Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .claude/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-forensics -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .agents/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-forensics -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .cursor/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-forensics -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .gemini/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-forensics -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .github/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-forensics -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "ctf-forensics" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/ctf-forensics into .opencode/skills/ctf-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ctf-forensics", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
ctf-forensics
GitHub stars
3.4k
Token cost
~9.2k tokens
SKILL.md length
3,387 words
Files
15
Skills in repo
6
Repo updated
First seen
Licence
MIT
At a glance
Provides digital forensics and signal analysis techniques for CTF challenges.
Works in 6 steps: USN Journal ($J) - File operations… → SAM registry - Account creation from key… → PowerShell history -… → …
Analyzing disk images
SKILL.md covers Prerequisites, Additional Resources, When to Pivot and Quick Start Commands, plus 18 more sections
Calls ffmpeg, git and python; reaches mempool.space; needs EV_KEY and SESSION_KEY
What it does
Ctf Forensics is an agent skill from ljagiello/ctf-skills. Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files and credentials.
Its SKILL.md is about 9.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files (for example `3d-printing.md`, `disk-advanced.md` and `disk-and-memory.md`). Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
It sits in Security, covering Capture the flag and Digital forensics. It works with Docker. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.
When your agent uses it
Analyzing disk images
Network captures
Cryptocurrency transactions
Windows registry
Example prompts
“Use the ctf-forensics skill to provide digital forensics and signal analysis techniques for CTF challenges”
“/ctf-forensics”
Requirements
Python 3
Docker
Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
2SAM registry - Account creation from key last_modified timestamps
3PowerShell history - ConsoleHost_history.txt (USN DATA_EXTEND = command timing)
4Defender MPLog - Separate log with threat detections and ASR events
5Prefetch - Program execution evidence
6User profile creation - First login time (profile dir in USN journal)
What it can do on your machine
Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves these tools, so the agent can use them without asking each time:
Bash
Read
Write
Edit
Glob
Grep
Task
WebFetch
WebSearch
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
ffmpeg
git
python
docker
pip
apt
brew
gem
pdftotext
adb
ffprobe
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
mempool.space
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
EV_KEY
SESSION_KEY
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compatibility
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
From compatibility in the SKILL.md frontmatter.
Context cost
Ctf Forensics loads about 9.2k tokens when it runs. Until then it costs about 108 tokens; SKILL.md has 3,387 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~108
When it runs· the whole SKILL.md, loaded when a task matches
~9.2k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: warnings
The automated check found patterns that need a careful read before installing.
WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:53
sh recovery, browser artifact analysis (Chrome/Chromium/Firefox history, cookies, downloads, local storage, session rest
NoteRuns commands with sudoSKILL.md:78
sudo mount -o loop,ro image.dd /mnt/evidence
NoteRuns commands with sudoSKILL.md:181
sudo mount -o loop,ro image.dd /mnt/evidence
WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:267
- **Chrome/Edge:** Decrypt `Login Data` SQLite with AES-GCM using DPAPI master key
NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/ctf-forensics/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
ctf-forensics
description
Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files and credentials.
1149 - RDP auth succeeded (RemoteConnectionManager, has source IP)
python
import Evtx.Evtx as evtx
with evtx.Evtx("Security.evtx") as log:
for record in log.records():
print(record.xml())
See windows.md for full event ID tables, registry analysis, SAM parsing, USN journal, and anti-forensics detection.
NTFS Alternate Data Streams (ADS): Hidden data attached to files via named NTFS streams. Invisible to dir/Explorer. Detect with fls -r image.dd | grep ":", extract with icat. See windows.md.
When Logs Are Cleared
If attacker cleared event logs, use these alternative sources:
JPEG DQT LSB: Unused quantization tables (ID 2, 3) carry LSB-encoded data; access via Image.open().quantization and extract bit 0 from each of 64 values
Multi-track audio subtraction: Two nearly-identical audio tracks in MKV/video; sox -m a0.wav "|sox a1.wav -p vol -1" diff.wav cancels shared content, flag appears in spectrogram of difference signal (5-12 kHz band)
Packet interval timing: Identical packets with two distinct interval values (e.g., 10ms/100ms) encode binary; filter by interface, compute inter-packet deltas, threshold to bits
Advanced PDF stego (Nullcon 2026 rdctd): Six techniques -- invisible text separators, URI annotations with escaped braces, Wiener deconvolution on blurred images, vector rectangle QR codes, compressed object streams (mutool clean -d), document metadata fields.
See steganography.md for full PDF steganography techniques and code.
See disk-and-memory.md for full Volatility plugin reference, VM forensics, and VMware snapshots. See disk-advanced.md for deleted partition recovery, ZFS forensics, and ransomware analysis.
Windows Password Hashes
bash
# Extract with impacket, crack with hashcat -m 1000
python -c "from impacket.examples.secretsdump import *; SAMHashes('SAM', LocalOperations('SYSTEM').getBootKey()).dump()"
Docker image forensics: Config JSON preserves ALL RUN commands even after cleanup. tar xf app.tar then inspect config blob. See linux-forensics.md.
Linux attack chains: Check auth.log, .bash_history, recent binaries, PCAP. See linux-forensics.md.
RAID 5 XOR recovery: Two disks of a 3-disk RAID 5 → XOR byte-by-byte to recover the third: bytes(a ^ b for a, b in zip(disk1, disk3)). See disk-advanced.md.
GIMP raw memory dump visual inspection: When Volatility fails, open .dmp in GIMP as raw RGB data at monitor width (~1920); scroll to find framebuffer screenshots of user's desktop. See disk-and-memory.md.
Kyoto Cabinet hash DB forensics: Recover key ordering from KC hash database with zeroed keys by inserting sequential probe keys and binary-diffing to find which hash slot each overwrites. See disk-advanced.md.
PowerShell ransomware: Extract scripts from minidump, find AES key, decrypt SMTP attachment. See disk-and-memory.md.
Linux ransomware + memory dump: If Volatility is unreliable, recover AES key via raw-memory candidate scanning and magic-byte validation; re-extract zip cleanly to avoid missing files/false negatives. See disk-advanced.md.
Deleted partitions:testdisk or kpartx -av. See disk-advanced.md.
ZFS forensics: Reconstruct labels, Fletcher4 checksums, PBKDF2 cracking. See disk-advanced.md.
BSON reconstruction: Reassemble BSON (Binary JSON) documents from raw bytes; parse with bson Python library. See disk-and-memory.md.
TrueCrypt mounting: Mount TrueCrypt/VeraCrypt volumes with known password using veracrypt --mount or cryptsetup open --type tcrypt. See disk-and-memory.md.
Caps-lock LED Morse from video: Track caps-lock LED pixel across security camera frames with OpenCV; on/off durations encode Morse code (short=dot, long=dash). See signals-and-hardware.md.
I2C protocol decoding: Decode I2C bus captures (SDA/SCL lines) to extract data from EEPROM or sensor communications. See signals-and-hardware.md.
Punched card OCR: Decode IBM-29 punch card images by mapping hole positions to characters using standard encoding grid. See signals-and-hardware.md.
USB HID mouse drawing: Render relative HID movements per draw mode as bitmap; separate modes, skip pen lifts, scale 5-8x. See peripheral-capture.md.
Side-channel power analysis: Multi-dimensional power traces (positions × guesses × traces × samples). Average across traces, find sample with max variance, select guess with max power at leak point. See signals-and-hardware.md.
Packet interval timing: Binary data encoded as inter-packet delays in PCAP. Two interval values = two bit values. See network-advanced.md.
BMP bitplane QR: Extract bitplanes 0-2 per RGB channel with NumPy; hidden QR often in bit 1 (not bit 0). See stego-image.md.
