mo ago B 21 tokens GPL-3.0

xss-dom

77

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide DOM-based XSS exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 15 tokens GPL-3.0

xss-reflected

78

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide reflected XSS exploitation during authorized penetration testing.

not rated 267 +1 5mo ago B 15 tokens GPL-3.0

xss-stored

79

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide stored (persistent) and blind XSS exploitation during authorized penetration testing.

not rated 267 +1 5mo ago A 20 tokens GPL-3.0

xxe

80

blacklanternsecurity/red-run

Skill Claude CodeCodex

Guide XML External Entity (XXE) injection exploitation during authorized penetration testing.

not rated 267 +1 5mo ago C 18 tokens GPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: