Back to Skills

ctf-web

Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling, OAuth/OIDC, SAML, prototype pollution, and similar web bugs. Do not use it for native binary memory corruption, reverse engineering of standalone executables, disk or memory forensics, or pure cryptanalys

1,912stars245forksUpdated 5/9/2026

Security Assessment

Critical Risk(0/100)

Detected risks:

Data Exfiltration([server-side-advanced-2.md] requests.post, [server-side-advanced.md] requests.post, [server-side-advanced-4.md] requests.post)
Remote Code Execution([cves.md] exec(, [server-side-advanced-2.md] exec(, [server-side-deser.md] pickle.loads)
Secret Exposure([auth-infra.md] token =, [auth-infra.md] token=, [web3.md] PRIVATE_KEY)
Sensitive File Access([cves.md] .ssh/, [server-side-2.md] /etc/passwd, [server-side-advanced-2.md] /etc/passwd)
Command Injection([server-side-advanced-4.md] child_process, [server-side-deser.md] os.system, [server-side-deser.md] subprocess.call)
Privilege Escalation([server-side-advanced-4.md] sudo)
Security Score0/100

About ctf-web

The `ctf-web` skill is designed to assist security researchers, penetration testers, and CTF participants in tackling web-based exploitation challenges. It provides structured guidance and execution strategies for identifying and exploiting vulnerabilities in HTTP applications, APIs, browser clients, template engines, authentication flows, and both frontend and backend surfaces. By consolidating knowledge of common web flaws such as XSS, SQL injection, SSTI, SSRF, XXE, JWT issues, authentication bypasses, file uploads, request smuggling, and prototype pollution, this skill streamlines the process of mapping an application, confirming trust boundaries, and applying targeted exploitation techniques. It is specifically tailored to web contexts, avoiding non-web-specific attacks like native binary exploitation or pure cryptanalysis unless the web path is essential to achieving the objective.

FAQ

How should I use the ctf-web skill during a CTF challenge?

Start by mapping the target application and confirming trust boundaries. Use the skill to guide exploration of web-specific vulnerabilities, then dive into detailed techniques for exploitation as needed.

What platforms and tools are required for ctf-web?

It requires a filesystem-based agent capable of running Bash and Python 3, along with internet access for installing dependencies. Compatible tools include Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, and WebSearch.

Which Python and system packages are needed?

Python packages include sqlmap, flask-unsign, and requests. Linux systems may require hashcat, jq, and curl via apt, while macOS uses Homebrew for the same packages. Go tools such as ffuf are also supported if Go is installed.

Can I use ctf-web for native binary exploitation or reverse engineering?

No, this skill is intended for web-based flaws. Native binary memory corruption, standalone executable reverse engineering, disk or memory forensics, and pure cryptanalysis are outside its scope unless the web flaw is the main attack vector.

Are there recommended additional resources?

Yes, detailed technique references include SQL injection, server-side vulnerabilities, deserialization, direct code execution, advanced SSRF, template injection, and other modern web attack playbooks provided in linked markdown files.

All Files

21 files
auth-infra.md14.1 KB
View
web3.md15.4 KB
View
cves.md15.6 KB
View
server-side-2.md15.5 KB
View
server-side-advanced-3.md6.9 KB
View
server-side-advanced-2.md25.6 KB
View
server-side-advanced.md15.7 KB
View
server-side-advanced-4.md21.7 KB
View
auth-jwt.md8.7 KB
View
server-side-deser.md21.8 KB
View
SKILL.md10.4 KB
View
server-side-exec.md21.5 KB
View
auth-and-access-2.md5.1 KB
View
server-side.md29.3 KB
View
auth-and-access.md34.6 KB
View
sql-injection.md37.7 KB
View
node-and-prototype.md6.7 KB
View
server-side-exec-2.md38.5 KB
View
client-side-advanced.md36.9 KB
View
client-side.md21.5 KB
View
field-notes.md34.9 KB
View

Install ctf-web

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill