Reverse Flow
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ljagiello/ctf-skills solve-challenge --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/solve-challenge .claude/skills/solve-challenge && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .claude/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ljagiello/ctf-skills/tree/main/solve-challengeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ljagiello/ctf-skills solve-challenge --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/solve-challenge .agents/skills/solve-challenge && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .agents/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ljagiello/ctf-skills solve-challenge --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/solve-challenge .cursor/skills/solve-challenge && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .cursor/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ljagiello/ctf-skills.git --path solve-challenge--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ljagiello/ctf-skills solve-challenge --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/solve-challenge .gemini/skills/solve-challenge && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .gemini/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ljagiello/ctf-skills solve-challengeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/solve-challenge .github/skills/solve-challenge && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .github/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ljagiello/ctf-skills solve-challenge --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/solve-challenge .opencode/skills/solve-challenge && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "solve-challenge" agent skill from https://github.com/ljagiello/ctf-skills/tree/main/solve-challenge into .opencode/skills/solve-challenge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solve-challenge", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
solve-challengeSolves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.
Solve Challenge is an agent skill from ljagiello/ctf-skills. Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine where to start. Do not use it when the category is already clear and a specialized skill can be invoked directly; this is the dispatcher and recon entrypoint, not the deepest reference for category-specific techniques.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf- skills.
It sits in Security, covering Capture the flag. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepTaskWebFetchWebSearchSkillFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashcurlpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CTF_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills.
From compatibility in the SKILL.md frontmatter.
Solve Challenge loads about 2.3k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 888 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, SkillAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ljagiello/ctf-skills at commit c332c7b, republished under its MIT licence (© ljagiello). 888 words, ~2,293 tokens.
.claude/skills/solve-challenge/SKILL.md (or your agent's skills folder).You're a skilled CTF player. Your goal is to solve the challenge and find the flag.
Two setup strategies depending on your workflow:
Use the central installer entrypoint:
bash scripts/install_ctf_tools.sh allRun a narrower mode when you only want one tool group:
bash scripts/install_ctf_tools.sh python
bash scripts/install_ctf_tools.sh apt
bash scripts/install_ctf_tools.sh brew
bash scripts/install_ctf_tools.sh gems
bash scripts/install_ctf_tools.sh go
bash scripts/install_ctf_tools.sh manualThe full package lists now live in scripts/install_ctf_tools.sh.
Each category skill's SKILL.md has a Prerequisites section listing only the tools needed for that category. Install as you go.
If the CTF platform URL is known, check if it runs CTFd and switch to API-driven navigation:
# Detect CTFd (look for /api/v1/ and /themes/core/)
curl -s "$CTF_URL/api/v1/" | head -5
curl -s "$CTF_URL" | grep -oE '/themes/core/'If CTFd is detected, ask the user for their API token (generated from CTFd Settings > Access Tokens). The token is not provided by default — the user must create one in the CTFd web UI first. Once provided, set the environment variables and proceed via API:
export CTF_URL="https://ctf.example.com"
export CTF_TOKEN="ctfd_..." # Ask user for thisInvoke /ctf-misc and load its ctfd-navigation.md for the full API reference and Python client class.
file * on everythingstrings, xxd | head, binwalk, checksec on binariesnc) to understand what they expectDetermine the primary category, then invoke the matching skill.
By file type:
.pcap, .pcapng, .evtx, .raw, .dd, .E01 -> forensics.elf, .exe, .so, .dll, binary with no extension -> reverse or pwn (check if remote service provided -- if yes, likely pwn).py, .sage, .txt with numbers -> crypto.apk, .wasm, .pyc -> reverse.safetensors, .pt, .pth, .bin, .onnx -> ai-mlBy challenge description keywords:
By service behavior:
Once you identify the category, invoke the matching skill to get specialized techniques:
| Category | Invoke | When to Use |
|---|---|---|
| Web | /ctf-web | XSS, SQLi, SSTI, SSRF, JWT, file uploads, prototype pollution |
| Pwn | /ctf-pwn | Buffer overflow, format string, heap, ROP, sandbox escape |
| Crypto | /ctf-crypto | RSA, AES, ECC, PRNG, ZKP, classical ciphers |
| Reverse | /ctf-reverse | Binary analysis, game clients, VMs, obfuscated code |
| Forensics | /ctf-forensics | Disk images, memory dumps, event logs, stego, network captures |
| OSINT | /ctf-osint | Social media, geolocation, DNS, public records |
| Malware | /ctf-malware | Obfuscated scripts, C2 traffic, PE/.NET analysis |
| AI/ML | /ctf-ai-ml | Model weights (.safetensors, .pt, .pth, .bin, .onnx), prompt injection, LoRA adapters, adversarial examples |
| Misc | /ctf-misc | Jails, encodings, RF/SDR, esoteric languages, constraint solving |
You can also invoke /ctf-<category> to load the full skill instructions with detailed techniques.
If your first approach doesn't work:
Common multi-category patterns:
After solving the challenge, invoke /ctf-writeup to generate a standardized submission-style writeup — concise, reproducible, and ready for competition organizers or teammates to validate.
Flags vary by CTF. Common formats:
flag{...}, FLAG{...}, CTF{...}, TEAM{...}ENO{...}, HTB{...}, picoCTF{...})Validation rule (important):
# Search for common flag patterns in files
grep -rniE '(flag|ctf|eno|htb|pico)\{' .
# Search in binary/memory output
strings output.bin | grep -iE '\{.*\}'# Recon
file * # Identify file types
strings binary | grep -i flag # Quick string search
xxd binary | head -20 # Hex dump header
binwalk -e firmware.bin # Extract embedded files
checksec --file=binary # Check binary protections
# Connect
nc host port # Connect to challenge
echo -e "answer1\nanswer2" | nc host port # Scripted input
curl -v http://host:port/ # HTTP recon
# Python exploit template
python3 -c "
from pwn import *
r = remote('host', port)
r.interactive()
"$ARGUMENTS
© ljagiello, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in solve-challenge of ljagiello/ctf-skills.
Open the folder on GitHubat commit c332c7b
Solve Challenge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Solve Challenge this skillljagiello/ctf-skills | 3.4k | — | ~2.3k | Automated safety check: Notes | MIT | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Helloctf SkillProbiusOfficial/Hello-CTF | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None |
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
ProbiusOfficial/Hello-CTF
Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
ljagiello/ctf-skills
Generates a single standardized submission-style CTF writeup for competition handoff and organizer review.
ljagiello/ctf-skills
Provides digital forensics and signal analysis techniques for CTF challenges.
Categories
Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. Solve Challenge is an agent skill from ljagiello/ctf-skills. Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.
Solve Challenge fits situations like: the user gives you a challenge bundle; A remote service; A suspicious file; only a vague challenge description and you must determine where to start.
Run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a claude-code`. Or copy the skill folder (solve-challenge in ljagiello/ctf-skills) into .claude/skills/solve-challenge in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a codex`. Or copy the skill folder (solve-challenge in ljagiello/ctf-skills) into .agents/skills/solve-challenge in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solve-challenge, .gemini/skills/solve-challenge, .github/skills/solve-challenge and .opencode/skills/solve-challenge in your project.
Going by SKILL.md and its folder, Solve Challenge needs the command-line tools its instructions call (bash, curl and python3) and credentials named CTF_TOKEN. Our summary lists: Python 3; A credential in CTF_TOKEN. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, Skill. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills..
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Solve Challenge is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Solve Challenge: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars), Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars) and Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,421 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.
Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.