Agent skill

CTF Campaign Driver

by Encod3d-Sec in Encod3d-Sec/TORCH

Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

MITAuto-check passedSecurity

Install CTF Campaign Driver

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill ctf-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH ctf-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/ctf-workflow .claude/skills/ctf-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ctf-workflow
GitHub stars
329
Token cost
~1.8k tokens
SKILL.md length
916 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

  • Works in 7 steps: python3 scripts/campaign.py init --type… → OSINT is OFF by default for CTF (pass 0… → Passes 1-3 feed state.md - rustscan/nmap… → …
  • Being handed a CTF box or address to take from foothold to root
  • SKILL.md covers The loop, Start / resume, Box recipes and Browser observation, plus 5 more sections
  • Calls python3

What it does

A single agent works a CTF or boot-to-root machine without asking an operator for approvals. A Python script, scripts/campaign.py, holds the campaign state, builds a board of work items from reconnaissance and prints the exact next action, including which skill and tool to use. The agent runs the next command, does what it prints, records the result and repeats, going depth-first.

A campaign begins by validating the scope file, which for a box is just the target host. The OSINT pass is skipped unless you invoke the skill with an osint argument. Early passes feed a state file with port-scan and web enumeration results, the board then lists foothold rows, and recording a foothold seeds privilege-escalation rows for that asset. Box-specific recipes are delegated to a companion skill named ctf-box. The excerpt is truncated, so later steps are not covered here.

When your agent uses it

  • Being handed a CTF box or address to take from foothold to root
  • Resuming a half-finished boot-to-root campaign from its recorded state
  • Tracking recon findings, footholds and privilege-escalation leads on a CTF machine

Example prompts

  • “Root this box. The target address is already in scope.md.”
  • “Continue the campaign from where we stopped and tell me the next action.”
  • “Record the reverse shell we just caught as a foothold and seed the privesc rows.”

Requirements

  • Python 3
  • A scope file naming the target
  • Scanning and exploitation tools such as nmap and msfconsole

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. python3 scripts/campaign.py init --type ctf - validates scope.md (for a box, scope is just
  2. OSINT is OFF by default for CTF (pass 0 is skipped). Only run it if this skill was invoked
  3. Passes 1-3 feed state.md - rustscan/nmap + web enum. Read every service banner, page source and
  4. python3 scripts/campaign.py board - writes the 4a foothold rows; once an asset is a foothold,
  5. Enter the loop, depth-first.
  6. When a foothold lands (a reverse shell in a tmux window via vm-scan.sh --win shell, or a
  7. Web RCE -> a real shell, THEN stabilize -- do not ride one-liners (recurring drift). The

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CTF Campaign Driver loads about 1.8k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 916 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 916 words, ~1,805 tokens.

Download SKILL.mdSave it as .claude/skills/ctf-workflow/SKILL.md (or your agent's skills folder).
name
ctf-workflow
description
Autonomous CTF / boot-to-root campaign driver. Runs a box end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool) every turn. Use when handed a box/IP to own end to end, "run the ctf workflow", "root this box", "foothold to root". Single agent, wiki-first, tool-first. OSINT is OFF unless you invoke with an osint argument. Delegates box recipes to ctf-box.

ctf-workflow

The driver is the plan. Run one command, do exactly what it prints, record the result, repeat. The gates are enforced by scripts/campaign.py.

The loop

python3 scripts/campaign.py next
python3 scripts/campaign.py note <row> --arsenal <slug>
python3 scripts/campaign.py done <row> --poc <img> --kind req   # | --dead R | --park Q | --find F

Every next now prints an APPROACH:/AVOID:/REFS: block for the served row (the distilled ctf-box method for that vuln class) - read it before acting.

Start / resume

  1. python3 scripts/campaign.py init --type ctf - validates scope.md (for a box, scope is just the target IP/host) + envelope.
  2. OSINT is OFF by default for CTF (pass 0 is skipped). Only run it if this skill was invoked with an explicit osint argument - a box's answer is on the box, not in Wayback.
  3. Passes 1-3 feed state.md - rustscan/nmap + web enum. Read every service banner, page source and config end to end.
  4. python3 scripts/campaign.py board - writes the 4a foothold rows; once an asset is a foothold, re-run board and it seeds the 4b privesc rows (pspy/linpeas auto + the manual checklist) for that asset.
  5. Enter the loop, depth-first.
  6. When a foothold lands (a reverse shell in a tmux window via vm-scan.sh --win shell, or a meterpreter/msfconsole session via --win msf), record it: python3 scripts/campaign.py foothold <target> --win shell (or --win msf; or ride it on the closing find with done ... --win). The driver flips the asset's state.md row to access=foothold and routes its 4b privesc rows through vm-rsh --win <win> (persistent session + operator visibility past foothold), and prints tmux attach -t <eng> for manual takeover. msf itself is operator-attach / drop-to-shell, not vm-rsh-driven (its wrapper frames a bash shell, not the msf6 > REPL). After recording a foothold, re-run python3 scripts/campaign.py board so the 4b privesc rows are seeded - next will not surface them until you do.
  7. Web RCE -> a real shell, THEN stabilize -- do not ride one-liners (recurring drift). The moment code-exec lands (a web-RCE primitive, an LFI->session-poison, a deser gadget), STOP hand-poking one-shot payloads: (a) catch it with a real handler by default - msfconsole's exploit/multi/handler (meterpreter first; a plain shell_reverse_tcp is the backup when meterpreter is blocked, e.g. Windows/EDR) (record via campaign.py foothold <target> --win msf, step 6). Reserve a raw nc -lvnp listener for when msf is unavailable: a raw nc pane's Ctrl-C kills the LISTENER (dropping the shell back to your own prompt, the false-root attacker-prompt trap) and it has no session management, while meterpreter also carries post/multi/recon/local_exploit_suggester escalation modules and built-in file transfer. (b) Before picking the LPORT, test target egress on common ports (80/443/53) - high ports like 4444 are frequently filtered, so pick an egress-allowed LPORT. (scripts/vm-handler.sh <eng> <lhost> picks a free egress port and launches the handler for you, printing the LPORT.) (c) If you did fall back to raw nc, stabilize it immediately with bash scripts/vm-stabilize.sh --win shell <eng> (pty + job control + window size). (d) Then record the foothold (step 6) and drive with vm-rsh. An unstabilized nc shell (no job control, mid-line wrapping) is what makes post-ex drift back into one-liners. Full discipline: Skill(ctf-box) Phase 3 (Deliver). The recon-capture hook fires this reflex once on the first service-account id.

Box recipes

ctf-workflow owns pass sequencing and the board; the per-service exploitation recipes live in Skill(ctf-box), which the driver hands off to - do not duplicate them here. Route a fingerprinted service to its Skill(hunt-*) as the board names it; use Skill(ctf-category) for a standalone challenge (pwn/rev/crypto/forensics/stego).

Show full SKILL.md (370 more words)Show less

Browser observation

A box is VPN-boxed, so the local chrome-devtools MCP browser cannot reach it - use the VM-side browser (scripts/browser.sh <url> / capture.sh web) to render a JS-heavy web service and read its DOM + network requests (the rendered XHR/fetch calls reveal API routes a curl crawl misses - often the intended path). Rendered screenshots of the flag/exploited state are valid web PoCs.

A service needing a manual login / MFA / CAPTCHA the agent can't do headlessly -> Skill(chrome-devtools-browser): a VISIBLE chromium on the VM desktop (scripts/browser-visible.sh) the operator drives, observed live via the chrome-devtools MCP.

Gates

G1 arsenal-first, G2 skill-first, G3 typed evidence (a flag on screen is a valid web PoC), G8 tool-first. Privesc always includes pspy + linpeas/winpeas - the board seeds these as 4b rows once an asset is recorded as a foothold (re-run board after foothold/done --win to seed them).

Once a foothold and a working escalation vector are identified, hand the exploit compile + escalation run to a sub-agent via Skill(delegate) - checklist, model choice, and the mandatory false-root/false-RCE hostname+uid guardrail all live there; keep the main agent driving the board.