Image puzzle reassembly: Edge-match pixel differences between piece borders, greedy placement in grid. See stego-image.md.
DeepSound audio stego with password cracking: Extract hash with deepsound2john.py, crack with John, retrieve hidden files from WAV; always check both spectrogram and DeepSound. See stego-advanced.md.
QR code reconstruction from curved reflection: Manually reconstruct QR from glass sphere reflection in video; flip, de-warp, use known plaintext prefix to fix early bytes, high ECC corrects the rest. See steganography.md.
Audio metadata octal: Exiftool comment with underscore-separated octal numbers → decode to ASCII/base64. See stego-advanced.md.
G-code visualization: Side projections (XZ/YZ) reveal text. See 3d-printing.md.
Git directory recovery:gitdumper.sh for exposed .git dirs. See linux-forensics.md.
KeePass v4 cracking: Standard keepass2john lacks v4/Argon2 support; use ivanmrsulja/keepass2john fork or keepass4brute. Generate wordlists with cewl. See linux-forensics.md.
Cross-channel multi-bit LSB: Different bit positions per RGB channel (R[0], G[1], B[2]) encode hidden data. See stego-advanced.md.
F5 JPEG DCT detection: Ratio of ±1 to ±2 AC coefficients drops from ~3:1 to ~1:1 with F5; sparse images need secondary ±2/±3 metric. See stego-image.md.
PNG unused palette stego: Unused PLTE entries (not referenced by pixels) carry hidden data in red channel values. See stego-image.md.
Keyboard acoustic side-channel: MFCC features from keystroke audio + KNN classification against labeled reference. 10ms window captures impact transient. See signals-and-hardware.md.
TCP flag covert channel: 6 TCP flag bits (FIN/SYN/RST/PSH/ACK/URG) = values 0-63, encoding base64 characters. Nonsensical flag combos on a consistent dest port = covert data. See network-advanced.md.
Brotli decompression bomb seam: Compressed bomb has repeating blocks; flag breaks the pattern at a seam. Compare adjacent blocks to find discontinuity, decompress only that region. See network-advanced.md.
Git reflog/fsck squash recovery:git rebase --squash leaves orphaned objects recoverable via git fsck --unreachable --no-reflogs. See linux-forensics.md.
DNS trailing byte binary: Extra bytes (0x30/0x31) appended after DNS question structure encode binary bits; 8-bit MSB-first chunks → ASCII. See network-advanced.md.
Fake TLS + mDNS key + printability merge: TCP stream disguised as TLS hides ZIP; XOR key from mDNS TXT record; merge two decrypted arrays by selecting printable characters. See network-advanced.md.
Seed-based pixel permutation stego: Deterministic pixel shuffle (Fisher-Yates with known seed) + multi-bitplane interleaved LSB extraction from Y channel → hidden QR code. See stego-image.md.
BTRFS snapshot recovery: Deleted files persist in BTRFS snapshots/alternate subvolumes. mount -o subvol=@backup accesses historical copies. See disk-recovery.md.
JPEG XL TOC permutation: JXL's progressive TOC permutation controls tile convergence order during partial decode. Truncate at increasing offsets, measure which tiles converge first → convergence order encodes flag. See stego-advanced-2.md.
Kitty terminal graphics:ESC_G protocol embeds zlib-compressed RGB image data in base64 chunks. Strip escape sequences, concatenate, decompress, reconstruct. See steganography.md.
ANSI escape sequence stego: Flag text interleaved between ANSI color codes and braille characters. Invisible when rendered; extract by stripping escape sequences and non-ASCII. See steganography.md.
Autostereogram solving: Duplicate layer, difference blend, shift horizontally ~100px to reveal hidden 3D text. See steganography.md.
Two-layer byte+line interleaving: Two files byte-interleaved, then scanlines interleaved. Deinterleave even/odd bytes first (valid images), then even/odd lines. See steganography.md.
