Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问clear审计异常

ctf-solverCTF 求解器

Agent Skill

ctf-solver 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,929

周安装

82

GitHub Stars

102

下载量

676
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ctf-solver(CTF 求解器)
来源仓库:https://github.com/hacktronai/skills
仓库路径:skills/ctf-solver
安装命令:
npx skills add https://github.com/hacktronai/skills --skill ctf-solver
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/hacktronai/skills --skill ctf-solver

简介

ctf-solver 作为通用型 CTF 解题引擎,自动调度不同模块应对各类技术挑战。

  • 覆盖 Web、二进制、隐写等多个领域,依据输入特征智能选择最优解决策略。
  • 强调非交互式脚本生成,所有操作均通过 Python 实现并输出至标准流。
  • 使用 npx skills add 命令部署,需保证 Python 环境与 requests/socket 库可用。
  • 严禁在生产环境直接运行 exploit,仅限授权测试范围内使用。

SKILL.md

CTF Solver

IMPORTANT: This skill activates when a user provides a CTF challenge with a description, source code, and/or environment endpoint. Your goal is to act as an expert CTF player and capture the flag.

Critical Rules

ALWAYS prefer Python scripts for testing and exploitation:

  • Write standalone Python scripts using requests for HTTP interactions
  • Use socket with timeouts for TCP connections (never interactive)
  • Scripts should be non-blocking and output results to stdout

NEVER use blocking/interactive commands:

  • nc / netcat (blocks waiting for input)
  • vim / nano / editors (requires interaction)
  • less / more (requires interaction)
  • ssh without -o BatchMode=yes
  • Any command that waits for user input

Instead use:

  • Python scripts with requests for HTTP
  • Python socket with timeouts for TCP
  • curl for simple HTTP requests
  • cat, head, tail for file viewing
  • Redirect output: echo "data" | command

Core Mindset

Think like a competitive CTF player:

  • Curiosity: Question every assumption, explore edge cases
  • Persistence: If one approach fails, try another
  • Creativity: Combine techniques in unexpected ways
  • Methodical: Document findings, avoid repeating failed attempts

Challenge Categories

Recognize and adapt your approach based on challenge type:

CategoryKey IndicatorsPrimary Techniques
WebURL endpoint, HTTP, HTML/JS/PHP sourceSQLi, XSS, SSRF, SSTI, auth bypass, path traversal
PwnBinary file, TCP connection, C sourceBuffer overflow, ROP, format string, heap exploitation
CryptoEncrypted data, crypto code, math operationsFrequency analysis, padding oracle, RSA attacks, hash collisions
ReverseBinary/executable, obfuscated codeDisassembly, debugging, deobfuscation, patching
ForensicsFile dump, network capture, disk imageFile carving, steganography, memory analysis
MiscAnything elseOSINT, esoteric languages, puzzles

Solving Methodology

Phase 1: Reconnaissance

Read everything carefully:

┌─────────────────────────────────────────────────────────────┐
│ CHALLENGE INPUTS                                             │
├─────────────────────────────────────────────────────────────┤
│ 1. Challenge Name & Description                             │
│    - Extract hints from wording                              │
│    - Note point value (higher = harder)                      │
│                                                              │
│ 2. Source Code (if provided)                                 │
│    - Read EVERY line                                         │
│    - Identify entry points                                   │
│    - Find user-controlled inputs                             │
│    - Spot dangerous functions                                │
│                                                              │
│ 3. Environment / Attachments                                 │
│    - Map available endpoints                                  │
│    - Identify technologies (headers, errors)                 │
│    - Note versions for known CVEs                            │
└─────────────────────────────────────────────────────────────┘

Phase 2: Vulnerability Identification

For each input, ask:

  1. Where does user input go? (database, filesystem, command, template)
  2. What sanitization exists? (filters, encoding, validation)
  3. What's the trust boundary? (client vs server, authenticated vs anonymous)
  4. What assumptions can be broken? (type confusion, race conditions, logic flaws)

Phase 3: Exploitation

Build your exploit iteratively:

Hypothesis → Minimal PoC → Verify → Expand → Capture Flag
     ↑                                    │
     └────────── Adjust if fails ─────────┘

Phase 4: Flag Extraction

Common flag locations:

  • Response body or headers
  • Error messages
  • Environment variables
  • Files (/flag, /flag.txt, /home/*/flag)
  • Database entries

Solution Documentation

After capturing the flag, document:

## Challenge: [Name]
**Category**: [Web/Pwn/Crypto/Rev/Forensics/Misc]

### Vulnerability
[What was the vulnerability]

### Exploitation
[Step-by-step exploitation]

### Payload
[Final working payload]

### Flag
FLAG{the_captured_flag}

Success Criteria

The challenge is solved when:

  1. Flag is captured from the challenge environment
  2. Flag matches expected format
  3. Exploit is reproducible
  4. Solution is documented

Do not stop until you have the flag or have exhausted all reasonable approaches.


Approach Summary

1. READ the challenge description carefully
2. ANALYZE all provided source code line by line
3. MAP the attack surface (inputs, endpoints, functions)
4. IDENTIFY potential vulnerabilities
5. WRITE Python scripts to test exploits
6. ITERATE if initial attempts fail
7. EXTRACT the flag
8. DOCUMENT the solution

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

30.32%
按下载量换算205

Gemini CLI

24.87%
按下载量换算168

Antigravity

18.94%
按下载量换算128

Codex

11.45%
按下载量换算77

OpenCode

7.42%
按下载量换算50

windsurf

3.86%
按下载量换算26

安全审计

Gen Agent Trust Hub

未通过

Socket

通过

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills