ctf-web
Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling, OAuth/OIDC, SAML, prototype pollution, and similar web bugs. Do not use it for native binary memory corruption, reverse engineering of standalone executables, disk or memory forensics, or pure cryptanalys
Security Assessment
Detected risks:
About ctf-web
The `ctf-web` skill is designed to assist security researchers, penetration testers, and CTF participants in tackling web-based exploitation challenges. It provides structured guidance and execution strategies for identifying and exploiting vulnerabilities in HTTP applications, APIs, browser clients, template engines, authentication flows, and both frontend and backend surfaces. By consolidating knowledge of common web flaws such as XSS, SQL injection, SSTI, SSRF, XXE, JWT issues, authentication bypasses, file uploads, request smuggling, and prototype pollution, this skill streamlines the process of mapping an application, confirming trust boundaries, and applying targeted exploitation techniques. It is specifically tailored to web contexts, avoiding non-web-specific attacks like native binary exploitation or pure cryptanalysis unless the web path is essential to achieving the objective.
FAQ
How should I use the ctf-web skill during a CTF challenge?
Start by mapping the target application and confirming trust boundaries. Use the skill to guide exploration of web-specific vulnerabilities, then dive into detailed techniques for exploitation as needed.
What platforms and tools are required for ctf-web?
It requires a filesystem-based agent capable of running Bash and Python 3, along with internet access for installing dependencies. Compatible tools include Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, and WebSearch.
Which Python and system packages are needed?
Python packages include sqlmap, flask-unsign, and requests. Linux systems may require hashcat, jq, and curl via apt, while macOS uses Homebrew for the same packages. Go tools such as ffuf are also supported if Go is installed.
Can I use ctf-web for native binary exploitation or reverse engineering?
No, this skill is intended for web-based flaws. Native binary memory corruption, standalone executable reverse engineering, disk or memory forensics, and pure cryptanalysis are outside its scope unless the web flaw is the main attack vector.
Are there recommended additional resources?
Yes, detailed technique references include SQL injection, server-side vulnerabilities, deserialization, direct code execution, advanced SSRF, template injection, and other modern web attack playbooks provided in linked markdown files.
All Files
21 filesInstall ctf-web
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
ljagiello/ctf-skills