claudemods

Sourcessnailsploit/claude-red

snailsploit/claude-red Incomplete

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.

Open upstream repository

Incomplete The queue state is partial, the last saved scan was truncated or incomplete, or a continuation record is still stored. Indexed content may be missing.

Repository

Canonical name
SnailSploit/Claude-Red
GitHub repository ID
1172273835
Package records
79 (historical registry records, not current availability)

Discovery and queue

First recorded source
search:topic:claude-skills fork:false
Discovered
Queue state
ok
Recorded errors
0
Last settled processing
Next-check eligibility
Eligible from

The first recorded source is what the queue stored first, not the full discovery history. The error count increases when processing ends in the error state and resets after a successful settlement; it is not a count of all attempts. “Last settled processing” is when it finished, not when it started.

Eligibility is calculated as of . It is not a schedule: each collector run handles only a limited number of sources, and being eligible does not promise when a check happens.

Last saved scan

Repository metadata read
Scan status
truncated
Scan saved
Extractor version
2
Continuation record
None

The scan record is separate from the queue state: the queue state shows processing progress, the scan record shows what was last saved. A continuation record only means unfinished state is stored; it has no remaining count.

Source-file evidence coverage

Raw counts of the pinned source files that stored package versions reference in this repository. They show what has been recorded, not how complete the repository is.

Scope and limits

Counts distinct pinned file links (repository, commit, path) across all stored versions, from any package, that name exactly this repository's canonical name. Files of packages owned by this repository are not counted unless some version links to them here. Alias names are not merged and no history is guessed from a current name.

“Known” means a regular-file identity is recorded. It does not mean a whole directory or package is covered. Links that are not valid pinned file URLs are not counted.

79 pinned source files referenced

  • 79 known
  • 0 absent at commit
  • 0 file listing truncated
  • 0 unsupported
  • 0 not recorded
  • 0 read failed

Deduplicated by repository, commit and path; the same path at two commits counts as two file identities. These are not component-group counts.

Failed source-commit reads 0

No source commit has a stored failed read for files that are still unrecorded.

Linked packages 79

Linked by verified repository identity. The count is historical registry records, not current availability.

Showing 1–20 of 79 results

  • offensive-active-directorySkill

    Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escala…

  • offensive-advanced-redteamSkill

    Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and do…

  • offensive-ai-securitySkill

    No description from upstream

  • offensive-anti-forensicsSkill

    Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary e…

  • offensive-api-abuseSkill

    Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses …

  • offensive-api-securitySkill

    Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass,…

  • offensive-basic-exploitationSkill

    No description from upstream

  • offensive-bluetooth-bleSkill

    Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubert…

  • offensive-bluetooth-classicSkill

    Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile ab…

  • offensive-bug-identificationSkill

    No description from upstream

  • offensive-business-logicSkill

    Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback a…

  • offensive-c2-frameworksSkill

    Command and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep …

  • offensive-cicd-pipelineSkill

    Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compro…

  • offensive-cicd-secretsSkill

    Comprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction from build contexts, exploitation of vault and secrets-manager misconfigurations (HashiCorp Vault,…

  • offensive-cloudSkill

    Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, gcp_en…

  • offensive-container-escapeSkill

    Container escape and breakout techniques targeting Docker, containerd, and Podman runtimes. Covers privileged container breakout via host filesystem mount and nsenter, Docker socket abuse through /var/run/docker.sock, Linux capability expl…

  • offensive-crash-analysisSkill

    No description from upstream

  • offensive-crypto-attacksSkill

    Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern …

  • offensive-data-exfiltrationSkill

    Dense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob…

  • offensive-deauth-disassocSkill

    Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth for DoS (with authorization), action-frame attacks bypassing 802.11w (PMF), beacon flooding, mdk4 /…

Saved scan notes 1

  • 4 packages with incomplete coverage

Recorded aliases 0

When last recorded, these names pointed to this repository. This is a recorded resolution, not a live GitHub check; packages and metadata are never merged because of it.

No aliases pointing to this repository are recorded.

Unsupported marketplace entries 0

Entries in this repository's marketplace that this registry does not support yet. They are preserved source data and are never fetched or executed.

No unsupported entries are recorded.