SMB RID recycling: Guest auth + LSARPC LsaLookupSids with incrementing RIDs enumerates AD accounts from PCAP. See network-advanced.md.
Timeroasting (MS-SNTP): NTP requests with machine RIDs extract HMAC-MD5 hashes from DC; crack with hashcat -m 31300. See network-advanced.md.
Android forensics: Extract APK with adb pull, analyze with apktool, check shared_prefs/ and SQLite databases in /data/data/<package>/. See disk-and-memory.md.
Docker container forensics:docker save exports layered tars; deleted files persist in earlier layers. docker history --no-trunc reveals build secrets. See disk-and-memory.md.
APFS snapshot recovery: Copy-on-write filesystem preserves historical file states in snapshots; use icat with different XID block offsets to read inodes across transaction IDs. See disk-advanced.md.
Windows KAPE triage: Pre-collected artifact ZIPs; start with PowerShell history → Amcache → MFT → registry hives. See disk-and-memory.md.
WordPerfect macro XOR:.wcm files contain macros with embedded encrypted data; XOR formula (a+b)-2*(a&b) = bitwise XOR. See disk-advanced.md.
TLS master key from coredump: Search coredump for session ID (from Wireshark handshake); read 48 bytes before it as master key. Create Wireshark pre-master-secret log file. See network.md.
Corrupted git blob repair: Single-byte corruption changes SHA-1; brute-force each byte position (256 × file_size) verifying with git hash-object. See linux-forensics.md.
Split archive reassembly from PCAP: Same-sized HTTP-transferred files with MD5-hash names are archive fragments; order by Apache directory listing timestamps, concatenate, extract password from TCP chat stream. See network.md.
Video frame accumulation: Video with flashing images at various positions; composite all frames (per-pixel maximum) reveals hidden QR code or image. See stego-advanced-2.md.
Reversed audio: Garbled audio that sounds like speech played backwards; sox audio.wav reversed.wav reverse or Audacity Effect → Reverse reveals hidden message. See stego-advanced-2.md.
Multi-stream video container stego: MP4/MKV with multiple video streams; default stream is a red herring, flag in secondary stream. ffprobe -hide_banner file.mp4 to enumerate, ffmpeg -i file.mp4 -map 0:1 -frames:v 1 flag.jpg to extract. See steganography.md.
FAT16 free space recovery: Flag hidden in unallocated clusters of FAT16 filesystem. Parse FAT table, enumerate free clusters (entry = 0x0000), read data region. See disk-recovery.md.
FAT16 deleted file recovery (fls/icat): FAT deletion replaces first byte of directory entry with 0xE5 but data remains. fls -r -d image.img lists deleted entries, icat image.img <inode> recovers by inode. See disk-recovery.md.
Ext2 orphaned inode recovery: Deleted file leaves orphaned inode; e2fsck -y disk.img reconnects to /lost+found. Also use debugfslsdel or icat. See disk-recovery.md.
Linux input_event keylogger parsing: 24-byte struct input_event binary dump; filter type==1 (EV_KEY), value==1 (press), map keycodes via input-event-codes.h. See signals-and-hardware.md.
VBA macro cell data to binary: Excel cells with numeric values; VBA CByte((val-78)/3) transforms to ELF bytes. Reimplement in Python, never run the macro. See linux-forensics.md.
RGB parity steganography: Sum R+G+B per pixel; even=white, odd=black renders hidden binary bitmap. See stego-image.md.
Hidden PDF objects: Unreferenced content stream objects not in /Kids array. Add to /Kids, increment /Count, re-render. See network-advanced.md.
Arnold's Cat Map descrambling: Periodic chaotic transform on square images; iterate forward map until original reappears. Period divides 3*N. See stego-advanced-2.md.
