← all repositories
0xwilliamortiz/claude-red

Claude’s Red Team Library Hires Experts by Trigger

A library of 58 offensive-security skills that prime Claude with expert red-team methodology for specific attack surfaces, loading on demand when conversation triggers match.

707 stars JavaScript Coding Assistants
Feature · 09 Aug 2026
The Markdown Arsenal: Distilling Offensive Expertise for Claude

Claude-Red encodes decades of offensive security tradecraft into modular, trigger-loaded skill files so that an LLM can behave like a context-aware operator rather than a brittle script generator.

Read the in-depth article
claude-red
Velocity · 7d
+0.0
★ / day
Trend
cooling
star history

What it does

claude-red is a collection of 58 structured SKILL.md files spanning 13 offensive-security categories, from SQL injection and HTTP request smuggling to WPA3 side-channels and Windows boundary escapes. Dropped into Claude’s skills system, each file acts as a specialist that knows the tooling, edge cases, and escalation paths for its domain. Skills activate on conversational triggers—mention SQLi and the injection expert loads, mention Zigbee and the wireless mesh attacker appears—so unused expertise stays out of the context window.

The interesting bit

The project treats prompt context like a magazine, not a backpack: instead of hauling every technique in a bloated system prompt, it loads only the expertise needed for the target at hand. That keeps token count low and focus high, which matters when you are chaining exploits or walking through gadget chains.

Key highlights

  • 58 skills across 13 categories, with heavy depth in web bugs (16 skills) and wireless attacks (13 skills).
  • Covers niche physical-layer territory often missing from AI security tools: BLE pairing downgrade, Zigbee Touchlink abuse, LoRaWAN ABP exploitation, and sub-GHz keyfobs.
  • Includes modern infrastructure tradecraft: indirect syscalls, PPID spoofing, unhooking, and Windows boundary escapes.
  • Ships with a companion CLI and optional Windows UI binary for installing and browsing the skill library.

Caveats

  • Several categories are still thin: Active Directory, cloud, mobile, IoT, and AI security each have only one overview skill, and the README notes these are “expanding” or awaiting splits into focused modules.
  • The README is truncated mid-sentence in the provided source, so the full exploit-development and fuzzing skill lists are incomplete.

Verdict

Worth a look if you use Claude Code for authorized pentesting, CTF prep, or bug-bounty triage and want domain-specific expertise without hand-holding. Skip it if you need a fully mature, balanced curriculum—this is a living library with clear gaps in mid-depth categories.

Frequently asked

What is 0xwilliamortiz/claude-red?
A library of 58 offensive-security skills that prime Claude with expert red-team methodology for specific attack surfaces, loading on demand when conversation triggers match.
Is claude-red open source?
Yes — 0xwilliamortiz/claude-red is open source, released under the MIT license.
What language is claude-red written in?
0xwilliamortiz/claude-red is primarily written in JavaScript.
How popular is claude-red?
0xwilliamortiz/claude-red has 707 stars on GitHub and is currently cooling off.
Where can I find claude-red?
0xwilliamortiz/claude-red is on GitHub at https://github.com/0xwilliamortiz/claude-red.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.