Agent skill

Red

by glebis in glebis/claude-skills

Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use).

MITAuto-check passedLegal & Compliance

Install Red

skills CLI
$ npx skills add glebis/claude-skills --skill red -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install glebis/claude-skills red --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/glebis/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/confide/skills/red .claude/skills/red && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
red
GitHub stars
389
Token cost
~881 tokens
SKILL.md length
308 words
Files
2 (incl. scripts)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use).

  • Works in 3 steps: Singling-out (deterministic, offline —… → Linkability (multi-file): given a… → Inference (LLM, optional, opt-in):…
  • The user asks to check residual re-id risk
  • SKILL.md covers GUARDRAILS — read before running, What it checks, Risk tier rule and How to run, plus 1 more section
  • Runs Python scripts from its folder; calls python3

What it does

Red is an agent skill from glebis/claude-skills. Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). Use when the user asks to "check residual re-id risk", "red-team my redaction", "what can an attacker still infer", "is this safe to share", or assess "re-identification risk" after anonymizing. Re-runs the CONFIDE detectors on the redacted output to surface surviving identifiers (singling-out), checks multiple files for linkability, and optionally probes a local model for still-inferable attribute CATEGORIES…

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/red.py`).

It sits in Legal & Compliance, covering Privacy and GDPR and Red teaming and adversary simulation. The repository describes itself as: Collection of Claude Code skills for enhanced AI workflows. The licence is MIT.

When your agent uses it

  • The user asks to check residual re-id risk
  • Red-team my redaction
  • What can an attacker still infer
  • Is this safe to share

Example prompts

  • “check residual re-id risk”
  • “red-team my redaction”
  • “what can an attacker still infer”
  • “/red”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Singling-out (deterministic, offline — the load-bearing signal): re-run
  2. Linkability (multi-file): given a folder, compare every file pair for shared
  3. Inference (LLM, optional, opt-in): prompt the local attacker model

What it can do on your machine

Read from SKILL.md and the folder at commit 7524dff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Red loads about 881 tokens when it runs. Until then it costs about 167 tokens; SKILL.md has 308 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~167
When it runs · the whole SKILL.md, loaded when a task matches
~881

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from glebis/claude-skills at commit 7524dff, republished under its MIT licence (© glebis). 308 words, ~881 tokens.

Download SKILL.mdSave it as .claude/skills/red/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
red
description
Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). Use when the user asks to "check residual re-id risk", "red-team my redaction", "what can an attacker still infer", "is this safe to share", or assess "re-identification risk" after anonymizing. Re-runs the CONFIDE detectors on the redacted output to surface surviving identifiers (singling-out), checks multiple files for linkability, and optionally probes a local model for still-inferable attribute CATEGORIES (inference) — mapped to GDPR Art-29. Reports risk categories/counts only, never a re-identification recipe. Pairs with confide:anon (run AFTER redacting).

confide:red — residual re-identification risk check

A defensive audit of YOUR OWN already-redacted output. It does not score against ground truth and is not a benchmark. It surfaces, qualitatively, what an attacker could still do — mapped to GDPR Art-29: singling-out, linkability, inference.

GUARDRAILS — read before running

  • Run only on the user's own redacted output. If asked to de-anonymize or re-identify third-party / non-consented data, refuse.
  • Report risk categories and counts only — never produce a step-by-step re-identification recipe or guess the hidden values.
  • Local attacker by default. Enable the cloud/LLM inference probe (--inference) only on synthetic or explicitly consented data.
  • Absence of a finding ≠ safety. A weak local detector/attacker is a FLOOR, not a ceiling. Always tell the user human review is still required.
  • This pairs with confide:anon — run red after redacting, on the redacted file.

What it checks

  1. Singling-out (deterministic, offline — the load-bearing signal): re-run detect_regex (+ detect_natasha if available) on the redacted text. Anything they still find is a surviving identifier the redaction missed. Counts by type.
  2. Linkability (multi-file): given a folder, compare every file pair for shared surviving quasi-identifiers and flag potentially linkable pairs (count + types only).
  3. Inference (LLM, optional, opt-in): prompt the local attacker model (cfg.red_attacker_model) for the attribute categories it could still infer (profession, location type, age band, …). Degrades gracefully if no model. WARN the user it under-reports (floor, not ceiling).

Risk tier rule

  • HIGH — any DIRECT identifier survives (EMAIL, PHONE, URL, ID, PERSON).
  • MEDIUM — only QUASI identifiers survive (LOCATION, ORG, DATE, AGE, PROFESSION, MEDICATION), or linkable pairs exist across files.
  • LOW — no surviving identifiers found (still NOT a guarantee).

How to run

bash
# single redacted file (offline, deterministic)
python3 skills/red/scripts/red.py path/to/file.green.md

# a folder of redacted files (adds linkability)
python3 skills/red/scripts/red.py path/to/redacted_dir/

# add the local inference probe — synthetic/consented data ONLY
python3 skills/red/scripts/red.py path/to/file.green.md --inference

# machine-readable
python3 skills/red/scripts/red.py path/to/file.green.md --json

Output

A residual-risk report: per-file surviving-identifier counts by type, an overall risk tier, the inference categories claimed (if probed), the linkable-pair count, and the caveat that absence of a finding ≠ safety; human review still required. No PII values, no re-identification steps.

© glebis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in confide/skills/red of glebis/claude-skills.

  • SKILL.md
  • scripts/red.py

Open the folder on GitHubat commit 7524dff

Compare with similar skills

Red next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Red compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Red this skillglebis/claude-skills389—~881Automated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT
Incident Reporting Navigatordavila7/claude-code-templates32k1 repos~4.7kAutomated safety check: PassCC-BY-4.0
Implementing Delinea Secret Server For Pammukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.0
Building Identity Governance Lifecycle Processmukul975/Anthropic-Cybersecurity-Skills34k—~7.3kAutomated safety check: PassApache-2.0
Automated Ropa Generationmukul975/Privacy-Data-Protection-Skills295—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    850 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Incident Reporting Navigator

    davila7/claude-code-templates

    A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…

    32k GitHub starsUsed in 1 repo~4.7k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Delinea Secret Server For Pam

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording, and Active…

    34k GitHub stars~4.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Building Identity Governance Lifecycle Process

    mukul975/Anthropic-Cybersecurity-Skills

    Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests…

    34k GitHub stars~7.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Automated Ropa Generation

    mukul975/Privacy-Data-Protection-Skills

    Generates Records of Processing Activities automatically from IT system inventories including Active Directory, cloud service catalogs, API gateway logs, and database schemas.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    DatabasesAuto-check passed
  • Pseudonymization Risk

    mukul975/Privacy-Data-Protection-Skills

    Assessment of pseudonymization techniques and re-identification risk.

    295 GitHub stars~3.2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed

More from glebis/claude-skills

All 91 skills in this repo
  • Runs a human-first workflow for labeling PII spans in a transcript, then scores inter-annotator agreement and drafts an adjudicated gold set.

    389 GitHub stars~1.3k tokensUpdated 12 days ago
    Auto-check passed
  • Automates a dedicated, logged-in Chrome instance per profile without ever closing the user's own open tabs or browser windows.

    389 GitHub stars~973 tokensUpdated 12 days ago
    Auto-check passed
  • Deep Research

    glebis/claude-skills

    This skill should be used when conducting comprehensive research on any topic using the OpenAI Deep Research API.

    389 GitHub stars~2.6k tokensUpdated 12 days ago
    Auto-check: notes
  • Elimination Research

    glebis/claude-skills

    This skill should be used for elimination-style research where the user wants to choose from a shortlist of products, tools, services, vendors, or other options using explicit criteria, numeric…

    389 GitHub stars~1.6k tokensUpdated 12 days ago
    Auto-check passed
  • Narrated HTML Presentations

    glebis/claude-skills

    Generates a self-contained HTML presentation with article and slides modes, ElevenLabs voiceover narration and optional GPT Image 2 illustrations.

    389 GitHub stars~2.3k tokensUpdated 12 days ago
    Auto-check: notes
  • Writes fictional but realistic coaching or therapy session transcripts for evals, demos and few-shot examples, in several modalities and export formats.

    389 GitHub stars~2.9k tokensUpdated 12 days ago
    Auto-check passed

Questions about Red

What does Red do?

Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). Red is an agent skill from glebis/claude-skills. Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use).

When should I use Red?

Red fits situations like: the user asks to check residual re-id risk; red-team my redaction; what can an attacker still infer; is this safe to share.

How do I install Red in Claude Code?

Run `npx skills add glebis/claude-skills --skill red -a claude-code`. Or copy the skill folder (confide/skills/red in glebis/claude-skills) into .claude/skills/red in your project. Claude Code loads it when a task matches its description.

How do I install Red in Codex?

Run `npx skills add glebis/claude-skills --skill red -a codex`. Or copy the skill folder (confide/skills/red in glebis/claude-skills) into .agents/skills/red in your project. Codex loads it when a task matches its description.

Can I use Red in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add glebis/claude-skills --skill red -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/red, .gemini/skills/red, .github/skills/red and .opencode/skills/red in your project.

What does Red need to run?

Going by SKILL.md and its folder, Red needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Red access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Red safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Red use?

Red is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Red use?

About 881 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Red?

Skills that share tags, products or a category with Red: Security Compliance (sangrokjung/claude-forge, 850 stars), Incident Reporting Navigator (davila7/claude-code-templates, 32k stars), Implementing Delinea Secret Server For Pam (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Identity Governance Lifecycle Process (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Red?

glebis (a GitHub user) maintains it in glebis/claude-skills, which has 389 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on September 26, 2026.

Source: glebis/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.