Run Gibson's repeatable red-team protocol against a target app to find security, auth, payment, PII/consent, and business-logic flaws before they ship — and before any paid third-party review. First target is ConferenceOS (mrhinkle/conference-os). Produces scored findings, files Critical/High as GitHub issues, and reports a readiness verdict. Use when Mark says "red team the app," "run Gibson," "run the red team," "security sweep," "attack conference-os," "are we secure," or "pre-pentest check."
Scanned 9/28/2026
Install to Claude Code
npx -y skills add The-AIE/the-gibson --skill red-team --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Red Team?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/the-aie-red-team)More formats (shields.io, HTML) on the badges page.
---
name: gibson-red-team
description: Run Gibson's repeatable red-team protocol against a target app to find security, auth, payment, PII/consent, and business-logic flaws before they ship — and before any paid third-party review. First target is ConferenceOS (mrhinkle/conference-os). Produces scored findings, files Critical/High as GitHub issues, and reports a readiness verdict. Use when Mark says "red team the app," "run Gibson," "run the red team," "security sweep," "attack conference-os," "are we secure," or "pre-pentest check."
---
# Gibson Red-Team
> **Authority:** Non-normative. Explanation, rationale, and history only. Binding commit/PR/merge rules live in [`AGENTS.md`](../../AGENTS.md). This file must not add, drop, or weaken those rules.
This skill runs the Gibson red-team protocol. The full method is in `PROTOCOL.md`; the target
under test is defined in `targets/<target>.md` (start with `conference-os.md`).
## Workflow
1. Read `PROTOCOL.md` and the relevant `targets/<target>.md`.
2. Confirm you are pointed at a preview/staging/local build — never destructive against prod.
3. Work Phases 1–6 in order. Log findings to `findings/YYYY-MM-DD-<target>.md` from `TEMPLATE.md`.
4. File Critical/High as GitHub issues on the target repo (`security` + severity labels).
5. Fix, re-run the relevant phase, and only mark a finding closed on a clean re-test.
6. Report the exit verdict: NOT READY or READY FOR THIRD-PARTY REVIEW.
## Downstream
This protocol is built to graduate into Chatterbuilt's Employee Handbook skill pack so the
agent crew can red-team the customer sites it maintains. See `PROTOCOL.md` § Downstream for the
handoff contract (crew runs Phases 1–5; Critical/High escalate to the owner; never touches real
customer PII).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!