Ctf Source Audit
wgpsec/AboutSecurity
CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/type-juggling .claude/skills/type-juggling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .claude/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-jugglingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/type-juggling .agents/skills/type-juggling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .agents/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/type-juggling .cursor/skills/type-juggling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .cursor/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/type-juggling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/type-juggling .gemini/skills/type-juggling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .gemini/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-jugglingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/type-juggling .github/skills/type-juggling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .github/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/type-juggling .opencode/skills/type-juggling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "type-juggling" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/type-juggling into .opencode/skills/type-juggling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "type-juggling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
type-jugglingPHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
Type Juggling is an agent skill from langbyyi/CyberStrikeAI-SRC. PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Capture the flag. It works with PHP. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
phpFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Type Juggling loads about 2.9k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 895 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 895 words, ~2,943 tokens.
.claude/skills/type-juggling/SKILL.md (or your agent's skills folder).AI LOAD INSTRUCTION: PHP
==coercion, magic hashes (0e…), HMAC/hash loose checks, NULL from bad types, and CTF-stylestrcmp/json_decode/intvaltricks. Use strict routing: map the sink (==vshash_equals), PHP major version, and whether both operands are attacker-controlled. 中文路由:遇到 PHP 登录/签名/md5($_GET['x'])==md5($_GET['y'])类题目或代码,优先读本 skill;若已用hash_equals/===则本路径通常不成立。
First-pass goal: prove the server branch treats unequal secrets/tokens as equal via coercion, not guess the real password.
password[]=x
password=
0
0e12345
240610708
QNKCDZO
true
[]
{"password":true}
admin%00php -r in lab)<?php
// Loose compare probes — run in target PHP major version if possible
var_dump('0e123' == '0e999');
var_dump('123a' == 123);
var_dump(md5('240610708') == md5('QNKCDZO'));| 线索 | 下一步 |
|---|---|
源码里出现 == 比较密码、token、HMAC 结果 | 走 Section 1–3 |
md5($a) == md5($b) 或 sha1 松散比较 | Section 2 魔法哈希 |
hash_hmac(...) != '0' 或和 "0" 比较 | Section 3 |
strcmp、json_decode(..., true)、intval | Section 5 |
==) — TRUTH TABLE & VERSIONSPHP compares operands with type juggling unless you use === or hash_equals() for secrets.
| Expression | Result | Mechanism (short) |
|---|---|---|
'0010e2' == '1e3' | true | Both strings look numeric → compared as floats; both parse to 1000.0 (not zero — common exam trap; see next row for real “both zero”) |
'0e462097431906509019562988736854' == '0e830400451993494058024219903391' | true | Both parse as 0.0 in scientific notation |
'123a' == 123 | true | String cast to int stops at first non-digit → 123 |
'abc' == 0 | true (PHP 7.x and earlier) | Non-numeric string compared to int → string becomes 0 |
'' == 0 | true | Empty string → 0 |
'' == false | true | both “falsy” in loose rules |
false == NULL | true | loose equality |
0 == false | true | loose equality |
'' == 0 == false == NULL | true (chain) | Each adjacent pair is true under == (''==0, 0==false, false==NULL) — classic “falsy” chain |
'0' == false | true | String '0' is the only non-empty string that compares as false to boolean |
'php' == 0 | false (PHP 8+) | PHP 8: non-numeric string no longer equals 0 |
| Topic | PHP 5.x / 7.x (typical) | PHP 8.0+ |
|---|---|---|
0 == "foo" | true (string → 0) | false |
String-to-number for "123a" | Still truncates for (int) / numeric compare in many == paths | Same idea for numeric strings; non-numeric vs int fixed as above |
md5([]) / sha1([]) | May warn / NULL-like behavior in older patterns | TypeError for wrong types — kills classic [] tricks unless error handling collapses to NULL |
Tester takeaway: always note PHP version from headers, X-Powered-By, or fingerprint; a payload that works on PHP 7 may fail on PHP 8.
