The AI Red Team Analyst skill for Claude
You show Claude your plan and it stops defending it. From that moment it attacks, with the means a real adversary would have: it maps at least three adversaries with their motive and attack vectors, exposes the assumptions under your plan, including the ones you never spoke out loud, scores them on likelihood times impact into a damage score, and delivers a defence for each main danger that you can carry out this week. That is red team thinking: hard on the plan, never on the person, and nothing invented to make the attack sound stronger.
the rules above come from the zip on this page · SKILL.md is 18,760 bytes
Plan in, attack out
reg. R.001This is the example that sits in the SKILL.md itself, shortened here as a session. A software maker wants to turn his one-off licence into a subscription and asks for a red team analysis before his customers carry one out on their own. Watch what happens with the competitor: it was not supplied as input, so it is marked as an assumption.
What the AI Red Team Analyst is
The AI Red Team Analyst is a free skill from the library of 100 skills we make available from AI and automation. A skill is an instruction file, SKILL.md, that gives an AI assistant a fixed way of working for one task; what Claude skills actually are NL is explained separately. This one is a file of 2,961 words that teaches Claude one thing: attack your plan the way a real adversary would, before that adversary gets the chance. You download the zip at the top of this page, put it in your Claude environment, and from that moment the request attack my plan turns into a structured analysis of six phases.
The problem the skill solves is a double role almost everyone plays. Whoever makes a plan also judges that same plan, and that combination produces predictable blind spots. You look for information that supports your plan and read criticism as noise. Your team is enthusiastic, so pushing back costs social capital and the doubter stays quiet. And you see the paths to success sharply in front of you, while the paths around them stay out of view. What a red team analysis does is organise the pushback your environment does not give you: someone who does not think along but thinks against, with a method instead of a mood.
It is written for anyone about to do something that costs money, time or reputation and is hard to undo. A business owner launching next month who does not know what he is missing. A team where everyone is enthusiastic, which is exactly the reason to get nervous. An investor reading a business case that the maker judged himself. The file's frontmatter lists those situations word for word as moments when Claude should pick up the skill on its own.
One thing you should know beforehand: the skill delivers dangers, not a verdict on you. It attacks the plan and leaves the person alone, and it never ends with objections only. Every main danger gets a defence you can carry out this week, with no budget you do not have. Attacking here is not a goal but a method for building your defence in time.
Why your own review is always too kind
Ask someone to judge his own plan and you get a defence with a few polite footnotes. That is not a character flaw, it is how minds work. The SKILL.md names the three mechanisms that undermine every self-assessment, and all three are well documented in the field red teaming comes from.
Confirmation drive. You have spent weeks inside the plan, so every signal that it holds feels like information and every signal that it does not feels like a detail for later. Anyone who wants to see his own assumptions wobble needs someone with no stake in keeping them standing. The Cognitive Bias Detector skill is the wider toolkit for this kind of thinking error; the red team analyst is the applied version for one concrete plan.
Group pressure. The moment a team is enthusiastic, criticism turns from a contribution into an attack on the mood. The doubter pays for that socially and stays quiet. A red team solves that by giving pushback a formal role: it is not your colleague being difficult, it is the method having its say today. Anyone who wants to run that division of roles in a team can also look at the Six Thinking Hats skill, where the black hat has the same function.
Planning optimism. You picture the route to success and see it clearly in front of you. The paths around it, where a customer gets angry, a supplier drops out or you yourself fall ill, do not appear in the estimate because you are not looking at them. That is why the file forces that look with a fixed adversary map and an assumption list of mandatory size: eight to twelve, even when the first five already hurt.
The difference between an ordinary review and a red team analysis is quickest to see as a diff, with lines drawn from the example in the skill:
The roles the skill takes on
reg. R.002An adversary is not always a competitor, and that might be the most useful rule in the file. At least three parties are mapped who stand to gain from your plan failing, or who can break it without any ill will at all, and for each one it thinks from three questions: what is the motive, what means does it have, and how fast can it act. These are the perspectives the SKILL.md prompts you to think through.
# for a personal decision with no external parties, the skill replaces the map with you yourself at different points in time
What is actually in the SKILL.md
A skill is only as good as its instructions, so we simply describe them here. The file opens with a frontmatter that sets out when Claude should pick up the skill. Not only for the literal requests like red team, attack my plan or be my devil's advocate, but also for sighs like: I am launching next month and I do not know what I am missing, everyone around me is enthusiastic and that makes me nervous, I made this plan myself and judged it myself, I want this shot down first.
Anyone who says something like that to Claude while the skill is loaded gets it automatically. The frontmatter also explicitly rules out: inventing plans that do not exist yet, attacking people, and technical security testing.
Next comes the role switch, and it is stated bluntly: once the skill is active, Claude stops defending the plan and attacks it with the means a real adversary would have. It also says this out loud to you, so you know exactly what stage the conversation is at. It then carries out seven fixed actions: naming the role switch, mapping at least three adversaries, exposing the assumptions under the plan including the unspoken ones, scoring eight to twelve assumptions on likelihood times impact, describing concrete attack vectors per adversary, writing a pre-mortem of a few paragraphs in which the plan has failed, and delivering one defensive action per main danger that you can carry out this week.
Before anything gets attacked, the skill runs through a mandatory input checklist: the plan in the form it exists in now, what it has to deliver and by when, what it costs in money, time and attention and what is irreversible, who is affected if this succeeds, what is already fixed and what can still change, the hard deadline, and what you personally find most nerve-racking. That last question is the sharpest of the set, because what you find most nerve-racking is usually the point you do not dare look at. If anything is missing, it asks in a single round and then carries on with marked assumptions.
The output always follows the same six phases: goal and scope of the attack, the adversary map, the assumption list, the attack vectors, the damage score and finally the pre-mortem with the defence. And there is a separate review mode: feed it an existing plan, business case or risk paragraph, and you first get an assumption density with quotes, a list of what is missing from it, an optimism check on timeline, conversion and cost, and a marker per section of whether a mistake there can be undone. Irreversible steps belong late in the plan, not early. The full analysis then still follows.
Anyone who wants to train probing questions as a standalone skill can turn to the Socratic Method skill NL for that; anyone who wants to learn to build a file like this themselves finds the full explanation with a template at writing your own SKILL.md NL.
The file closes with writing rules that guard the tone, and one of them sums up the whole skill: say the unpleasant part out loud, because a red team that softens things is useless. But attack the plan, never the person who made it.
Likelihood times impact
reg. R.003Ten assumptions from the example in the SKILL.md, scored the way the skill does it: per assumption the likelihood that it is wrong on a scale of 1 to 5, the impact if it is wrong on the same scale, and the product of the two as the damage score. The list is sorted descending and a cut-off line falls under the main dangers. Everything above the line gets a defence in phase six.
The theory the skill rests on
Red teaming does not come from business but from the military and intelligence world, and the skill names its sources so you can look them up yourself. The US Army set up the University of Foreign Military and Cultural Studies, the institute generally credited with the Red Team Handbook and its structured techniques for arguing against your own plan. Bryce Hoffman carried that methodology into business in his 2017 book Red Teaming. The core idea is the same in both worlds: an organisation that only judges its own plan cannot, by definition, see its own blind spots, so you set up a separate role that gets paid to think against it.
The pre-mortem comes from Gary Klein. He described the technique in Harvard Business Review in 2007: move yourself to a moment in the future where the plan has failed and write the history of that failure. The difference with an ordinary risk analysis lies in the certainty. You do not ask whether it could go wrong, you establish that it has gone wrong and work out how, and that takes the brake of politeness off.
