CTF ZIP Archive Key Recovery
zhaoxuya520/reverse-skill
Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.
Ensures codebase deliverables are properly archived into a ZIP file before marking task complete
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverable --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .claude/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .claude/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverableType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverable --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .agents/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .agents/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverable --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .cursor/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .cursor/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HKUDS/OpenSpace.git --path benchmarks/gdpval/skills/finalize-zip-deliverable--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverable --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .gemini/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .gemini/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverableInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .github/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .github/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .github/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HKUDS/OpenSpace finalize-zip-deliverable --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/benchmarks/gdpval/skills/finalize-zip-deliverable .opencode/skills/finalize-zip-deliverable && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "finalize-zip-deliverable" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/finalize-zip-deliverable into .opencode/skills/finalize-zip-deliverable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finalize-zip-deliverable", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
finalize-zip-deliverableEnsures codebase deliverables are properly archived into a ZIP file before marking task complete
Finalize Zip Deliverable is an agent skill from HKUDS/OpenSpace. Ensures codebase deliverables are properly archived into a ZIP file before marking task complete
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
The repository describes itself as: "OpenSpace: The Skill Management Layer for AI Agents" -- https://open-space.cloud/. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3827781. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Finalize Zip Deliverable loads about 1.5k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 740 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
**Missing Files:** Hidden files (e.g., `.env`, `.gitignore`) may need explicit inclusion depending on requirements.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HKUDS/OpenSpace at commit 3827781, republished under its MIT licence (© HKUDS). 740 words, ~1,510 tokens.
.claude/skills/finalize-zip-deliverable/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.CRITICAL: This skill defines a MANDATORY workflow that MUST be executed before any task can be marked complete. Task completion is BLOCKED until ZIP verification passes.
Agents often assume that creating the project directory and files constitutes task completion. However, many tasks require a single downloadable artifact (ZIP file) for delivery. You are forbidden from declaring task completion until the ZIP artifact is created and verified.
ITERATION-AWARE PRIORITY: If the agent's iteration count approaches the task limit (e.g., iteration 25 of 30), ZIP creation MUST be elevated to highest priority. Do not continue adding features or refining code—execute the ZIP command immediately with whatever files exist.
TRIGGER CONDITION: When iteration count reaches 25/30 (or 80% of any iteration limit), activate the following protocol:
RATIONALE: A partial ZIP deliverable is ALWAYS preferable to zero deliverable. Never exhaust iterations without creating the required artifact.
When triggered by the early warning system, execute this fallback procedure:
# Create ZIP with whatever files currently exist
zip -r project_fallback.zip ./project/ 2>/dev/null || zip -r project_fallback.zip ./*
# Verify creation succeeded
ls -lh project_fallback.zipAcceptable fallback scenarios:
Unacceptable outcome: No ZIP file created due to iteration exhaustion.
Throughout task execution, track your iteration count relative to the task limit.
Before archiving, confirm that all intended source code, configuration files, and assets exist within the project directory.
package.json, README.md, source files) are present.Run the compression command explicitly as a dedicated action. Do not bundle this step with code generation.
zip -r <output_filename>.zip <project_directory>/Example:
zip -r project.zip ./projectConfirm the ZIP file was successfully created and is not empty.
ls -lh <output_filename>.zipunzip -l <output_filename>.zipBEFORE declaring task complete, you MUST verify all items below. Task completion is BLOCKED until this checklist passes:
All required source code and configuration files exist in the project directory ITERATION STATUS CHECK: If approaching iteration limit (≥25/30), execute ZIP fallback immediately regardless of project completeness.
All required source code and configuration files exist in the project directory (OR fallback triggered due to iteration limit)
zip -r <output_filename>.zip <project_directory>/ command has been executed
If in fallback mode, ZIP filename includes fallback suffix for clarity (e.g., project_fallback.zip)
ZIP file exists at the expected path (verify with ls -lh <output_filename>.zip)
ZIP file size is greater than 0 bytes
ZIP contents have been inspected (optional but recommended: unzip -l <output_filename>.zip)
COMPLETION RULE: The zip command MUST be executed as the FINAL step before any <COMPLETE> declaration. Never declare completion after file generation without first creating and verifying the ZIP artifact.
ITERATION OVERRIDE RULE: If iteration count ≥25/30, the ZIP command becomes the IMMEDIATE next action, superseding all other pending work.