hash_equals((string)$expected, (string)$actual); // timing-safe, strict string
// or
$expected === $actual;0e… + digits only)When both sides are hex-looking hash strings that match ^0e[0-9]+$, PHP treats them as floats in scientific notation → value 0.0. Then md5(A) == md5(B) is true even though digests differ as strings.
| Algorithm | Example input | Digest (starts with 0e + all decimal digits) |
|---|---|---|
| MD5 | 240610708 | 0e462097431906509019562988736854 |
| MD5 | QNKCDZO | 0e830400451993494058024219903391 |
| SHA-1 | 10932435112 | 0e07766915004133176347055865026311692244 |
| SHA-224 | (brute-force / precomputed) | Example form: 0e + decimal digits only → == with another such string is true |
| SHA-256 | (brute-force / precomputed) | Same pattern: only strings matching ^0e\d+$ collide under == |
Why it works: md5('240610708') == md5('QNKCDZO') → both sides match ^0e[0-9]+$ → both interpreted as 0.0 == 0.0 → true.
if (md5($_GET['a']) == md5($_GET['b']) && $_GET['a'] != $_GET['b']) {
// intended: different strings, same md5 (impossible for md5)
// actual: two different strings whose *digests* are magic hashes
}?a=240610708&b=QNKCDZOFor SHA-224/256, treat as search problem: brute-force inputs until digest matches ^0e\d+$; pair two distinct inputs. Longer hashes = harder; MD5/SHA1 examples above are the usual teaching set.
"0" OR 0)If logic uses loose inequality against a constant:
if (hash_hmac('md5', $data, $key) != '0') { /* ok */ }
// or == 0, == false with string "0e...", etc.Brute-force $data (e.g. timestamp, nonce, counter) until hash_hmac output matches ^0e[0-9]+$ (for MD5 output) or the code’s specific loose rule — then the hash may compare equal to 0 or to another magic digest under ==.
0e digest for a numeric message)| Concept | Example |
|---|---|
| Message type | Unix timestamp, incrementing id, millisecond clock |
| Timestamp brute-force pattern | Tutorials sometimes cite 1539805986 → 0e772967136366835494939987377058 as a magic-hash style example; md5('1539805986') does not yield that digest in stock PHP — use the idea (scan timestamps / counters until output matches ^0e[0-9]+$) and always verify against the exact function + key in the target code. |
| Goal | Find $data such that hash_hmac('md5', $data, $key) matches ^0e[0-9]+$ |
| Note | Without knowing $key, you may still brute $data if algorithm/output are visible in a oracle; CTFs often leak or fix key |
# Conceptual: try many timestamps
for t in range(T0, T1):
if re.fullmatch(r'0e\d+', hmac_md5(str(t), key)):
use tMitigation: hash_equals($mac, $expected) + fixed-length hex/binary encoding; never compare HMAC to bare "0".
Invalid types can yield NULL on the compared side; loose equality to another NULL or coerced value may pass.
| Call | Typical PHP 7/8 behavior |
|---|---|
md5([]) | PHP 8: TypeError; older: warnings / not reliable across versions |
sha1([]) | Same |
| Idea | If error handler or custom wrapper converts failures to NULL, then NULL == NULL or NULL == sha1("x") if other side is also NULL |
// CTF / broken code mental model:
@sha1($_GET['x']) == @sha1($_GET['y']); // if both error to NULL → trueReal audits: look for @, custom try/catch that sets hash to null, or user input passed where a string is required.
strcmp / strcasecmp with arraysstrcmp([], "password"); // NULL in PHP 7/8 (invalid args)
// NULL == 0 → true in loose compare if code does:
if (strcmp($_GET['p'], $secret) == 0)Payload:
?p[]=1intval bypass// Hex: base 0 lets PHP interpret 0x prefix (version-dependent; always verify)
intval("0x1A", 0); // → 26
// Octal: leading 0 can be parsed as octal with base 0
intval("010", 0); // → 8 (classic teaching example; confirm on target PHP)
// Scientific notation: intval() alone stops at 'e'; cast via float first
intval((float) "1e2"); // → 100?id=0x1A
?id=010
?id=1e2json_decode + true for associative array auth{"password": true}$j = json_decode($input, true);
if ($j['password'] == $stored_string) // true == "nonempty" often true — see PHP loose rulesis_numeric + loose compareis_numeric("0e12345"); // true
"0e12345" == 0; // true (scientific notation → 0.0)Unserialize user input into objects whose __toString or properties feed into md5($obj) or loose compare — combine with magic hash strings on properties (CTF). Look for unserialize($_…) near == on hashes.
