> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← Back to Articles

Claude-Red: Offensive Security Prompt Engineering as a Knowledge Injection Attack

[ View on GitHub ]

Claude-Red: Offensive Security Prompt Engineering as a Knowledge Injection Attack

Hook

What if the best way to remember how to exploit WPA3-SAE downgrade attacks or bypass Windows CFG wasn't documentation—but a conversation that makes an AI think it's a penetration tester?

Context

Offensive security has always been a knowledge density problem. During live engagements, practitioners juggle mental models across wildly different attack surfaces: one moment you're chaining ADCS certificate template misconfigurations (ESC1 through ESC15), the next you're fuzzing Z-Wave S2 key exchange for IoT lateral movement. Traditional resources fragment across formats—PTES frameworks gather dust as compliance PDFs, HackTricks offers unstructured GitHub markdown, MITRE ATT&CK maps techniques but never explains how to execute them. Meanwhile, integrated frameworks like Metasploit excel at exploitation but fail at methodology transfer; they automate attacks you already understand, not the recall problem of "what's the attack sequence for Zigbee Touchlink commissioning abuse again?"

Claude-Red exploits a different surface: Claude's system prompt mechanism. Rather than building another framework or cheatsheet, SnailSploit reverse-engineered how to inject expert-level offensive methodology directly into an LLM's context window. Each of the 78 SKILL.md files is a structured prompt that primes Claude with domain-specific attack taxonomy, tool chains, and escalation paths. When you load offensive-kerberos.md, you're not querying documentation—you're performing a privilege escalation on Claude itself, temporarily granting it the persona of a Kerberoasting specialist. The conversational interface becomes a dial-an-expert system where "I have domain user credentials" triggers the model to summon Active Directory attack chains without you remembering whether Rubeus or Impacket's GetUserSPNs.py comes first.

Technical Insight

Skill Structure

Match

No Match

Yes

No

Git Sparse Checkout

web/, infrastructure/, exploit-dev/

Contains

Contains

Contains

Contains

Triggers

User Query

Skill Trigger Detection

Load Relevant SKILL.md

Manual Selection

Parse Skill Metadata

Cross-References Found?

Load Referenced Skills

Compose Context Window

Claude Response Generation

Methodology + Payloads

Skills Repository

Category Filter

Threat Model

Tool Chain

Attack Taxonomy

Escalation Paths

System architecture — auto-generated

The architecture is deceptively simple: zero code execution, pure prompt engineering. Each skill is self-contained markdown following a consistent schema—threat model, prerequisites, tooling, methodology steps, escalation paths, and cross-references to related skills. The /web/offensive-sqli.md skill likely structures something like:

# Offensive SQL Injection

## Context
You are an expert penetration tester specializing in SQL injection. 
Provide methodology for identifying, exploiting, and escalating SQLi vulns.

## Attack Taxonomy
1. Detection: Error-based, Boolean-based, Time-based, UNION-based
2. Exploitation: Data exfil, auth bypass, stacked queries
3. Escalation: File read/write, OS command execution, privilege escalation

## Tooling Chain
- sqlmap (automated): `sqlmap -u <url> --batch --risk=3 --level=5`
- Manual: Burp Suite, python requests, curl
- Database-specific: MySQL UDF exec, MSSQL xp_cmdshell, PostgreSQL COPY

## Methodology
[Detailed step-by-step with payload examples and WAF bypass techniques]

## Escalation Paths
- SQLi → File Write → Webshell (see: offensive-file-upload)
- SQLi → NTLM Relay (MSSQL xp_dirtree, see: offensive-ntlm-relay)

The compositional magic happens through cross-references. Loading offensive-active-directory doesn't just give you AD methodology—it references offensive-kerberos, offensive-acl-abuse, and offensive-gpo-abuse. Claude's 200k token context window becomes a dependency resolver, letting you chain "I compromised a domain user" → Kerberoasting → RBCD attack → DCSync in a single conversation thread. No imports, no module systems—just markdown files that assume Claude can hold the entire attack graph in memory.

