Today, SpecterOps released a new open-source skills marketplace for offensive security research and red team operations. We are proud to have collaborated on this project over the last few weeks and hope more teams will join now that it’s public. The initial release includes plugins for Fortra’s Cobalt Strike and Outflank C2. Get started here: https://github.com/SpecterOps/skills
Background
I recently reached out to a few red teams we’ve worked with before to discuss developing a public AI marketplace focused on offensive security. I was inspired by the Trail of Bits marketplace and wanted to see a similar project for offensive security. This task was too large to take on alone, so I contacted a few other researchers to discuss a joint effort. Imagine my surprise when SpecterOps told me they were nearly done implementing a similar project! I could not have been happier, of course. SpecterOps has a long history of high-quality open-source work, and they had already done so much to make the marketplace a reality. I am grateful they invited us to contribute in the last sprint of their project, and Fortra will continue to support this effort now that it has been made public.
MCP, Skills, and Plugins
I initially found MCP servers, skills, and plugins somewhat confusing as they can overlap in functionality. Here is my current understanding:
- MCP servers give agents access to tools and data, whether those services run locally or remotely. Skills are often preferred over MCP servers, except in situations where authentication is required.
- Skills provide reusable instructions, references, and examples in a Markdown file. A skill can bundle additional Markdown files and even scripts.
- Plugins package one or more skills and MCP servers so they are easy to install into clients like Codex CLI or Claude Code. Unlike MCP and skills, plugins are not vendor-agnostic.
The SpecterOps AI skills repository contains many plugins, each focused on a particular technology or use case. For example, the c2-cobaltstrike plugin has skills for writing Aggressor scripts and Malleable C2 profiles. Other examples, like the bloodhound plugin, connect to a remote MCP server and include skills to help an LLM use the associated tools.
Reusable Tradecraft
As described in an excellent blog from Trail of Bits, an AI skills marketplace aims to make expertise reusable. While there are many great blogs, open-source tools, and conference presentations on red team tradecraft, this is not easily digestible by an AI agent. Of course, this does not replace the operator. Instead, these skills should allow red teamers to automate some of their workflows so they can focus on the most valuable parts of an engagement: finding gaps specific to a target organization, evading modern security products, and reaching interesting objectives.
We invite red teamers, malware developers, security researchers, reverse engineers, and anyone interested in semi-autonomous research and operations to explore the repository and contribute back to the knowledge base. Contributors are welcome to add new plugins, but also correcting existing skills, documenting edge cases, adding references, or otherwise improving an existing plugin can be equally valuable. A public knowledge base is best when the community gets involved. This is only the beginning!
Outflank continually expands the tools and techniques available in Outflank Security Tooling (OST), a broad set of evasive tools that allow users to safely and easily perform complex tasks. While we will continue adding to the public AI skills marketplace, a private marketplace with OST-specific plugins will be available soon. Consider scheduling an expert-led demo to learn more about the diverse offerings in OST.