PhanNhatTien090

Claude Redteam — Security skill for Claude Code

Security community

Agentic pentest/red-team framework orchestrated by Claude Code — automated recon, hunt, validate, and report workflow with built-in safety guardrails.

How to install Claude Redteam

This entry records only its repository, not the path inside it, so there is no exact command to give. Open PhanNhatTien090/claude-redteam and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Claude Redteam does

Agentic pentest/red-team framework orchestrated by Claude Code — automated recon, hunt, validate, and report workflow with built-in safety guardrails.

Alternatives in Security

  • Free Code — The free build of Claude Code 8.1k ★
  • T3mp3st — autonomous red teaming platform; multi-agent offensive-security meta-harness 5.7k ★
  • Skills Audit Report — Date: 2026-02-15 Auditor: Automated Skill Quality Audit Scope: Recently added skills in business-growth/, fina 5.3k ★

README

Claude RedTeam

Agentic pentest / bug-bounty framework orchestrated by Claude Code

License: MIT Stars Issues

FeaturesQuickstartStructureScope of useLicense


Recon → hunt → validate → report, with state that survives across sessions, 64 vulnerability-class playbooks, and a guard-hook layer built to stop long offensive-security sessions from getting killed mid-engagement by an LLM's own safety classifier.

[!NOTE] Most "AI agent does pentesting" demos break the moment a real engagement needs more than a handful of tool calls — raw HTTP dumps, exploit payloads, and offensive narration pile up in context until the session gets flagged and killed. This framework exists to run *real, client-scoped, contractually-authorized* engagements without that happening.

Features

🗂️ Persistent state Facts, tokens, findings, and history live in versioned JSON/JSONL (state.py, history.py, api_catalog.py) — not chat context. Resume any engagement in a fresh session.
📚 64 playbooks IDOR, SSRF, GraphQL, OAuth/SAML, cache poisoning, prototype pollution, mobile (iOS/Android + Frida), cloud/IAM, LLM OWASP Top 10, and more — loaded on demand via /skill-load.
🤖 6 subagents recon, recon-ranking, chain-scouting, finding validation, a