In this skill the pre-mortem is part of phase six; anyone who wants only that technique, in its full form with failure categories, early signals and kill criteria, uses the separate Pre-Mortem Analyst skill NL. If it is not the attack you are after but the assumptions themselves, the first principles thinker strips your plan down to what is demonstrably true.
The assumptions check comes from Richards Heuer. His 1999 Psychology of Intelligence Analysis describes how analysts mistake their own assumptions for facts, and the key assumptions check he later worked out with Randolph Pherson in Structured Analytic Techniques is the practical answer to it: write down every assumption under the plan, including the ones that seem so obvious nobody says them out loud, and test how solid each one is. Phase three of this skill is that technique in working form, including the requirement to mark unspoken assumptions separately. Anyone who wants to see how such an assumption forms in your head, from observation to conclusion, finds that step model in the Ladder of Inference skill.
The variants come from the same field. The file names four you can bring in alongside it: devil's advocate, where one person systematically takes the opposing position; Team A versus Team B, where two groups get the same information and reach a conclusion separately; analysis of competing hypotheses, where you set several explanations side by side and look for evidence that rules one out; and the what-if analysis, where you take an event as settled and reason backwards to what had to be true beforehand. Which form fits when is covered further on, under the limits.
Even without installing the skill you can test your own plan with these principles: name who stands to gain if it fails, write your assumptions down as claims that can be true or false, and treat unanimous enthusiasm as a signal to probe further rather than as proof.
What the skill refuses
reg. R.004The SKILL.md contains a list of seven things the skill never does, and that list matters precisely because of the attacking role. Attacking without limits produces nothing but a blunt axe. In conversation the rules play out like this: each one is a request you might make, with the response the skill gives according to its own instructions.
Installing in Claude Code, Claude.ai or Codex
The zip contains one folder with the SKILL.md inside it. Installing is a matter of putting the file in the right place, and that place differs per environment. SKILL.md has been an open standard since December 2025, so the same skill also works in Codex, Cursor and Gemini CLI. So you are not downloading a Claude file but a working instruction that any modern AI assistant can read.
- Unzip it into
~/.claude/skills/(or.claude/skills/in your project). - Claude then recognises the skill automatically as soon as you ask it to attack or vet your plan.
- You can also call it directly, with
/ai-red-team-analist.
- Go to Customize and then Skills.
- Upload the zip there as a skill.
- Or paste the contents of SKILL.md into the project instructions of a Project.
- Open
AGENTS.mdin your repo. - Paste the contents of SKILL.md into it, or put SKILL.md next to it as a separate file and refer to it from
AGENTS.md. - Codex reads that along at the start of every session.
After that, using it is simple: paste your plan and ask for an attack. The more complete your input, the sharper the vectors; whatever is missing, the skill asks for in a single round. New to skills? Read what Claude skills are NL first, and the installation guide for Claude, Codex and Cursor NL. The wider explanation of working with AI is in the knowledge base.
When to use it, and when not
The full six phases are at their strongest for launches, big investments and decisions that are hard to undo: precisely the moments when a missed blind spot is most costly. Alongside that it has lighter forms, and it advises itself on when which one fits.
If time is short or the plan is still early, it runs only the pre-mortem: that takes a quarter of an hour and delivers the most per minute. If the plan is technical or financial and adversaries barely matter, such as with an internal system migration, the key assumptions check is enough. If there is a team with two camps, Team A versus Team B is the form: both camps get the same information and reach a conclusion separately. And if the question is not what could go wrong but what is already going on, for example with falling sales that could have several causes, it switches to analysis of competing hypotheses.
There are also situations where you are better off leaving it alone. It does not invent plans: something has to exist to attack, otherwise there is only a blank page and an opinion. It does not attack people, so a conflict with a business partner does not belong here. And it is explicitly not a technical security test: anyone who wants to know whether their systems are safe needs a different discipline. For a personal decision with no external parties, it skips the adversary map and replaces it with you yourself at different points in time, because even without a competitor you can be your own most dangerous adversary.
