🛡️
QualityJavaScript

Red Team

by tjboudreaux

Red Team is a Quality skill for Claude Code, published by tjboudreaux in cc-thinking-skills.

969 stars133 forkson tjboudreaux/cc-thinking-skillsAdded 2026/08/21+1% in starsRepository updated 2026/08/07
agent-skillsai-toolsanthropicclaudeclaude-codecritical-thinkingdecision-makingfirst-principlesmental-modelsproblem-solvingsystems-thinking
Install in seconds
Install Red Team
Copy Red Team into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/tjboudreaux/cc-thinking-skills/tree/main/skills/thinking-red-team ~/.claude/skills/thinking-red-team

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/tjboudreaux/cc-thinking-skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/thinking-red-team/SKILL.md in tjboudreaux/cc-thinking-skills
Installs to
~/.claude/skills/thinking-red-team
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Red Team does

Red Team helps you assess code, auth, APIs, and infrastructure you are authorized to test. It models attacker paths and keeps only findings with a reproducible exploit and verified mitigation.

Red Team is cataloged under Quality on DirSkills. Red Team comes from a repository tagged agent-skills, ai-tools, anthropic, claude and claude-code.

Documentation

README

Red Team

Adversarial security review of systems you are authorized to assess. Attack before an outsider does, but report only what you can actually break: every finding needs a concrete exploit path and a check that the proposed fix closes it.

When to Use

  • Security review of code, authentication, authorization, APIs, data handling, or infrastructure you control and are permitted to probe.
  • Pre-launch hardening of systems that handle auth, money, personal data, or privileged actions.
  • Checking whether a specific vulnerability class (injection, XSS, IDOR, auth bypass, SSRF, secret exposure, etc.) is present with a real path.
  • Validating that a claimed control actually blocks the attack, not only that a scanner is quiet.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Red Team

  • What else does tjboudreaux publish alongside Red Team?

    Red Team is one of 25 skills that DirSkills catalogs from tjboudreaux/cc-thinking-skills, the repository it ships in. Its siblings there include Bounded Rationality, Circle Of Competence and Effectuation. Each one is a separate skill with its own page in this directory, installs the same way Red Team does, and is maintained by tjboudreaux in that same repository. The rest of the collection is listed on the tjboudreaux/cc-thinking-skills page.

  • How does Red Team compare to other Quality skills?

    Red Team ranks #863 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Red Team against them. Open each page to compare what they document and how they install.

More from tjboudreaux/cc-thinking-skills

Red Team is one of 25 skills cataloged on DirSkills from tjboudreaux/cc-thinking-skills.

See all 25 skills
🧭
1w ago

Bounded Rationality

Bounded Rationality helps you set a clear sufficiency threshold before searching, then stop at the first option that meets it. Use it for open-ended comparisons or investigations with limited time or context.
AI Engineering
969133
🧭
1w ago

Circle Of Competence

Circle Of Competence checks whether a claim is grounded before answering. Use it to fetch evidence, mark uncertainty, or abstain when a specific fact is unverified and wrongness would matter.
AI Engineering
969133
🧭
1w ago

Effectuation

Effectuation starts from available means and an affordable loss cap when outcomes are too uncertain to forecast. Use it to choose controllable actions, seek real commitments, and let the goal emerge from what becomes possible.
AI Engineering
969133
🧠
1w ago

First Principles

First Principles strips unsupported assumptions from a problem, keeps only independently supported constraints, and rebuilds the simplest solution. Use it when a limit seems fixed by convention, pricing, or precedent instead of physics or measured need.
AI Engineering
969133
🧠
1w ago

Five Whys Plus

Five Whys Plus builds an evidence-linked causal chain from a localized fault to an actionable systemic root. Use it when the proximate cause is known but you need to prevent recurrence and verify which enabling conditions made it possible.
AI Engineering
969133
🧠
1w ago

Jobs To Be Done Thinking

Jobs To Be Done Thinking helps decide what to build, cut, or reposition by framing the user's circumstance, desired progress, and competing workarounds. It is used when adoption is unclear or a shipped feature is underperforming.
AI Engineering
969133