Installation exploits git sparse-checkout for surgical category loading:

# Clone only wireless attack skills
git clone --filter=blob:none --sparse https://github.com/SnailSploit/Claude-Red
cd Claude-Red
git sparse-checkout set wireless/

# Concatenate skills for Claude API system prompt
cat wireless/offensive-wifi-*.md > wifi-skills.txt

For Claude interfaces without native Skills API support (which, as of early 2025, is most of them), you manually concatenate relevant skills and inject them as system prompts. The Python install script is just a wrapper around this pattern—it doesn't manage state, orchestrate execution, or validate outputs. You're literally copying markdown into Claude's context and hoping its instruction-following holds.

The /wireless/ category reveals the depth: 14 skills covering 802.11 (WPA3-SAE Dragonblood, PMKID attacks, FragAttacks), Bluetooth Low Energy (pairing model abuse, GATT fuzzing), Zigbee (Touchlink commissioning, key transport), Z-Wave (S0/S2 downgrade), and LoRaWAN (OTAA replay, ABP session hijacking). Each skill encodes not just theory but operational tradecraft—expected tool output, common failure modes, and when to pivot techniques. The offensive-zigbee-touchlink.md skill likely walks through using Killerbee to force factory resets on smart home devices, a niche attack that's documented in scattered research papers but never consolidated into penetration testing methodology.

The exploit development skills (offensive-exploit-development, offensive-windows-mitigations) target a different audience: vulnerability researchers needing to recall ROP gadget chaining for modern Windows with CFG/ACG/CET. These aren't "run this Metasploit module" guides—they're structured prompts that make Claude walk you through ASLR bypass strategies or TOCTOU race condition analysis. The prompt engineering encodes procedural knowledge ("First check for DEP, then identify memory disclosure primitives, then...") rather than declarative facts.

Critically, there's no validation layer. If Claude hallucinates a sqlmap flag or misremembers Impacket syntax, you discover it when the command fails in your terminal. The system trusts Claude's pre-training and the skill's prompt engineering to produce accurate methodology, which works until it doesn't—particularly for newer techniques where Claude's training data is sparse.

Gotcha

The elephant in the room: you're piping engagement data through Anthropic's API. Every target hostname, compromised credential, and reconnaissance output you discuss with Claude gets logged somewhere in Anthropic's infrastructure. For red team assessments with strict data residency requirements (financial sector, government, healthcare), this is a non-starter unless you're running Claude in a dedicated VPC with contractual data handling agreements. The project offers zero guidance on operational security, sanitization, or compliance implications. Practitioners are left navigating "Is discussing client.corp's domain admin hash with Claude a breach of our SOW?"

Skill staleness is structural. Offensive security evolves faster than markdown—new ADCS escalation paths (ESC16 anyone?), novel EDR hooking bypasses, and emerging cloud vulnerabilities invalidate methodology within months. Claude-Red has no CI/CD pipeline for integrating new research, no versioning system for tracking when techniques become outdated, and no community contribution guidelines visible in the repo. The 4,785 stars suggest interest, but GitHub shows no pull request culture for keeping skills current. You're trusting SnailSploit's manual curation cadence, which for a volunteer project means skills bit-rot until someone notices.

The beginner cliff is steep. Skills assume you already know how to operate tools, they just optimize what to do next. If you don't know what Impacket is, why Rubeus matters, or how to interpret bloodhound output, the offensive-active-directory skill drowns you in jargon. This isn't a learning resource—it's a structured recall aid for practitioners who've already internalized the basics but need checklists for domains they touch quarterly. The /exploit-dev/ skills expect fluency in assembly, debugger operation, and Windows internals that takes years to develop.

Verdict

Use if: You're an intermediate-to-advanced penetration tester or red teamer who treats Claude as a research assistant during authorized engagements, particularly if you work across diverse attack surfaces (web + AD + wireless + IoT) and need rapid methodology recall without context-switching to Google. The wireless and Windows internals coverage alone justifies it for practitioners tired of duct-taping blog posts into coherent attack chains. Also use if you're experimenting with LLM-augmented offensive workflows and want a ready-made prompt library to understand what structured security knowledge injection looks like at scale. Skip if: Your engagements have data residency requirements that prohibit third-party API usage (you can't risk client intel in Anthropic's logs), you need reproducible automation rather than conversational guidance (use Metasploit/Cobalt Strike/Mythic instead), you're a beginner expecting learning resources (these skills assume prerequisite knowledge you don't have), or you require frequently-updated methodology (the static repo will lag behind evolving tradecraft). Also skip if you're philosophically opposed to outsourcing security decision-making to LLMs that might hallucinate critical steps during live exploitation.