Prefer a clean post-ex command channel over driving msf sessions -c (delayed output, quoting pain): a webshell writing enum output to a web-served file then curl it, or a single-tool read/decrypt done locally on already-exfiltrated data.

Autonomy

No approvals. The verifier is optional for CTF (a captured flag self-verifies). Both flags captured -> set ## STATUS: SOLVED in state.md, then the driver prints the close-out chain.

Discipline

  • Do NOT invoke superpowers:brainstorming/writing-plans mid-box; keep no parallel task list.
  • One agent. Read service output whole - the foothold hides in the handler a grep skips.
  • Reuse captured creds across hosts before researching new ones.
  • Long/observed tools (sqlmap, big scans) go in a NAMED tmux window (scripts/vm-scan.sh), never a blind background pipe -- you must WATCH a scanner that can trip a target's rate-limiter/ban.
  • Capture the flag/root state to poc/ AS IT LANDS (scripts/capture.sh), even on a curl/ssh-only box -- a transient exploited state cannot be re-shot after the turn.

Close-out

Run the printed chain: Skill(walkthrough) -> Skill(learn).

If the driver is unavailable

Manual fallback: read Approach.md, take the top open row, run its wiki lookup then its hunt skill or Skill(ctf-box), capture evidence, mark [x]; on exhaustion one Deadends.md line + [!].

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/ctf-workflow of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

CTF Campaign Driver next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CTF Campaign Driver compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CTF Campaign Driver this skillEncod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT
Add Community Skillsamugit83/redamon2.9k—~775Automated safety check: PassMIT
Exploiting Ms17 010 Eternalblue Vulnerabilitymukul975/Anthropic-Cybersecurity-Skills34k—~963Automated safety check: PassApache-2.0
Penetration Flowlingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT
Insecure Deserialization PlaybookPentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.0
NmapBrownFineSecurity/iothackbot8581 repos~3.8kAutomated safety check: NotesMIT

Similar skills

  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    2.9k GitHub stars~775 tokensUpdated yesterday
    SecurityAuto-check passed
  • Exploiting Ms17 010 Eternalblue Vulnerability

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's…

    34k GitHub stars~963 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Ssti

    PentesterFlow/agent

    Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about CTF Campaign Driver

What does CTF Campaign Driver do?

Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn. A single agent works a CTF or boot-to-root machine without asking an operator for approvals.py, holds the campaign state, builds a board of work items from reconnaissance and prints the exact next action, including which skill and tool to use.

When should I use CTF Campaign Driver?

CTF Campaign Driver fits situations like: being handed a CTF box or address to take from foothold to root; resuming a half-finished boot-to-root campaign from its recorded state; tracking recon findings, footholds and privilege-escalation leads on a CTF machine.

How do I install CTF Campaign Driver in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill ctf-workflow -a claude-code`. Or copy the skill folder (skills/workflow/ctf-workflow in Encod3d-Sec/TORCH) into .claude/skills/ctf-workflow in your project. Claude Code loads it when a task matches its description.

How do I install CTF Campaign Driver in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill ctf-workflow -a codex`. Or copy the skill folder (skills/workflow/ctf-workflow in Encod3d-Sec/TORCH) into .agents/skills/ctf-workflow in your project. Codex loads it when a task matches its description.

Can I use CTF Campaign Driver in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill ctf-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ctf-workflow, .gemini/skills/ctf-workflow, .github/skills/ctf-workflow and .opencode/skills/ctf-workflow in your project.

What does CTF Campaign Driver need to run?

Going by SKILL.md and its folder, CTF Campaign Driver needs the command-line tools its instructions call (python3). Our summary lists: Python 3; A scope file naming the target; Scanning and exploitation tools such as nmap and msfconsole.

Does CTF Campaign Driver access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is CTF Campaign Driver safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CTF Campaign Driver use?

CTF Campaign Driver is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CTF Campaign Driver use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CTF Campaign Driver?

Skills that share tags, products or a category with CTF Campaign Driver: Add Community Skill (samugit83/redamon, 2.9k stars), Exploiting Ms17 010 Eternalblue Vulnerability (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars) and Insecure Deserialization Playbook (PentesterFlow/agent, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CTF Campaign Driver?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.