credteam

Execute live red-team assessments against running systems with source code access.

65|2|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/joshft/correctless --skill credteam
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: credteam
Source: https://github.com/joshft/correctless/tree/main/correctless/skills/credteam
Command: npx skills add https://github.com/joshft/correctless --skill credteam

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Live adversarial red-team assessments against running systems to validate security controls and response readiness. This approach ensures that an organization's defenses are exercised with real-world objectives, mapping trust boundaries and testing detection and containment capabilities.

Core Features & Use Cases

  • Objective-driven engagement: conducts live, goal-oriented penetration testing against a running system with source code access.
  • Isolated environments: enforces strict isolation checks and safety rails to prevent testing on public networks.
  • Structured reporting: produces a narrative attack chain, boundary mapping, and concrete remediation recommendations suitable for CI regression tests.
  • Progress visibility: provides ongoing status updates and phase transitions to keep stakeholders informed throughout long-running assessments.
  • Use Case: simulate a red-team objective such as data exfiltration or privilege escalation to verify defenses and incident response.

Quick Start

Install the credteam skill and initiate a live, objective-driven red-team assessment in an isolated environment.

Frequently Asked Questions about credteam

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run objective-driven red-team assessments against running systems?

Objective-driven red-team assessments execute live, goal-oriented penetration testing against a running system with source code access. This validates security controls and incident response readiness through realistic adversarial testing.

What is the best way to validate security controls and response readiness with penetration testing?

Live penetration testing validates security controls by simulating red-team objectives like data exfiltration or privilege escalation. It maps trust boundaries and tests detection and containment capabilities against running systems.

Can I use source code access to map trust boundaries during a live security assessment?

Yes, live red-team assessments leverage source code access to map trust boundaries and test detection capabilities. This approach generates an attack narrative and structured remediation recommendations suitable for CI regression tests.

Does live red-team testing require isolated environments and safety rails?

Live red-team testing enforces strict isolation checks and safety rails to prevent testing on public networks. Isolated environments ensure adversarial assessments remain contained while validating security boundaries.

How do I generate structured remediation reports from a penetration testing engagement?

Penetration testing engagements generate structured remediation reporting by producing narrative attack chains and boundary mapping. These outputs provide concrete remediation recommendations suitable for CI regression tests.

What are the limitations of running adversarial testing on live systems?

Adversarial testing on live systems requires strict isolation validation to prevent impact on public networks. Assessments are constrained by safety rails and depend on source code access to maintain isolation guarantees.