And the most honest limit: a red team analysis does not make your plan good, it makes it tested. If the attack turns up little, that says something about your preparation, and if it turns up a lot you still have the choice of what to do with it. It protects you against blind spots, not against decisions you make with your eyes open. If, after the attack, you still need to work out what kind of decision this actually is and which approach fits it, the Cynefin Decider skill is the logical next step.
Run it yourself, or have it run
reg. R.005This skill is the free do-it-yourself version of analysis work we also deliver as a service. It stays complete and with no catches, but be aware of what a skill is: it teaches your AI how to do something, while every new session starts empty. What you get is not the engine and not the memory. You prompt, you supply your plans and your context again every time, you check the result. Anyone who wants that differently has two next steps: hand off the engine, or sort out the memory.
where you are now The skill: you are the engine You run the AI Red Team Analyst yourself in Claude, Codex or Cursor. Costs nothing, works today, and you keep it entirely in your own hands: no trial period, no locked parts. The limit is your own discipline: the attack only happens when you remember to ask for it, and usually that is after the decision instead of before it.
a bespoke role A bespoke role: the attack as a standing part of the process Hiring a red team separately for a single plan is not a service we offer off the shelf. The three roles we set up ready-made are the Quote employee (sorting incoming enquiries and preparing draft quotes), the Sales employee (prospect research and outreach drafts) and the Reporting employee (summaries and weekly and monthly reports from your own data). This work is not among them, so this becomes a bespoke role through Mansotti, the company of which TheSEO is the trading name. What such a role can do is automatically give every plan that comes in a second reading, line up the assumptions and bring in the defences from earlier rounds. That only becomes worthwhile once plans worth attacking come in as a matter of routine. The control stays with you, because output remains a draft until a human approves it. Read what an AI employee is and does.
everything from one source Jarvis: all your AIs work from the same company knowledge The skill teaches the AI, the brain is where the memory lives. Want all your AIs working from the same company knowledge? That is Jarvis, the organisation brain. It connects ChatGPT, Claude, Codex and your people to the same projects, core knowledge and decisions, so your next AI session does not start from zero. That matters especially for a red team: an attack is only as good as its context, and a brain that knows your market, your customers and your earlier decisions does not need to be handed that again every session. What that delivers in practice, from the plans to your first week, you can read at Jarvis itself.
What Jarvis actually delivers
reg. R.006Rung 3 deserves more than a paragraph, because this is the difference between a smart chat and a system you can build on. Jarvis is the organisation brain: it remembers what your AIs need to know, divides up the work and keeps track of what happened. You notice it first at the start of a new session.
We have been running on this system ourselves for months. Every agent session, every task and every decision gets logged in it and can be read back. A new session therefore does not start blank: it first retrieves the recorded decisions, the running projects and the latest changes, and carries on where the previous one stopped. So we are not describing a promise but the way of working we ourselves are in every day.
See the four plans at jarvis/prijzen NL. Through the waiting list NL you only pass on your preferred plan, without obligation. That does not yet create an account, an order or a payment obligation. We discuss bespoke business setups first.
The skills around it
reg. R.007On its own a red team analysis has little value: a decision comes before it and a correction comes after it. These skills from the same library each cover a different part of that chain.
The same family
organising pushbackThree ways to argue against your own plan, each with a different starting point.
Pre-Mortem AnalystReconstructs the failure from the future, where the red team actively causes it as the adversary.SKILL NL Inversion ThinkerTurns the success question into how would I guarantee failure, and turns the failure mechanisms into counter-actions.SKILL Six Thinking Hats AnalystThe team form: criticism gets its own hat, so pushing back becomes a role instead of an attack.SKILLDeciding as a discipline
the decision clusterThe attack is one step in a decision process. These three carry the other steps.
Cynefin DeciderWorks out what kind of problem you actually have, before you loose an approach on it.SKILL WRAP DeciderThe full decision process; the red team supplies the pushback that belongs inside it.SKILL NL OODA Loop DeciderFor correcting course afterwards: observing and deciding the moment an attack vector becomes reality.SKILLSharpen the attack
probing questions and thinking errorsA good attack starts with sharp questions and honesty about your own thinking errors.
Socratic Method CoachThe probing technique that questions every assumption until it stands bare.SKILL NL Cognitive Bias DetectorRecognises the thinking errors, such as confirmation drive, that make a red team analysis necessary.SKILL Ladder of Inference CoachShows how an observation grows in your head into the assumption phase three exposes.SKILLLooking further
the contextWhere this skill comes from and what else there is.
The whole skill libraryAll 100 free skills in one place, sorted by topic.HUB NL AI and automationThe service behind it: from standalone skills to working automation in your business.SRV AI trainingIf your team wants to learn to set this kind of work up itself.SRV NL What are Claude skills?New to skills? The full explanation in plain language, with examples.DOC NLFrequently asked questions
What does the AI Red Team Analyst skill cost?
Nothing. The skill is free, comes under the MIT licence, and you do not have to create an account or leave an email address. You download a 7.3 KB zip containing a folder and a single file, SKILL.md, and that is the complete skill. There is no paid version and no sales email follows.
Does this skill also work in Codex, Cursor or Gemini CLI?
Yes. SKILL.md has been an open standard since December 2025, so the same file also works in Codex, Cursor, Gemini CLI and other tools that follow the standard. In Codex you unzip it into .agents/skills/ in your project, or into ~/.agents/skills/ for all your projects; Codex has supported SKILL.md directly since the open standard of December 2025. Putting the contents of SKILL.md into your AGENTS.md still works too. The instructions themselves are just readable text, so any AI assistant that accepts instruction files can handle it.
What is the difference between a red team analysis and a pre-mortem?
A pre-mortem is a single technique: you move yourself to a moment where the plan has failed and reason backwards. A red team analysis is broader. The pre-mortem sits inside it as part of phase six, but before that the skill first builds an adversary map, exposes the assumptions under your plan and describes concrete attack vectors per adversary. If you only want that one technique, there is a separate Pre-Mortem Analyst skill. You use the red team analysis if you also want to know who stands to gain from your plan failing, and what that party actually does about it.
Does the skill invent competitors or figures to make the attack stronger?
No. That is a hard rule in the file: no invented figures, competitor names, customer reactions or events. If the skill brings in an adversary you did not supply, such as a competitor with a similar product, it explicitly marks that as an assumption. The attack has to be hard, not invented, because a defence against an invented danger is time thrown away.
Is this the same as a technical security test or pentest?
No. The skill attacks plans, not systems. It does not run technical security tests and does not advise on attacking networks or software either; that is stated explicitly in its refusals. If you want to know whether your server can withstand an attack, you hire an ethical hacker. If you want to know whether your launch can withstand an angry customer, a competitor and your own optimism, you use this skill.
Does the skill also say whether I should stop with my plan?
Only if you explicitly ask for that. The skill delivers the dangers, sorted by damage score, and a defence for each main danger; the decision to continue, adjust or stop stays yours. That limit is stated in the file itself, together with the rule that a damage score is a sorting tool and not a prediction.
What does the skill need from me to work?
Your plan in the form it exists in now, what it has to deliver and by when, what it costs in money, time and attention, who is affected if it succeeds, what is already fixed and what can still change, the hard deadline and what you personally find most nerve-racking. That last one is not a side note: what you find most nerve-racking is usually the point you do not dare look at. If anything is missing, the skill asks in a single round and then carries on with marked assumptions.
Attack your visibility too, for once
A red team analysis works on any plan, so also on the assumption that customers will find you anyway. If you would rather test that assumption with real data than a gut feeling, the free SEO scan shows in a few seconds where your site stands. And if you want to talk further about what else AI can do for your business, from standalone skills to full automation, we are happy to do that in a conversation.