FAILURE CONSEQUENCE: Declaring task complete without ZIP verification = task failure. Directory creation alone does NOT equal deliverable completion. CRITICAL FAILURE: Exhausting all iterations without ZIP creation = complete task failure regardless of code quality.
.env, .gitignore) may need explicit inclusion depending on requirements.zip utility is available in the execution environment. If not, install it or use an alternative (e.g., tar).zip command executed successfully.© HKUDS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in benchmarks/gdpval/skills/finalize-zip-deliverable of HKUDS/OpenSpace.
Open the folder on GitHubat commit 3827781
Finalize Zip Deliverable next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Finalize Zip Deliverable this skillHKUDS/OpenSpace | 7.8k | — | ~1.5k | Automated safety check: Notes | MIT | |
| CTF ZIP Archive Key Recoveryzhaoxuya520/reverse-skill | 40k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| OpenSpec Bulk Change ArchiverFission-AI/OpenSpec | 71k | 2 repos | ~5.6k | Automated safety check: Pass | MIT | |
| Finalize Agent Promptgithub/awesome-copilot | 40k | 1 repos | ~224 | Automated safety check: Pass | MIT | |
| Implementation Final Reviewopenai/openai-agents-python | 30k | — | ~2k | Automated safety check: Pass | MIT | |
| Zip Formatadamhathcock/sharpcompress | 2.6k | — | ~613 | Automated safety check: Pass | MIT |
zhaoxuya520/reverse-skill
Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.
Fission-AI/OpenSpec
Archives several completed OpenSpec changes in one operation, checking the codebase to resolve spec conflicts rather than archiving blindly.
github/awesome-copilot
Finalize prompt file using the role of an AI agent to polish the prompt for the end user.
openai/openai-agents-python
Review completed implementation changes before final verification.
adamhathcock/sharpcompress
Reference the ZIP/ZIP64/PKWARE APPNOTE archive container format.
garrytan/gbrain
Import AI-assistant chat exports (ChatGPT, Claude, Perplexity) and agent session transcripts into the brain as one dated page per conversation under conversations/, validate each page against the…
HKUDS/OpenSpace
Walks through producing a master audio track plus stems in Python, from checking a reference file and timing sections by BPM to effects, a zip archive and final verification.
HKUDS/OpenSpace
Handle cascading data retrieval tool failures by falling back to embedded knowledge generation
HKUDS/OpenSpace
Gives an agent a workaround when its code-execution sandbox keeps failing: save the Python script to a file and run it through the shell instead.
HKUDS/OpenSpace
A recovery routine for agents whose sandboxed code runner keeps failing: save the Python script to disk, then run it through the shell and read the output.
HKUDS/OpenSpace
Fallback ladder for failed sandboxed code runs, plus the habit of fixing the working directory first so generated files land in the right place.
HKUDS/OpenSpace
Fallback workflow for executing Python code when executecodesandbox fails repeatedly
Ensures codebase deliverables are properly archived into a ZIP file before marking task complete. Finalize Zip Deliverable is an agent skill from HKUDS/OpenSpace.
Run `npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a claude-code`. Or copy the skill folder (benchmarks/gdpval/skills/finalize-zip-deliverable in HKUDS/OpenSpace) into .claude/skills/finalize-zip-deliverable in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a codex`. Or copy the skill folder (benchmarks/gdpval/skills/finalize-zip-deliverable in HKUDS/OpenSpace) into .agents/skills/finalize-zip-deliverable in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HKUDS/OpenSpace --skill finalize-zip-deliverable -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/finalize-zip-deliverable, .gemini/skills/finalize-zip-deliverable, .github/skills/finalize-zip-deliverable and .opencode/skills/finalize-zip-deliverable in your project.
SKILL.md names no scripts, command-line tools or credentials: Finalize Zip Deliverable is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Finalize Zip Deliverable is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Finalize Zip Deliverable: CTF ZIP Archive Key Recovery (zhaoxuya520/reverse-skill, 40k stars), OpenSpec Bulk Change Archiver (Fission-AI/OpenSpec, 71k stars), Finalize Agent Prompt (github/awesome-copilot, 40k stars) and Implementation Final Review (openai/openai-agents-python, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HKUDS (a GitHub organization) maintains it in HKUDS/OpenSpace, which has 7,750 GitHub stars. The repository holds 199 skills in this directory. The repository was last updated on August 12, 2026.
Source: HKUDS/OpenSpace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.