SkillAgentSearch skills...

writing-offensive-skills

Use when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection, red-flags tables, flowchart rules)

Install / Use

npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Security

Supported Platforms

Claude Code

Our assessment of writing-offensive-skills

writing-offensive-skills scores 85/100 on our quality scale, 796th of 1,096 Security skills we index.

Its SKILL.md is 3.2 KB long, well organised into 11 sections with 2 code examples: a solid amount of guidance for an agent.

It has 377 GitHub stars, a meaningful sign that others use it.

Substance
26/30
Structure
18/20
Description
15/15
Adoption
11/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 14 days ago, so writing-offensive-skills is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

writing-offensive-skills compared with similar skills

All 4 of these similar skills score higher than writing-offensive-skills; compare them before choosing.

SkillScoreStarsUpdatedFormat
writing-offensive-skills (this skill)by hypnguyen12098537714d agoSKILL.md
algorithmic-artby anthropics100177.9k12d agoSKILL.md
pptxby anthropics100177.9k12d agoSKILL.md
designby nextlevelbuilder100130.2k13d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k13d agoSKILL.md

Frequently asked questions

How do I install writing-offensive-skills?
Run npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills. The install tabs above show the steps for each supported agent.
Which AI agents does writing-offensive-skills work with?
It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
Is writing-offensive-skills safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is writing-offensive-skills still maintained?
The repository was last updated 14 days ago, so writing-offensive-skills is actively maintained.

name: writing-offensive-skills description: Use when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection, red-flags tables, flowchart rules)

Writing Offensive Skills

Overview

Conventions for authoring skills in this repo so the dispatcher can find them and operators can trust them. This adapts superpowers' skill conventions to offensive security.

REQUIRED BACKGROUND: superpowers:writing-skills (the general conventions) and superpowers:test-driven-development (skills are tested like code — baseline failure first).

Description = triggers only

The description: field decides whether the dispatcher loads the skill. Write Use when… triggering conditions and symptoms ONLY — never summarize the skill's workflow (a workflow summary makes Claude follow the description instead of reading the skill).

# BAD  (summarizes workflow): description: Recon skill that enumerates subdomains then scans ports
# GOOD (triggers only):       description: Use when mapping a target's external attack surface — subdomains, hosts, exposed services

Third person, technology-specific only if the skill is. Verb-first / gerund names.

Skill layout (progressive disclosure)

skills/<name>/
  SKILL.md         # thin router, <=180 lines
  references/      # per-technique deep-dives (theory + 2024-2026 + code + detection + OPSEC)
  scripts/         # runnable tooling (no placeholders)

Domain (technique) skill SKILL.md sections, in order: frontmatter → When to Activate → Technique Map (Technique | ATT&CK Txxxx | CWE | reference | script) → Quick Start → OPSEC & Detection table → Deep Dives (links into references/).

Discipline skill (a hard rule, e.g. finding/scope/opsec-discipline): Overview with the Iron Law → the rule → Red Flags (STOP signals) → Rationalizations table (excuse | reality). State "violating the letter is violating the spirit" and close loopholes explicitly.

The four pillars (every technique)

2024-2026 currency (web-search-verified CVEs; no fabricated ids — mark unverified ones), runnable scripts, OPSEC + detection pairing, technique-level ATT&CK + CWE.

Flowcharts

Only for non-obvious decision points / "where you might stop too early". Never for reference material (use tables), code (use blocks), or linear steps (use lists).

Cross-references

Name only, with explicit markers: **REQUIRED:** scope-discipline. Never @-link (force-loads, burns context). Frontmatter references:/scripts: list the files the skill ships.

Test before you trust

A skill that enforces discipline must resist rationalization under pressure. Capture the excuses an agent makes without the skill, put each in the Rationalizations table, and re-check. Safety-relevant scripts get a tests/ suite (run pytest) and an adversarial review before they're trusted.

Red Flags

  • Description summarizes the workflow → rewrite to triggers only
  • A domain skill with no Technique Map / no ATT&CK+CWE / no detection → incomplete
  • A discipline skill with no Red Flags / no Rationalizations table → won't hold under pressure
  • Fabricated CVE/arXiv ids presented as real → mark UNVERIFIED or remove

Related Skills

View on GitHub
GitHub Stars377
CategorySecurity
Updated14d ago
Forks65

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions