Topic · Security

Best red teaming and adversary simulation skills for Claude Code, Codex and other agents.

Skills that simulate adversary tactics for authorised red-team exercises.
skills
147
official
5

Red teaming and adversary simulation skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Red teaming and adversary simulation skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

Tencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0today
2

Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

responsibleai/ASSERT327—~11kAutomated safety check: NotesMITtoday
3

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT1 mo ago
4

Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).

elvisun/loss-function-development176—~2.9kAutomated safety check: NotesMIT3 mo ago
5

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

ADScanPro/Claude-AD209—~2.6kAutomated safety check: PassMIT1 mo ago
6

Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

Tencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0today
7

Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction.

Tencent/AI-Infra-Guard6.8k—~1.1kAutomated safety check: WarnApache-2.0today
8

Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

ADScanPro/Claude-AD209—~2.9kAutomated safety check: NotesMIT1 mo ago
9

Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count…

JuliusBrussee/skills161—~2kAutomated safety check: PassMIT2 mo ago
10

Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

seb1n/awesome-ai-agent-skills206—~2.8kAutomated safety check: PassMIT1 mo ago
11

The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

ADScanPro/Claude-AD209—~2.4kAutomated safety check: PassMIT1 mo ago
12

Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators.

ahmadvh/octochains375—~1.3kAutomated safety check: PassUnknown1 mo ago
13

Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts.

Tencent/AI-Infra-Guard6.8k—~760Automated safety check: PassApache-2.0today
14

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

ADScanPro/Claude-AD209—~3.6kAutomated safety check: PassMIT1 mo ago
15

Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

warpdotdev/common-skills6061 repo~1.8kAutomated safety check: PassMIT6 days ago
16

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

ADScanPro/Claude-AD209—~1.9kAutomated safety check: PassMIT1 mo ago
17

Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes.

Tencent/AI-Infra-Guard6.8k—~954Automated safety check: PassApache-2.0today
18

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

ADScanPro/Claude-AD209—~2.9kAutomated safety check: NotesMIT1 mo ago
19

Audit Entra ID app registration and service principal security posture.

SCStelz/security-investigator249—~21kAutomated safety check: PassMITyesterday
20

A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing…

gaasher/Agent-Loop-Skills174—~3.6kAutomated safety check: PassMIT3 mo ago
21

Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
22

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
23

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

ADScanPro/Claude-AD209—~1.7kAutomated safety check: PassMIT1 mo ago
24

Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMITyesterday
25

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMITtoday
26

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads276—~895Automated safety check: PassMIT8 days ago
27

Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

digoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.09 days ago
28

Multi-turn adversary simulation. An agent skill from NovusEdge/palpatine.

NovusEdge/palpatine110—~1.1kAutomated safety check: PassUnknown22 days ago
29

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
30

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
31

Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
32

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests (Event ID 4769) targeting service accounts with SPNs, which attackers request offline to crack service account passwords.

mukul975/Anthropic-Cybersecurity-Skills34k—~914Automated safety check: PassApache-2.01 mo ago
33

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
34

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
35

Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping…

mukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.01 mo ago
36

Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse.

mukul975/Anthropic-Cybersecurity-Skills34k—~922Automated safety check: PassApache-2.01 mo ago
37

Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
38

Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk…

mukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.01 mo ago
39

Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.01 mo ago
40

Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.01 mo ago
41

Hardens the Docker daemon (dockerd) through /etc/docker/daemon.json with user namespace remapping, TLS client authentication, seccomp profiles, and CIS Docker Benchmark controls such as icc…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: NotesApache-2.01 mo ago
42

Hunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e.

mukul975/Anthropic-Cybersecurity-Skills34k—~925Automated safety check: PassApache-2.01 mo ago
43

Runs a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~914Automated safety check: PassApache-2.01 mo ago
44

Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
45

Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
46

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
47

Perform structured log source onboarding into SIEM platforms (Splunk, Elastic, Sentinel, QRadar, or similar) by prioritizing sources with a tiered value framework, configuring collectors, building…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
48

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago

Questions, answered from the data.

What is the best red teaming and adversary simulation skill?

Authorization Bypass Detection from Tencent/AI-Infra-Guard ranks first of the 147 red teaming and adversary simulation skills listed here, with the highest score: its repository has 6.8k GitHub stars, its SKILL.md loads about 753 tokens and it passes the automated safety check with no findings. Next come Run Assert Eval and Osint Methodology.

Which red teaming and adversary simulation skills are official?

5 of the 147 red teaming and adversary simulation skills are official, published by the vendor's own GitHub organization: GitHub Actions Hardening, Secops Investigate, Amazon Workspaces Agent Access, Azure Kusto Irql and Rds Db2.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.