Agent Plugins Marketplace
All plugins

offensive-claude

v1.8.1

Spec-driven offensive-security framework for Claude Code: 31 kill-chain skills, executable safety controls (scope/finding/OPSEC discipline), pattern-learning memory, and a bounded engagement engine — with a SessionStart dispatcher that enforces skill-invocation discipline.

Claude Code34 Skills

By hypnguyen1209License: MIT338 GitHub starsUpdated 2 months ago

Directory evidence

Runtimes
Claude Code
Parsed components
34 skill or MCP entries
Source updated
Jul 3, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology

Install offensive-claude for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install offensive-claude@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/hypnguyen1209/offensive-claude

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The repository root is the plugin root.

Plugin files

offensive-claude/
├── .claude-plugin/plugin.json
├── skills/active-directory-attack/SKILL.md
├── skills/ai-agent-redteam/SKILL.md
├── skills/ai-security/SKILL.md
├── skills/browser-exploitation/SKILL.md
├── skills/cicd-supply-chain/SKILL.md
├── skills/cloud-security/SKILL.md
├── skills/coding-mastery/SKILL.md
├── skills/container-k8s-escape/SKILL.md
├── skills/crypto-analysis/SKILL.md
├── skills/edr-evasion/SKILL.md
├── skills/engagement-flow/SKILL.md
├── skills/engagement-memory/SKILL.md
├── skills/exploit-development/SKILL.md
├── skills/finding-discipline/SKILL.md
├── skills/incident-response/SKILL.md
├── skills/initial-access/SKILL.md
├── skills/malware-analysis/SKILL.md
├── skills/mobile-pentest/SKILL.md
├── skills/network-attack/SKILL.md
├── skills/opsec-discipline/SKILL.md
├── skills/privesc-linux/SKILL.md
├── skills/privesc-windows/SKILL.md
├── skills/recon-osint/SKILL.md
├── skills/red-team-ops/SKILL.md
├── skills/reverse-engineering/SKILL.md
├── skills/scope-discipline/SKILL.md
├── skills/shellcode-dev/SKILL.md
├── skills/threat-hunting/SKILL.md
├── skills/threat-model-discipline/SKILL.md
├── skills/using-offensive-claude/SKILL.md
├── skills/vulnerability-analysis/SKILL.md
├── skills/web-pentest/SKILL.md
├── skills/windows-boundaries/SKILL.md
└── skills/writing-offensive-skills/SKILL.md

Included Skills34

active-directory-attackskills/active-directory-attack/SKILL.md

Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CVE-2025-33073), ADCS ESC1-16 (EKUwu), ticket forgery & DCSync, dMSA BadSuccessor (CVE-2025-53779), BloodHound attack-path enumeration, domain dominance

ai-agent-redteamskills/ai-agent-redteam/SKILL.md

Use when red-teaming an agentic AI / LLM application — indirect & zero-click prompt injection, MCP tool poisoning, persistent memory poisoning, excessive-agency tool abuse, multi-turn jailbreaks, PyRIT/Garak/Promptfoo harnesses

ai-securityskills/ai-security/SKILL.md

Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/vector poisoning, agentic/MCP exploitation (CVE-2025-54136), ML supply-chain RCE (pickle CVE-2025-32434), model extraction / membership inference / adversarial suffixes (GCG)

browser-exploitationskills/browser-exploitation/SKILL.md

Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, renderer-to-browser sandbox escape (Mojo IPC, GPU/Dawn/ANGLE), Electron/webview IPC abuse, 1-click RCE chains

cicd-supply-chainskills/cicd-supply-chain/SKILL.md

Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution, compromised/mutable-tag actions, dependency confusion, registry worms, runner backdoors, OIDC trust abuse, SLSA/provenance

cloud-securityskills/cloud-security/SKILL.md

Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse

coding-masteryskills/coding-mastery/SKILL.md

Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, automation, cryptography implementation

container-k8s-escapeskills/container-k8s-escape/SKILL.md

Use when breaking out of a container or escalating inside Kubernetes — runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot

crypto-analysisskills/crypto-analysis/SKILL.md

Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum migration review

edr-evasionskills/edr-evasion/SKILL.md

Use when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection, AMSI bypass, ETW patching, memory/sleep encryption, behavioral evasion

engagement-flowskills/engagement-flow/SKILL.md

Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain phases with quality gates instead of jumping straight to exploitation

engagement-memoryskills/engagement-memory/SKILL.md

Use when recalling prior techniques at recon/weaponize, or recording a confirmed finding at report — cross-engagement pattern memory ranked by impact

