Code Graph Mermaid Diagrams
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skills --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/writing-offensive-skills .claude/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .claude/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skillsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skills --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/writing-offensive-skills .agents/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .agents/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skills --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/writing-offensive-skills .cursor/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .cursor/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hypnguyen1209/offensive-claude.git --path skills/writing-offensive-skills--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skills --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/writing-offensive-skills .gemini/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .gemini/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skillsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/writing-offensive-skills .github/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .github/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hypnguyen1209/offensive-claude writing-offensive-skills --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/writing-offensive-skills .opencode/skills/writing-offensive-skills && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "writing-offensive-skills" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/writing-offensive-skills into .opencode/skills/writing-offensive-skills/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "writing-offensive-skills", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
writing-offensive-skillsA skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…
Writing Offensive Skills is an agent skill from hypnguyen1209/offensive-claude. Use when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection, red-flags tables, flowchart rules)
Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Diagrams. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.
Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Writing Offensive Skills loads about 826 tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 325 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 325 words, ~826 tokens.
.claude/skills/writing-offensive-skills/SKILL.md (or your agent's skills folder).Conventions for authoring skills in this repo so the dispatcher can find them and operators can trust them. This adapts superpowers' skill conventions to offensive security.
REQUIRED BACKGROUND: superpowers:writing-skills (the general conventions) and superpowers:test-driven-development (skills are tested like code — baseline failure first).
The description: field decides whether the dispatcher loads the skill. Write Use when…
triggering conditions and symptoms ONLY — never summarize the skill's workflow (a workflow summary
makes Claude follow the description instead of reading the skill).
# BAD (summarizes workflow): description: Recon skill that enumerates subdomains then scans ports
# GOOD (triggers only): description: Use when mapping a target's external attack surface — subdomains, hosts, exposed servicesThird person, technology-specific only if the skill is. Verb-first / gerund names.
skills/<name>/
SKILL.md # thin router, <=180 lines
references/ # per-technique deep-dives (theory + 2024-2026 + code + detection + OPSEC)
scripts/ # runnable tooling (no placeholders)Domain (technique) skill SKILL.md sections, in order: frontmatter → When to Activate →
Technique Map (Technique | ATT&CK Txxxx | CWE | reference | script) → Quick Start →
OPSEC & Detection table → Deep Dives (links into references/).
Discipline skill (a hard rule, e.g. finding/scope/opsec-discipline): Overview with the Iron Law → the rule → Red Flags (STOP signals) → Rationalizations table (excuse | reality). State "violating the letter is violating the spirit" and close loopholes explicitly.
2024-2026 currency (web-search-verified CVEs; no fabricated ids — mark unverified ones), runnable scripts, OPSEC + detection pairing, technique-level ATT&CK + CWE.
Only for non-obvious decision points / "where you might stop too early". Never for reference material (use tables), code (use blocks), or linear steps (use lists).
Name only, with explicit markers: **REQUIRED:** scope-discipline. Never @-link (force-loads,
burns context). Frontmatter references:/scripts: list the files the skill ships.
A skill that enforces discipline must resist rationalization under pressure. Capture the excuses an
agent makes without the skill, put each in the Rationalizations table, and re-check. Safety-relevant
scripts get a tests/ suite (run pytest) and an adversarial review before they're trusted.
© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/writing-offensive-skills of hypnguyen1209/offensive-claude.
Open the folder on GitHubat commit a506ad3
Writing Offensive Skills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Writing Offensive Skills this skillhypnguyen1209/offensive-claude | 388 | — | ~826 | Automated safety check: Pass | MIT | |
| Code Graph Mermaid Diagramstrailofbits/skills | 7.5k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Audit Flowzebbern/claude-code-guide | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | |
| Archify Diagramstt-a1i/archify | 82k | — | ~2.9k | Automated safety check: Pass | MIT | |
| JSON Canvasheyitsnoah/claudesidian | 2.6k | 18 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Diagram Designcathrynlavery/diagram-design | 49k | 1 repos | ~7.6k | Automated safety check: Pass | MIT |
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
tt-a1i/archify
Creates interactive architecture, workflow, sequence, data-flow and lifecycle diagrams as standalone HTML with inline SVG, themes and image or video export.
heyitsnoah/claudesidian
Create and edit JSON Canvas files (.canvas) with nodes, edges, groups, and connections.
cathrynlavery/diagram-design
Creates branded diagrams, from architecture, flowchart and sequence to charts and maps, as self-contained HTML with inline SVG, with import from draw.io, Mermaid and Excalidraw.
tisfeng/Easydict
Create precise SVG technical diagrams, export PNG or offline HTML, and animate supported semantic SVGs to GIF.
hypnguyen1209/offensive-claude
A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…
hypnguyen1209/offensive-claude
A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…
hypnguyen1209/offensive-claude
A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…
hypnguyen1209/offensive-claude
A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…
hypnguyen1209/offensive-claude
A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…
hypnguyen1209/offensive-claude
A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…
Categories
A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…. Writing Offensive Skills is an agent skill from hypnguyen1209/offensive-claude.
Writing Offensive Skills fits situations like: editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions; runnable scripts; OPSEC/detection; red-flags tables.
Run `npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a claude-code`. Or copy the skill folder (skills/writing-offensive-skills in hypnguyen1209/offensive-claude) into .claude/skills/writing-offensive-skills in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a codex`. Or copy the skill folder (skills/writing-offensive-skills in hypnguyen1209/offensive-claude) into .agents/skills/writing-offensive-skills in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill writing-offensive-skills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/writing-offensive-skills, .gemini/skills/writing-offensive-skills, .github/skills/writing-offensive-skills and .opencode/skills/writing-offensive-skills in your project.
SKILL.md names no scripts, command-line tools or credentials: Writing Offensive Skills is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Writing Offensive Skills is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 826 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Writing Offensive Skills: Code Graph Mermaid Diagrams (trailofbits/skills, 7.5k stars), Audit Flow (zebbern/claude-code-guide, 4.7k stars), Archify Diagrams (tt-a1i/archify, 82k stars) and JSON Canvas (heyitsnoah/claudesidian, 2.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.
Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.