+------------------+
| PHP loose compare|
| or hash == hash? |
+--------+---------+
|
+-------------+-------------+
| |
+------v------+ +------v------+
| Uses === or | | Uses == or |
| hash_equals | | strcmp == 0 |
+------+------+ +------+-------+
| |
STOP (likely) +-----v-----+
| Operand |
| types? |
+-----+-----+
+--------------+---+--------------+
| | |
+------v------+ +-----v-----+ +-------v--------+
| Both numeric| | One int & | | Hash digests |
| strings 0e… | | one string| | both 0e\d+ ? |
+------+------+ +-----+-----+ +-------+--------+
| | |
MAGIC HASH STRING/INT MAGIC HASH
COLLISION JUGGLING (md5/sha1/…)
| | |
+------+-------+------------------+
|
+------v------+
| HMAC / MAC |
| vs "0" |
+------+------+
|
brute $data
for 0e… digest
|
+------v------+
| Arrays / |
| json true / |
| strcmp([]) |
+-------------+| Tool | Use |
|---|---|
Local php CLI | Reproduce == behavior for target major version |
| Static code review | Grep ==, != on crypto outputs; find missing hash_equals |
| CTF frameworks | Payload generators for magic hashes and 0e search |
Safety & scope: Use only on authorized targets (CTF, lab, written permission). This skill explains language semantics for defense and assessment — not a license to attack systems without consent.
© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/type-juggling of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 166ee1c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.
Type Juggling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Type Juggling this skilllangbyyi/CyberStrikeAI-SRC | 134 | 1 repos | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Ctf Source Auditwgpsec/AboutSecurity | 1.8k | — | ~1.4k | Automated safety check: Notes | None | |
| Ctf Flag Verificationwgpsec/AboutSecurity | 1.8k | — | ~644 | Automated safety check: Pass | None | |
| Ctf Web Reconwgpsec/AboutSecurity | 1.8k | — | ~624 | Automated safety check: Notes | None | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 936 | — | ~2.4k | Automated safety check: Pass | MIT |
wgpsec/AboutSecurity
CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式
wgpsec/AboutSecurity
CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL…
wgpsec/AboutSecurity
CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
RuoJi6/audit-skills
当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
langbyyi/CyberStrikeAI-SRC
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
langbyyi/CyberStrikeAI-SRC
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
langbyyi/CyberStrikeAI-SRC
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.
Works with
Categories
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC. Type Juggling is an agent skill from langbyyi/CyberStrikeAI-SRC. PHP type juggling and weak comparison (==) bypass.
Type Juggling fits situations like: HMAC/signature checks; token validation uses loose equality; numeric coercion; hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a claude-code`. Or copy the skill folder (skills/type-juggling in langbyyi/CyberStrikeAI-SRC) into .claude/skills/type-juggling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a codex`. Or copy the skill folder (skills/type-juggling in langbyyi/CyberStrikeAI-SRC) into .agents/skills/type-juggling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/type-juggling, .gemini/skills/type-juggling, .github/skills/type-juggling and .opencode/skills/type-juggling in your project.
Going by SKILL.md and its folder, Type Juggling needs the command-line tools its instructions call (php).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Type Juggling is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Type Juggling: Ctf Source Audit (wgpsec/AboutSecurity, 1.8k stars), Ctf Flag Verification (wgpsec/AboutSecurity, 1.8k stars), Ctf Web Recon (wgpsec/AboutSecurity, 1.8k stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 134 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.