exploit-developmentskills/exploit-development/SKILL.md

Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox

finding-disciplineskills/finding-discipline/SKILL.md

Use when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONFIRMED] or writing it into the report

incident-responseskills/incident-response/SKILL.md

Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining, anti-forensics detection, cloud IR, ransomware/ESXi response

initial-accessskills/initial-access/SKILL.md

Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-chain, credential stuffing, exposed-service exploitation

malware-analysisskills/malware-analysis/SKILL.md

Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)

mobile-pentestskills/mobile-pentest/SKILL.md

Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE

network-attackskills/network-attack/SKILL.md

Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay (CVE-2025-33073), TUN pivoting (Ligolo-ng/Chisel), MitM, network-service RCE (CVE-2024-38077), WPA2/WPA3 wireless

opsec-disciplineskills/opsec-discipline/SKILL.md

Use when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or feeding captured traffic to the model) — to decide detection footprint, cleanup, and secret redaction first

privesc-linuxskills/privesc-linux/SKILL.md

Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LD_PRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe, GameOver(lay)), service misconfig (PwnKit, Looney Tunables), container/namespace escape

privesc-windowsskills/privesc-windows/SKILL.md

Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel EoP + BYOVD (CVE-2025-29824), token-rights abuse, LSASS/SAM/DPAPI credential harvesting

recon-osintskills/recon-osint/SKILL.md

Use when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover, multi-cloud/Azure tenant recon, GitHub secret dorking, breach/infostealer credential intel, CVE prioritization (EPSS/KEV)

red-team-opsskills/red-team-ops/SKILL.md

Use when running a full red-team engagement end-to-end — initial access, persistence, privilege escalation, defense evasion, C2 infrastructure, EDR bypass, living-off-the-land

reverse-engineeringskills/reverse-engineering/SKILL.md

Use when reverse-engineering a binary or firmware — static triage + decompilation (Ghidra/IDA/Binary Ninja), dynamic instrumentation (GDB/Frida 17/angr), anti-reversing & packer bypass, OLLVM/VM deobfuscation, UEFI/BIOS RE & Secure Boot research, patch-diffing for n-days

scope-disciplineskills/scope-discipline/SKILL.md

Use when about to send a request to, scan, enumerate, exploit, or otherwise interact with any host, IP, URL, or asset — before the first packet reaches a target

shellcode-devskills/shellcode-dev/SKILL.md

Use when writing position-independent shellcode or a loader — PEB walking, API hashing, null-byte avoidance, encoders, loaders, PE-to-shellcode conversion, cross-platform shellcode

threat-huntingskills/threat-hunting/SKILL.md

Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation

threat-model-disciplineskills/threat-model-discipline/SKILL.md

Use when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before advancing

using-offensive-claudeskills/using-offensive-claude/SKILL.md

Use when starting any offensive-security engagement or task — establishes how to find and invoke the right skill before any action (including clarifying questions, recon, exploitation, or reporting)

vulnerability-analysisskills/vulnerability-analysis/SKILL.md

Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks

web-pentestskills/web-pentest/SKILL.md

Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race

windows-boundariesskills/windows-boundaries/SKILL.md

Use when crossing a Windows security boundary or escaping a sandbox — kernel/user crossing (win32k/dxgkrnl UAF CVE-2025-24983), BYOVD kernel R/W, UAC/COM elevation, AppContainer/LPAC & Chromium-Mojo sandbox escape (CVE-2025-2783), PPL bypass, RPC/ALPC & named-pipe impersonation

writing-offensive-skillsskills/writing-offensive-skills/SKILL.md

Use when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection, red-flags tables, flowchart rules)

Plugin manifests1

.claude-plugin/plugin.json
{
  "name": "offensive-claude",
  "description": "Spec-driven offensive-security framework for Claude Code: 31 kill-chain skills, executable safety controls (scope/finding/OPSEC discipline), pattern-learning memory, and a bounded engagement engine — with a SessionStart dispatcher that enforces skill-invocation discipline.",
  "version": "1.8.1",
  "author": {
    "name": "hypnguyen1209",
    "email": "[email protected]"
  },
  "homepage": "https://github.com/hypnguyen1209/offensive-claude",
  "repository": "https://github.com/hypnguyen1209/offensive-claude",
  "license": "MIT",
  "keywords": [
    "security",
    "offensive-security",
    "pentest",
    "red-team",
    "cyber-kill-chain",
    "skills",
    "mitre-attack"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[offensive-claude on Agent Plugins Marketplace](https://pluginsmp.com/plugins/offensive-claude)