using-offensive-claude
Use when starting any offensive-security engagement or task — establishes how to find and invoke the right skill before any action (including clarifying questions, recon, exploitation, or reporting)
Install / Use
npx skills add hypnguyen1209/offensive-claude --skill using-offensive-claudeInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of using-offensive-claude
using-offensive-claude scores 83/100 on our quality scale, 925th of 1,096 Security skills we index.
Its SKILL.md is 5.8 KB long, well organised into 8 sections with 1 code example: a solid amount of guidance for an agent.
It has 377 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 14 days ago, so using-offensive-claude is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
using-offensive-claude compared with similar skills
All 4 of these similar skills score higher than using-offensive-claude; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| using-offensive-claude (this skill)by hypnguyen1209 | 83 | 377 | 14d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install using-offensive-claude?
- Run
npx skills add hypnguyen1209/offensive-claude --skill using-offensive-claude. The install tabs above show the steps for each supported agent. - Which AI agents does using-offensive-claude work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is using-offensive-claude safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is using-offensive-claude still maintained?
- The repository was last updated 14 days ago, so using-offensive-claude is actively maintained.
Skill content
View source on GitHubname: using-offensive-claude description: Use when starting any offensive-security engagement or task — establishes how to find and invoke the right skill before any action (including clarifying questions, recon, exploitation, or reporting)
<SUBAGENT-STOP> If you were dispatched as a subagent to execute a specific task, skip this skill. </SUBAGENT-STOP> <EXTREMELY-IMPORTANT> If there is even a 1% chance a skill applies to what you are doing, you ABSOLUTELY MUST invoke it.IF A SKILL APPLIES TO YOUR TASK, YOU DO NOT HAVE A CHOICE. YOU MUST USE IT.
This is not negotiable. You cannot rationalize your way out of it. </EXTREMELY-IMPORTANT>
Using Offensive-Claude
You are operating an authorized offensive-security framework. Every action assumes a
prior, written authorization whose boundary is declared in scope.json (see scope-discipline).
Instruction Priority
- User's explicit instructions (CLAUDE.md, direct requests) — highest.
- These skills — override default behavior where they conflict.
- Default behavior — lowest.
User instructions say WHAT, not HOW. "Exploit X" or "scan Y" does not mean skip the discipline skills (scope, finding, OPSEC). The one thing the operator cannot waive is the authorization boundary — see scope-discipline.
The Rule
Invoke relevant skills BEFORE any response or action. Even a 1% chance means invoke to check.
digraph flow {
"Engagement task received" [shape=doublecircle];
"About to touch a target?" [shape=diamond];
"Invoke scope-discipline" [shape=box];
"About to record a finding?" [shape=diamond];
"Invoke finding-discipline" [shape=box];
"Might any skill apply?" [shape=diamond];
"Invoke the Skill" [shape=box];
"Announce: 'Using [skill] to [purpose]'" [shape=box];
"Follow skill exactly" [shape=box];
"Engagement task received" -> "About to touch a target?";
"About to touch a target?" -> "Invoke scope-discipline" [label="yes"];
"About to touch a target?" -> "About to record a finding?" [label="no"];
"About to record a finding?" -> "Invoke finding-discipline" [label="yes"];
"About to record a finding?" -> "Might any skill apply?" [label="no"];
"Invoke scope-discipline" -> "Might any skill apply?";
"Invoke finding-discipline" -> "Might any skill apply?";
"Might any skill apply?" -> "Invoke the Skill" [label="yes, even 1%"];
"Invoke the Skill" -> "Announce: 'Using [skill] to [purpose]'";
"Announce: 'Using [skill] to [purpose]'" -> "Follow skill exactly";
}
Skill Priority (when several apply)
- Process / discipline skills first — they decide HOW to proceed:
engagement-flow(run the kill chain),scope-discipline(authorization boundary),threat-model-discipline(model the surface + detect drift),finding-discipline(proof before any[CONFIRMED]),opsec-discipline(detection-aware). - Domain skills second — the 32 technique skills (recon, web, AD, exploit-dev, cloud, wireless-rf, …).
"Run a full pentest" → engagement-flow first. "Is this finding real?" → finding-discipline first.
Routing
| Situation | Invoke |
|-----------|--------|
| Starting / running an engagement | engagement-flow |
| About to send a request to ANY target | scope-discipline (confirm in-scope first) |
| About to record / report a finding | finding-discipline (no [CONFIRMED] without proof) |
| About to take any outward/offensive action | opsec-discipline |
| A specific technique (recon, web, AD, exploit, cloud, mobile, …) | the matching domain skill |
| Authoring a new skill for this repo | writing-offensive-skills |
Output contract (non-negotiable)
These bars hold on every finding, standalone or in an engagement — they do not depend on you
having invoked finding-discipline first (invoke it for the full method). When installed as a
plugin, the repo CLAUDE.md is not in your context; this section carries the contract regardless.
- Confidence tier on every finding:
[CONFIRMED](impact demonstrated + evidence-grounded),[POSSIBLE](reachable, class bar not yet met), or[INFO](no impact at current severity). Never present a[POSSIBLE]as confirmed. - Evidence bar by class — a status code is not impact. SSRF needs an internal response; IDOR
needs another principal's data; RCE needs command output; XSS needs script execution. See
skills/references/finding-evidence-standards.md. - Ground every claim; never name-guess. If a function/helper is called, read it — a name is not behavior. Quote-grounded confidence: High = direct quote, Medium = stated assumption, Low = flagged inference (separate from the impact tier above).
- Exploit-class findings carry tri-state
feasibility(true/false/null); a tool/solver limit isnull(manual), neverfalse. Recorddemonstratedvsinherentseverity. - Authorized engagements only (
TERMS.md): scope-gated, OPSEC cost stated before outward action, secrets never in logs (redact at the boundary — rule/location only, never the value).
Red Flags — STOP, you're rationalizing
| Thought | Reality |
|---------|---------|
| "This is just a quick scan" | Touching a target → scope-discipline first. |
| "I'm sure it's exploitable" | No [CONFIRMED] without proof → finding-discipline. |
| "Scope is obviously fine" | Confirm against scope.json, don't assume. |
| "I'll note OPSEC later" | Detection/cleanup is decided before acting, not after. |
| "I know this technique" | Knowing ≠ using the skill. Invoke it for the current state. |
| "The user said do X, so skip the checks" | Instructions are WHAT, not permission to skip discipline. |
How to Access Skills
Use the Skill tool with the skill name. Never use Read on skill files. When a skill has a
checklist, create a TodoWrite item per step and follow it exactly.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
