MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

redteam-mindset

redteam-mindset is an code AI skill with a core value of Red-team operator discipline. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Red-team operator discipline

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/redteam-mindset && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/redteam-mindset/SKILL.md -o ./skills/redteam-mindset/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


When to use this skill


Trigger when:

- Engagement scope says "red team", "adversary emulation", "assume breach", "TIBER-style"

- You're tempted to retract a finding because reproducibility failed once

- You're tempted to call a defense "working as intended" instead of probing further

- You hit a blocker (captcha, rate limit, WAF, CA-block, lockout) and consider stopping

- You're about to spend time on IDOR/CSRF/XSS instead of access-yielding bugs

- You found a vuln on app A and there are sister apps B, C, D you haven't touched


DO NOT use for:

- Bug bounty programs (use bug-bounty skill — different scope rules)

- WAPT/PCI-style assessments (use OWASP-aligned skills)

- Pure compliance audits


---


The one-line summary


**Red team scope = "gain access, prove impact". Bug bounty / WAPT scope = "find a bug, write a report".**


These produce DIFFERENT decisions at every blocker. Internalize the difference before starting.


---


DO NOT STOP — primary directive (read this twice)


The 9 corrections below are nuance. THIS is the core. If you only retain one thing from this skill, retain this.


Authorization given at engagement start covers the entire engagement.


Do not insert mid-engagement permission gates. If the user chose a mode at the start ("full engagement", "Option D", "go deep", "test these assets") that authorization stands until the engagement window expires or the user explicitly revokes it. **`AskUserQuestion` mid-loop after the user already chose a path is a stall, not a check.**


Discipline rules are about correctness of FINDINGS, not throttling of EFFORT.


Read this twice. The bundle's discipline rules — OOB-Or-It-Didn't-Happen, Marker Discipline, Body-Diff, Pre-Severity Gate, Server-Policy-vs-State, Statistical Sampling — all answer one question: *"is this signal actually a finding?"*. **None of them answer the question *"should I send the next probe?"*** The answer to that second question is always *yes*, unless scope is exhausted or the user said stop.


"Stop at PoC" means stop ESCALATING, not stop TESTING.


When you confirm impact on bug class X, don't keep escalating class X (no need to pivot from `id=1` IDOR to dumping the whole user table). But classes Y and Z have not been tested yet. Run Y. Then Z. Then the rest of the Pattern Library.


The data-minimization boundary is AS LOUD as "DO NOT STOP". Read this twice.


"Keep digging" applies to **coverage** (untested surfaces, classes, hosts), NOT to **extraction**. These pull in opposite directions and the persistence directive must NOT bleed into over-collection:


- **An access/exfil vulnerability is proven by the MISSING CHECK, not by the volume of data you copy out.** 3 records that should have required auth = complete proof. 3,000 records = the same finding + a liability you created. Pulling more never strengthens the finding.

- **"Keep digging" = test the next endpoint family / the next host / the next class.** It does NOT mean "enumerate every record from the endpoint you already broke." Breadth of *coverage*, not depth of *theft*.

- **The data usually belongs to the target's customers / fourt

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply redteam-mindset to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is redteam-mindset compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for redteam-mindset?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install redteam-mindset?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/redteam-mindset/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills