Ling: Skill for Claude Code

.agents/skills/red-team-tactics/SKILL.md

red-team-tactics is a skill for Claude Code from MisonL/Ling. It costs 31 tokens per session (1,679 once invoked), scanned A, original, MIT.

Red-team security guidance based on MITRE ATT&CK, a framework that organizes real-world attacker behaviors. It covers attack stages, information gathering, avoiding detection, and reporting.

In plain words
What is it for?
Use it to plan or review authorized security simulations, map activities to attack stages, compare passive and active reconnaissance, and prepare findings.
Why use it?
It provides a structured way to think through how an attacker might enter, move through, and affect a system, as well as how to document the exercise.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: installed under .agents/ (shared by several agents).

This is MisonL/Ling's own configuration. It tells Claude Code how to work on Ling itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything Ling configures →

Reuse

Borrowing it

Nothing to install: this file belongs to MisonL/Ling. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/MisonL/Ling/main/.agents/skills/red-team-tactics/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/MisonL/Ling

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for red-team-tactics

README.md
[![agentmods](https://agentmods.dev/badge/skills/misonl/ling/red-team-tactics/github.svg)](https://agentmods.dev/skills/misonl/ling/red-team-tactics)
Your own site
<a href="https://agentmods.dev/skills/misonl/ling/red-team-tactics"><img src="https://agentmods.dev/badge/skills/misonl/ling/red-team-tactics/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for red-team-tactics

Your own site · 80×15
<a href="https://agentmods.dev/skills/misonl/ling/red-team-tactics"><img src="https://agentmods.dev/badge/skills/misonl/ling/red-team-tactics.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 31 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,679 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00031 $0.01679
Opus 5 $0.00015 $0.00839
Sonnet 5 $0.00006 $0.00336
Haiku 4.5 $0.00003 $0.00168

Measured 8d ago against content hash d13a7c0c0677, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

red-team-tactics scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/red-team-tactics/SKILL.md · 204 lines

How it starts

The opening of the file, as written. The whole thing — 204 lines — stays where its author put it; the contents beside it link to each section on GitHub.

红队战术

基于 MITRE ATT&CK 框架的对抗模拟原则。


1. MITRE ATT&CK 攻击阶段

攻击生命周期

侦察(Reconnaissance)-> 初始访问(Initial Access)-> 执行(Execution)-> 持久化(Persistence)
        v                    v                    v                  v
    权限提升(Priv Esc)-> 防御规避(Defense Evasion)-> 凭据访问(Credential Access)-> 发现(Discovery)
        v                    v                    v                  v
    横向移动(Lateral Movement)-> 数据收集(Collection)-> 指挥控制(C2)-> 数据泄露(Exfiltration)-> 影响力(Impact)

各阶段目标

阶段 核心目标
侦察(Recon) 映射攻击面
初始访问 获取首个立足点
执行(Execution) 在目标上运行代码
持久化 在重启后依然存活
权限提升 获取管理员(Admin)或 Root 权限
防御规避 躲避安全检测
凭据访问 收集并提取各类凭据
发现(Discovery) 映射内网环境
横向移动 扩散至其他系统
数据收集 搜集目标敏感数据
指挥控制(C2) 维持命令下发通道
数据泄露(Exfil) 提取并带出数据

2. 侦察准则

被动侦察与主动侦察

类型 权衡(Trade-off)
被动侦察 不与目标直接接触,获取信息有限,但安全性极高
主动侦察 直接接触目标,获取信息多,但暴露风险极高

信息搜集重点

类别 价值所在
技术栈 选择合适的攻击向量
员工信息 用于社会工程学攻击
网络范围 确定扫描范围
第三方协作 开展供应链攻击

3. 初始访问向量

选择标准

向量 适用场景
网络钓鱼(Phishing) 针对人员,需要邮件访问权限
公开漏洞(Exploits) 暴露在外的易受攻击服务
合规凭据 泄露或被暴力破解的帐号
供应链攻击 通过第三方供应商接入

4. 权限提升原则

Windows 平台关注点

检查项 利用机会
未加引号的服务路径 利用路径写入漏洞
弱服务权限 修改服务执行逻辑
令牌特权(Token) 滥用 SeDebug 等特权
存储的凭据 离线或在线提取

Read the full file on GitHub · 204 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 204 lines · 31 tokens per session scan A d13a7c0c0677

Subscribe to this mod's changes

red-team-tactics is a skill published in the GitHub repository MisonL/Ling (8 stars, last pushed 5mo ago), licensed MIT. It adds 31 tokens to every session and 1,679 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

local-ai-agents

Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…

microsoft/ai-agents-for-beginners · 200 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

next-cache-components-optimizer

Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…

vercel/next.js · 170 tokens

next-partial-prefetching-adoption

Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…

vercel/next.js · 103 tokens

chronicle

Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…

microsoft/vscode · 72 tokens