Python in-memory source recovery: Attach pyrasite-shell to running Python process, decompile func_code objects with uncompyle6 (Python <=3.8) or pycdc (Python 3.9+), dump globals() for secrets. See linux-forensics.md.
HFS+ resource fork recovery: Hidden data in HFS+ Resource Forks invisible to binwalk/foremost; use HFSExplorer + 010 Editor HFS template to extract extent records. See disk-advanced.md.
Serial UART from WAV audio: Square wave in audio encodes UART serial data; determine baud rate, parse start/stop bits, decode LSB-first byte frames. See signals-and-hardware.md.
High-resolution SSTV demodulation: Standard SSTV decoders fail on high-sample-rate recordings; use manual FM demodulation via arccos + differentiation. See stego-advanced-2.md.
Corrupted ZIP header repair: Fix filename length fields in both Local File Header (offset 26) and Central Directory (offset 28); fallback: brute-force raw deflate at candidate offsets. See disk-recovery.md.
SQLite edit history reconstruction: Replay insert/remove diffs from SQLite diff table to reconstruct document at every intermediate state; flag may have been typed then deleted. See disk-advanced.md.
MJPEG FFD9 trailing byte stego: Extra bytes after JPEG EOI marker (FFD9) in MJPEG frames create invisible covert channel; split on FFD8, extract post-FFD9 data. See stego-advanced-2.md.
USB MIDI Launchpad grid reconstruction: MIDI Note On/Off in USB PCAP maps to 8x8 Launchpad grid (key = row*16 + col); reconstruct visual patterns from button press sequences. See signals-and-hardware.md.
SMB RID Recycling via LSARPC (Midnight 2026)
Enumerate AD accounts from PCAP by analyzing LSARPC LsaLookupSids calls with sequential RIDs after Guest auth. Filter: dcerpc.cn_bind_to_str contains lsarpc.
Quick path:tshark --export-objects http,/tmp/objects extracts uploaded files instantly. Check for multipart POST uploads, unusual User-Agent strings, and exfiltrated files (images with flag text). See network.md.
Ctf Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…
Provides digital forensics and signal analysis techniques for CTF challenges. Ctf Forensics is an agent skill from ljagiello/ctf-skills. Provides digital forensics and signal analysis techniques for CTF challenges.
When should I use Ctf Forensics?
Ctf Forensics fits situations like: analyzing disk images; network captures; cryptocurrency transactions; windows registry.
How do I install Ctf Forensics in Claude Code?
Run `npx skills add ljagiello/ctf-skills --skill ctf-forensics -a claude-code`. Or copy the skill folder (ctf-forensics in ljagiello/ctf-skills) into .claude/skills/ctf-forensics in your project. Claude Code loads it when a task matches its description.
How do I install Ctf Forensics in Codex?
Run `npx skills add ljagiello/ctf-skills --skill ctf-forensics -a codex`. Or copy the skill folder (ctf-forensics in ljagiello/ctf-skills) into .agents/skills/ctf-forensics in your project. Codex loads it when a task matches its description.
Can I use Ctf Forensics in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill ctf-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ctf-forensics, .gemini/skills/ctf-forensics, .github/skills/ctf-forensics and .opencode/skills/ctf-forensics in your project.
What does Ctf Forensics need to run?
Going by SKILL.md and its folder, Ctf Forensics needs the command-line tools its instructions call (ffmpeg, git, python, docker, pip and apt) and credentials named EV_KEY and SESSION_KEY. Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation..
Does Ctf Forensics access the network?
SKILL.md names 1 domain. In commands or code: mempool.space; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Ctf Forensics safe to install?
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
What licence does Ctf Forensics use?
Ctf Forensics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Ctf Forensics use?
About 9.2k tokens (SKILL.md is roughly 37k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Ctf Forensics?
Skills that share tags, products or a category with Ctf Forensics: Building Incident Timeline With Timesketch (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Codeql (elastic/kibana, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Ctf Forensics?
ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,416 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.
Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.