SnailSploit/Claude-Red

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.

About the project

claude-red is a library of structured skills that give Claude specialized offensive-security methods for areas such as web vulnerabilities, shellcode, exploit development, and identity systems. It is intended for authorized red-team work, bug-bounty triage, security research, CTF preparation, and operator training. Its catalogue contains the project's skills for loading these security specializations into Claude.

3.0kStars on the repository
74Mods indexed here, across every type
8d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

SnailSploit/Claude-Red

Skill Claude CodeCodex

HTTP request smuggling checklist: CL.TE, TE.CL, TE.TE variants, detection with timing and differential responses, WAF bypass, cache poisoning, credential hijacking, and request smuggling via HTTP/2. Use when testing reverse proxy/load balancer configurations.

not rated 3.0k +31 8d ago A SkillSpector: pass 0 tokens original MIT

offensive-sqli

50

SnailSploit/Claude-Red

Skill Claude CodeCodex

SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based blind, out-of-band, second-order, NoSQL, GraphQL, WebSocket, and JSON-operator SQLi. Includes WAF bypass techniques, database-specific exploitation (MySQL, MSSQL, PostgreSQL…

not rated 3.0k +31 8d ago B SkillSpector: warn 117 tokens original MIT

offensive-ssrf

51

SnailSploit/Claude-Red

Skill Claude CodeCodex

Server-Side Request Forgery testing checklist: SSRF discovery, blind SSRF with out-of-band, cloud metadata endpoints (AWS/GCP/Azure), SSRF filter bypass techniques (IP encoding, DNS rebinding, redirect chains), and SSRF to RCE escalation. Use for web app SSRF testing and bug bounty.

not rated 3.0k +31 8d ago D 0 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

WAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.

not rated 3.0k +31 8d ago C SkillSpector: warn 0 tokens original MIT

offensive-xss

53

SnailSploit/Claude-Red

Skill Claude CodeCodex

Cross-Site Scripting testing checklist: stored/reflected/DOM/blind XSS discovery, polyglot payloads, CSP bypass, XSS filter bypass, event handler injection, DOM clobbering, mutation XSS, and impact escalation (session hijack, phishing, keylogging). Use for web app XSS testing and bug bounty.

not rated 3.0k +31 8d ago D 0 tokens original MIT

offensive-xxe

54

SnailSploit/Claude-Red

Skill Claude CodeCodex

XML External Entity injection testing checklist: classic XXE, blind XXE (out-of-band), XXE via file upload (SVG/docx), XXE in SOAP/REST, error-based XXE, XInclude attacks, and XXE filter bypass. Use for web app XXE testing and bug bounty.

not rated 3.0k +31 8d ago C SkillSpector: warn 0 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE…

not rated 3.0k +31 8d ago B SkillSpector: warn 122 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive…

not rated 3.0k +31 8d ago B SkillSpector: warn 123 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth for DoS (with authorization), action-frame attacks bypassing 802.11w (PMF), beacon flooding, mdk4 / aireplay-ng tooling, and rate-limit / PMF-aware operation. Use to coerce client…

not rated 3.0k +31 8d ago B SkillSpector: warn 103 tokens original MIT

offensive-evil-twin

58

SnailSploit/Claude-Red

Skill Claude CodeCodex

Evil Twin / KARMA / Mana access point methodology — rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe response, Mana selective probe response, captive portal phishing, deauth-driven client coercion to attacker AP, MAC randomization defeat via PNL leak analysis, post-association…

not rated 3.0k +31 8d ago D 129 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT…

not rated 3.0k +31 8d ago B SkillSpector: warn 125 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz protocol replay (KeeLoq garage doors, fixed-code remotes, TPMS spoofing, smart plug telemetry), HackRF / RTL-SDR /…

not rated 3.0k +31 8d ago A SkillSpector: warn 163 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and…

not rated 3.0k +31 8d ago A SkillSpector: warn 130 tokens original MIT

offensive-wifi

62

SnailSploit/Claude-Red

Skill Claude CodeCodex

Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons…

not rated 3.0k +31 8d ago A SkillSpector: warn 183 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

WPA/WPA2/WPA3-Enterprise (802.1X / EAP) attack methodology — EAP method identification (PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, EAP-GTC, EAP-PWD, EAP-FAST), evil-twin RADIUS attacks with eaphammer for credential capture, MSCHAPv2 challenge-response cracking, EAP-TLS client certificate theft paths (DPAPI, NDES, AD CS…

not rated 3.0k +31 8d ago B SkillSpector: warn 162 tokens original MIT

offensive-wpa2-psk

64

SnailSploit/Claude-Red

Skill Claude CodeCodex

WPA/WPA2-PSK attack methodology — four-way handshake capture via targeted deauthentication, PMKID attacks (no client required), hcxdumptool / hcxpcapngtool conversion to hashcat hc22000 format, GPU-accelerated cracking with dictionary, mask, and rule-based attacks, vendor default-PSK generators (UPC, Sky, BT, etc.)…

not rated 3.0k +31 8d ago B SkillSpector: warn 133 tokens original MIT

offensive-wpa3-sae

65

SnailSploit/Claude-Red

Skill Claude CodeCodex

WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377, 13456), SAE auth flooding for AP CPU exhaustion, Hash-to-Element (H2E) timing analysis, group downgrade, and 6 GHz / Wi-Fi 6E spec…

not rated 3.0k +31 8d ago B SkillSpector: warn 142 tokens original MIT

offensive-wps

66

SnailSploit/Claude-Red

Skill Claude CodeCodex

WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout handling, time-of-day evasion, WPS push-button vulnerability windows, and PIN-to-PSK derivation. Use when a target SOHO…

not rated 3.0k +31 8d ago B SkillSpector: warn 110 tokens original MIT

offensive-z-wave

67

SnailSploit/Claude-Red

Skill Claude CodeCodex

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting…

not rated 3.0k +31 8d ago A SkillSpector: pass 113 tokens original MIT

SnailSploit/Claude-Red

Skill Claude CodeCodex

Zigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, KillerBee toolkit, Touchlink commissioning abuse with the well-known transport key, replay/injection attacks, Zigbee Cluster Library command abuse for door locks and bulbs, Thread…

not rated 3.0k +31 8d ago A SkillSpector: pass 126 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: