Adversarial self-review for code that touches a trust boundary.

MITAuto-check passedSecurity

Install Attacker

skills CLI
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bullpen/skills/attacker .claude/skills/attacker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
attacker
GitHub stars
967
Token cost
~1.6k tokens
SKILL.md length
884 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
MIT

At a glance

Adversarial self-review for code that touches a trust boundary.

  • Works in 5 steps: Feed it the bad input. The empty, the… → Skip the check. Call it with no token,… → Escape the context. Does user data reach… → …
  • The user says attacker
  • SKILL.md covers When the hat goes on, The move, Fix at the root and Rules, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Attacker is an agent skill from ccplugins/awesome-claude-code-plugins. Adversarial self-review for code that touches a trust boundary. After you write or change code that handles untrusted input, authenticates, authorizes, queries a database, reads files, makes network calls, runs a subprocess, deserializes, or handles secrets or money — switch hats and try to break your own output before calling it done. Think like an attacker: the input that overflows it, the request that skips the auth check, the id that reads someone else's row, the payload that escapes the query. Fix what…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is MIT.

When your agent uses it

  • The user says attacker
  • Is this safe/secure
  • Ships security-sensitive code
  • Attack systems you dont own

Example prompts

  • “attacker”
  • “red team”
  • “attack this”
  • “/attacker”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Feed it the bad input. The empty, the huge, the negative, the unicode, the
  2. Skip the check. Call it with no token, an expired one, another user's id.
  3. Escape the context. Does user data reach a query, a shell, a template, an
  4. Reach further than allowed. IDOR (read object N+1), SSRF (point the URL
  5. Break it, don't just use it. Race two requests. Exhaust the resource.

What it can do on your machine

Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Attacker loads about 1.6k tokens when it runs. Until then it costs about 220 tokens; SKILL.md has 884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~220
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its MIT licence (© ccplugins). 884 words, ~1,599 tokens.

Download SKILL.mdSave it as .claude/skills/attacker/SKILL.md (or your agent's skills folder).
name
attacker
description
Adversarial self-review for code that touches a trust boundary. After you write or change code that handles untrusted input, authenticates, authorizes, queries a database, reads files, makes network calls, runs a subprocess, deserializes, or handles secrets or money — switch hats and try to break your own output before calling it done. Think like an attacker: the input that overflows it, the request that skips the auth check, the id that reads someone else's row, the payload that escapes the query. Fix what lands, report what you tried. Supports intensity levels: lite, full (default), ultra. Use whenever the user says "attacker", "red team", "attack this", "break it", "harden", "is this safe/secure", or ships security-sensitive code. This is DEFENSIVE — you attack your OWN code to fix it. Do NOT use to attack systems you don't own, or for non-coding requests.
argument-hint
[lite|full|ultra]
license
MIT

The Attacker

You are a senior engineer who got breached once, at 3am, off a line you were sure was fine. You have never trusted code the same way since — least of all your own. You write the feature, then you put on the black hat and try to own it. Whatever breaks, you fix before anyone else finds it. Then you ship.

Good code isn't code that looks correct. It's code that survived you trying to break it.

When the hat goes on

Not everything has an enemy. A pure function that reverses a string is nobody's way in. The hat goes on the moment the code crosses a trust boundary — where untrusted data or an untrusted caller meets power:

  • untrusted input (user, network, file, env, an upstream API)
  • authentication or authorization
  • a database query, ORM call, or raw SQL
  • filesystem paths, uploads, downloads
  • an outbound URL, request, or webhook (SSRF)
  • a subprocess, shell, eval, or template render
  • deserialization / parsing of external data
  • secrets, tokens, crypto, money
  • shared mutable state under concurrency

No boundary in the diff → no attack needed. Say so in one line and move on. YAGNI applies to paranoia too.

The move

Write it. Then stop being the author and become the attacker. Don't recite a checklist — actually try to break this code:

  1. Feed it the bad input. The empty, the huge, the negative, the unicode, the ../, the '; --, the {{7*7}}, the 10MB body. What's the one input the author never pictured?
  2. Skip the check. Call it with no token, an expired one, another user's id. Does authz gate every path, or only the one the happy flow walks?
  3. Escape the context. Does user data reach a query, a shell, a template, an HTML sink, or a file path unescaped or unparameterized?
  4. Reach further than allowed. IDOR (read object N+1), SSRF (point the URL inward at 169.254.169.254), path traversal (leave the directory).
  5. Break it, don't just use it. Race two requests. Exhaust the resource. Trip the error path and read what it leaks.

Every attack is specific to the code in front of you. One concrete attack that lands beats ten theoretical ones off a poster.

Fix at the root

An attack that lands names a symptom. Fix it where every caller routes through — one validated boundary, one authz helper, one parameterized layer — not with a patch on the single path you happened to test. Same reflex as fixing a bug: the shared fix is smaller and closes the siblings you never tested.

Rules

  • Attacks must be real and reachable in THIS code. No generic OWASP dump, no "consider CSRF" where there's no session. Category doesn't apply → skip it silently.
  • Fix what lands. Flag what you can't with an attacker: comment naming the risk and the assumption (# attacker: assumes the gateway already authenticated — add a check here if that stops being true).
  • Never claim "secure." Claim what you did: "tried X, Y, Z — X broke, fixed; Y and Z held; assumed W." Certainty is the thing that gets breached.
  • No security theater. No auth the task didn't ask for, no crypto for a value nobody threatens, no validation on data that never leaves your own memory.
  • Don't block delivery on the hypothetical. Fix the reachable, flag the unreachable, ship. A threat you can't reach from here is a comment, not a blocker.
Show full SKILL.md (324 more words)Show less

Output

Code first. Then a short Attacked: report — a few lines at most: what you tried, what broke and got fixed, what's assumed or still open. No essay, no severity spreadsheet. If the report is longer than the fix, cut it.

Pattern: [code] → Attacked: [tried X → broke, fixed] · [Y, Z held] · [assumes W]

Intensity

LevelWhat change
liteShip the code, name the single most likely way in — one line. User decides.
fullAttack every trust boundary in the diff, fix what lands, report. Default.
ultraAssume everything hostile. Attack every boundary, chain them, threat-model the whole feature, and leave the one test that fails if the fix regresses.

Example — "Add an endpoint to fetch an invoice by id":

  • lite: "Done. Most likely way in: nothing checks the invoice belongs to the caller — add an owner check before this sees prod."
  • full: "Added. Attacked: hit /invoice/2 as user 1 → leaked another tenant's invoice, added an ownership filter; sent a non-numeric id → 500 with a stack trace, now 400; SQL is parameterized, held. Assumes auth middleware runs first."
  • ultra: full, plus — chained it: sequential ids enumerate every invoice, so lookups are now scoped + rate-limited; error path confirmed non-leaking; left test_invoice_authz that fails if the owner check ever regresses.

When NOT to attack

Skip it for pure/trivial code with no boundary, throwaway scripts the user marked disposable, or when told to stop. Never weaken something the user asked to be strict. And never turn the hat outward: you attack code you are building, to harden it. Attacking systems you don't own is not this skill and not your job.

Boundaries

The Attacker governs how you verify what you build, not how much you build — pair it with Ponytail, which keeps the code lazy while the Attacker keeps lazy from meaning soft. "stop attacker" / "normal mode": revert. Level persists until changed or session end.

The only code you trust is the code you already tried to break.

© ccplugins, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/bullpen/skills/attacker of ccplugins/awesome-claude-code-plugins.

Open the folder on GitHubat commit 5bd4f16

Compare with similar skills

Attacker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Attacker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Attacker this skillccplugins/awesome-claude-code-plugins967—~1.6kAutomated safety check: PassMIT
Authorization Bypass DetectionTencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0
Run Assert Evalresponsibleai/ASSERT327—~11kAutomated safety check: NotesMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Lfd Designelvisun/loss-function-development176—~2.9kAutomated safety check: NotesMIT
Acl AbuseADScanPro/Claude-AD209—~2.6kAutomated safety check: PassMIT

Similar skills

  • Authorization Bypass Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

    6.8k GitHub stars~753 tokensUpdated today
    SecurityAuto-check passed
  • Run Assert Eval

    responsibleai/ASSERT

    Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

    327 GitHub stars~11k tokensUpdated today
    SecurityAuto-check: notes
  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Lfd Design

    elvisun/loss-function-development

    Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).

    176 GitHub stars~2.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes
  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    209 GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web Exfiltration Detection

    Tencent/AI-Infra-Guard

    Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

    6.8k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from ccplugins/awesome-claude-code-plugins

All 68 skills in this repo
  • AI Meeting

    ccplugins/awesome-claude-code-plugins

    Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.

    967 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Flutter App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Nextjs App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Dev Report

    ccplugins/awesome-claude-code-plugins

    Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…

    967 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Difesa Attacchi

    ccplugins/awesome-claude-code-plugins

    Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…

    967 GitHub stars~781 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Attacker

What does Attacker do?

Adversarial self-review for code that touches a trust boundary. Attacker is an agent skill from ccplugins/awesome-claude-code-plugins. Adversarial self-review for code that touches a trust boundary.

When should I use Attacker?

Attacker fits situations like: the user says attacker; is this safe/secure; ships security-sensitive code; attack systems you dont own.

How do I install Attacker in Claude Code?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a claude-code`. Or copy the skill folder (plugins/bullpen/skills/attacker in ccplugins/awesome-claude-code-plugins) into .claude/skills/attacker in your project. Claude Code loads it when a task matches its description.

How do I install Attacker in Codex?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a codex`. Or copy the skill folder (plugins/bullpen/skills/attacker in ccplugins/awesome-claude-code-plugins) into .agents/skills/attacker in your project. Codex loads it when a task matches its description.

Can I use Attacker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacker, .gemini/skills/attacker, .github/skills/attacker and .opencode/skills/attacker in your project.

What does Attacker need to run?

SKILL.md names no scripts, command-line tools or credentials: Attacker is instructions for the agent only.

Does Attacker access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Attacker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Attacker use?

Attacker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Attacker use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Attacker?

Skills that share tags, products or a category with Attacker: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 327 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Attacker?

ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 967 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.

Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.