ljagiello/ctf-skills

Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more

About the project

ctf-skills is a collection of agent instructions for solving capture-the-flag security challenges, including web exploitation, binary vulnerabilities, cryptography, reverse engineering, forensics, and OSINT. It is intended for agents and people working through CTF problems, and its skills can be loaded into supported coding-agent workflows.

3.2kStars on the repository
11Mods indexed here, across every type
16d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ctf-ai-ml

01

ljagiello/ctf-skills

Skill Claude Code

Provides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network analysis, LoRA adapter exploitation, LLM jailbreaking, or…

not rated 3.2k +49 16d ago B Socket: warnSnyk: failSkillSpector: warn 67 tokens original MIT

ctf-crypto

02

ljagiello/ctf-skills

Skill Claude Code

Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block cipher weaknesses.

not rated 3.2k +49 16d ago A Socket: warnSnyk: failSkillSpector: warn 78 tokens original MIT

ctf-forensics

03

ljagiello/ctf-skills

Skill Claude Code

Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio…

not rated 3.2k +49 16d ago D Socket: warnSnyk: warn 88 tokens original MIT

ctf-malware

04

ljagiello/ctf-skills

Skill Claude Code

Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility malfind, process…

not rated 3.2k +49 16d ago A Socket: passSnyk: failSkillSpector: warn 101 tokens original MIT

ctf-misc

05

ljagiello/ctf-skills

Skill Claude Code

Provides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game theory, unusual sandbox escapes, and hybrid logic puzzles.…

not rated 3.2k +49 16d ago A ✓ AI review Socket: warnSnyk: failSkillSpector: warn 122 tokens original MIT

ctf-osint

06

ljagiello/ctf-skills

Skill Claude Code

Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes and coordinates.

not rated 3.2k +49 16d ago A Socket: passSnyk: warnSkillSpector: warn 65 tokens original MIT

ctf-pwn

07

ljagiello/ctf-skills

Skill Claude Code needs its repo

Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc, shellcode, kernel…

not rated 3.2k +49 16d ago C Socket: failSnyk: failSkillSpector: warn 122 tokens original MIT

ctf-reverse

08

ljagiello/ctf-skills

Skill Claude Code

Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, game clients, malware-like loaders, and anti-debug or…

not rated 3.2k +49 16d ago A Socket: warnSnyk: warn 125 tokens copy · 84% MIT

ctf-web

09

ljagiello/ctf-skills

Skill Claude Code

Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling, OAuth/OIDC, SAML…

not rated 3.2k +49 16d ago B Socket: warnSnyk: failSkillSpector: warn 124 tokens original MIT

ctf-writeup

10

ljagiello/ctf-skills

Skill Claude Code

Generates a single standardized submission-style CTF writeup for competition handoff and organizer review. Use after solving a CTF challenge to document the solution steps, tools used, and lessons learned in a structured format.

not rated 3.2k +49 16d ago A Socket: passSnyk: failSkillSpector: pass 48 tokens original MIT

solve-challenge

11

ljagiello/ctf-skills

Skill Claude Code needs its repo

Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine where to start. Do not…

not rated 3.2k +49 16d ago A Socket: warnSnyk: failSkillSpector: warn 102 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: