Multi-AI Offensive Security Skills Library
A 34-skill offensive security library, native in Claude and expanding to ChatGPT, Gemini, and Microsoft Copilot.
Author: Sunil Gentyala, Independent Researcher License: Apache-2.0
Every existing offensive security skills library targets a single AI. Security operators use multiple AI platforms depending on context, client environment, and task type. OmniRed's full 34-skill library runs natively in Claude today, with a growing subset ported to ChatGPT, Gemini, and Microsoft Copilot — see Platform Coverage for exactly what's available where.
Beyond platform breadth, OmniRed introduces three categories that no other library covers:
| Category | What it covers | Why it matters |
|---|---|---|
ai-native/ |
Prompt injection, jailbreaking, model extraction, system prompt leak | Direct attacks against AI systems as targets |
mcp/ |
Tool poisoning, rug pull, context injection, server impersonation | Attacks on Model Context Protocol agent pipelines |
llm-pipeline/ |
RAG poisoning, embedding attacks, retrieval manipulation | Attacks on the data layer feeding LLMs |
These categories were developed alongside published research in MCP security (ContextGuard, IEEE ICCBI 2026) and the ARGUS agentic red-team scanner.
Claude has the full library natively as installable skills. Other platforms have a curated subset ported to their instruction format — porting the rest is the single highest-value contribution right now (see ROADMAP.md).
| Category | Skills | Claude | ChatGPT | Gemini | Copilot |
|---|---|---|---|---|---|
| ai-native | 4 | 4/4 | 2/4 | 1/4 | 1/4 |
| mcp | 3 | 3/3 | 1/3 | 1/3 | 1/3 |
| llm-pipeline | 2 | 2/2 | 1/2 | 1/2 | 0/2 |
| web | 9 | 9/9 | 1/9 | 1/9 | 1/9 |
| auth, AD, cloud, infra, recon, supply-chain, utility | 16 | 16/16 | 0/16 | 0/16 | 0/16 |
| Total | 34 | 34/34 | 5/34 | 5/34 | 3/34 |
| Platform | Format | Setup |
|---|---|---|
| Claude Code | Native plugin (SKILL.md per skill) |
See below |
| ChatGPT | Custom GPT instructions | chatgpt/PLATFORM.md |
| Gemini | Gem instructions | gemini/PLATFORM.md |
| Microsoft Copilot | Copilot Studio agent instructions | copilot/PLATFORM.md |
skills/
├── ai-native/ NEW - AI/LLM systems as targets
│ ├── prompt-injection/ Direct + indirect + cross-context injection
│ ├── jailbreaking/ Constitutional AI bypass, roleplay, persona attacks
│ ├── model-extraction/ Query-based model stealing
│ └── system-prompt-extraction/ Leaked system prompt recovery
│
├── mcp/ NEW - Model Context Protocol attacks
│ ├── tool-poisoning/ Hidden instructions in tool descriptions
│ ├── rug-pull/ Capability changes post-attestation
│ └── context-injection/ Cross-server context manipulation
│
├── llm-pipeline/ NEW - Data-layer attacks on LLM systems
│ ├── rag-poisoning/ Document + index poisoning
│ └── embedding-attacks/ Adversarial embedding manipulation
│
├── web/ Web application attacks (9 skills)
├── auth/ Authentication attacks (3 skills)
├── active-directory/ AD attacks (3 skills)
├── cloud/ Cloud attacks (3 skills)
├── infrastructure/ EDR evasion, initial access (2 skills)
├── recon/ OSINT, subdomain enumeration (2 skills)
├── supply-chain/ Model weight tampering (1 skill)
└── utility/ Report writing, CVSS4 scoring (2 skills)
Total: 34 skills across 11 categories, 4 AI platforms
Option A — Plugin marketplace (recommended)
/plugin marketplace add sunilgentyala/OmniRed
/plugin install omni-red@omni-red
Option B — Local testing (no install)
git clone https://github.com/sunilgentyala/OmniRed
claude --plugin-dir ./OmniRedOption C — Manual
# PowerShell
.\scripts\install-claude.ps1Option D — Sparse checkout (one category)
git clone --filter=blob:none --sparse https://github.com/sunilgentyala/OmniRed
cd OmniRed
git sparse-checkout set skills/ai-native skills/mcpOnce installed, trigger any skill by describing your task:
"I need to test this RAG pipeline for poisoning vulnerabilities"
→ loads skills/llm-pipeline/rag-poisoning
"Check this MCP server's tool descriptions for injection"
→ loads skills/mcp/tool-poisoning
"Test this app for SQL injection"
→ loads skills/web/sqli
See EXAMPLES.md for three full worked walkthroughs (MCP tool poisoning, IDOR, SQL injection triage).
OmniRed skills map directly to ARGUS scan profiles. Use ARGUS to automate payload generation across the same attack surfaces covered here.
# Run ARGUS covering the same attack surfaces as OmniRed ai-native skills
argus scan --target anthropic --model claude-sonnet-4-6 --profile fullSee ARGUS for automated LLM red-teaming.
Every skill is tagged with:
- OWASP LLM Top 10 (2025) — see shared/owasp-llm-top10-mapping.md
- MITRE ATLAS — see shared/mitre-atlas-mapping.md
- CVSS v4.0 vectors included in utility skills
OmniRed is designed for:
- Authorized penetration testing engagements
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Red team operator training
See SECURITY.md for full responsible use policy.
The platform-parity gap in the coverage matrix above is the best place to start — see CONTRIBUTING.md for how to port a skill or add a new one, and ROADMAP.md for what's planned next.
| Project | What it is |
|---|---|
| ARGUS | Agentic LLM red-team scanner (automated scanning) |
| ContextGuard | MCP zero-trust middleware (defense) |
| mcp-trust-anchor | MCP context poisoning defense |
| model-provenance-guard | Model supply chain security |
@misc{gentyala2026omni,
title = {OmniRed: Multi-AI Offensive Security Skills Library},
author = {Gentyala, Sunil},
year = {2026},
url = {https://github.com/sunilgentyala/OmniRed}
}