Agent skill

Solve Challenge

by ljagiello in ljagiello/ctf-skills

Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.

MITAuto-check: notesSecurity

Install Solve Challenge

skills CLI
$ npx skills add ljagiello/ctf-skills --skill solve-challenge -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ljagiello/ctf-skills solve-challenge --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/solve-challenge .claude/skills/solve-challenge && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
solve-challenge
GitHub stars
3.4k
Token cost
~2.3k tokens
SKILL.md length
888 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.

  • Works in 6 steps: CTFd Platform Detection → Recon → Categorize → …
  • The user gives you a challenge bundle
  • SKILL.md covers Environment Setup, Workflow, Flag Formats and Quick Reference, plus 1 more section
  • Calls bash, curl and python3; needs CTF_TOKEN

What it does

Solve Challenge is an agent skill from ljagiello/ctf-skills. Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine where to start. Do not use it when the category is already clear and a specialized skill can be invoked directly; this is the dispatcher and recon entrypoint, not the deepest reference for category-specific techniques.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf- skills.

It sits in Security, covering Capture the flag. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.

When your agent uses it

  • The user gives you a challenge bundle
  • A remote service
  • A suspicious file
  • Only a vague challenge description and you must determine where to start

Example prompts

  • “Use the solve-challenge skill to solve CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to…”
  • “/solve-challenge”

Requirements

  • Python 3
  • A credential in CTF_TOKEN
  • Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills.
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, Skill

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. CTFd Platform Detection
  2. Recon
  3. Categorize
  4. Invoke the Category Skill
  5. Pivot When Stuck
  6. Generate Write-up

What it can do on your machine

Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Task
    • WebFetch
    • WebSearch
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CTF_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills.

    From compatibility in the SKILL.md frontmatter.

Context cost

Solve Challenge loads about 2.3k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 888 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, Skill

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ljagiello/ctf-skills at commit c332c7b, republished under its MIT licence (© ljagiello). 888 words, ~2,293 tokens.

Download SKILL.mdSave it as .claude/skills/solve-challenge/SKILL.md (or your agent's skills folder).
name
solve-challenge
description
Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine where to start. Do not use it when the category is already clear and a specialized skill can be invoked directly; this is the dispatcher and recon entrypoint, not the deepest reference for category-specific techniques.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, Skill
compatibility
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills.
license
MIT
metadata.user-invocable
true
metadata.argument-hint
[category] [challenge-file-or-url]

CTF Challenge Solver

You're a skilled CTF player. Your goal is to solve the challenge and find the flag.

Environment Setup

Two setup strategies depending on your workflow:

Use the central installer entrypoint:

bash
bash scripts/install_ctf_tools.sh all

Run a narrower mode when you only want one tool group:

bash
bash scripts/install_ctf_tools.sh python
bash scripts/install_ctf_tools.sh apt
bash scripts/install_ctf_tools.sh brew
bash scripts/install_ctf_tools.sh gems
bash scripts/install_ctf_tools.sh go
bash scripts/install_ctf_tools.sh manual

The full package lists now live in scripts/install_ctf_tools.sh.

On-demand (during challenges)

Each category skill's SKILL.md has a Prerequisites section listing only the tools needed for that category. Install as you go.

Workflow

Step 0: CTFd Platform Detection

If the CTF platform URL is known, check if it runs CTFd and switch to API-driven navigation:

bash
# Detect CTFd (look for /api/v1/ and /themes/core/)
curl -s "$CTF_URL/api/v1/" | head -5
curl -s "$CTF_URL" | grep -oE '/themes/core/'

If CTFd is detected, ask the user for their API token (generated from CTFd Settings > Access Tokens). The token is not provided by default — the user must create one in the CTFd web UI first. Once provided, set the environment variables and proceed via API:

bash
export CTF_URL="https://ctf.example.com"
export CTF_TOKEN="ctfd_..."  # Ask user for this

Invoke /ctf-misc and load its ctfd-navigation.md for the full API reference and Python client class.

Step 1: Recon
  1. Explore files -- List the challenge directory, run file * on everything
  2. Triage binaries -- strings, xxd | head, binwalk, checksec on binaries
  3. Fetch links -- If the challenge mentions URLs, fetch them FIRST for context
  4. Connect -- Try remote services (nc) to understand what they expect
  5. Read hints -- Challenge descriptions, filenames, and comments often contain clues
Step 2: Categorize

Determine the primary category, then invoke the matching skill.

By file type:

  • .pcap, .pcapng, .evtx, .raw, .dd, .E01 -> forensics
  • .elf, .exe, .so, .dll, binary with no extension -> reverse or pwn (check if remote service provided -- if yes, likely pwn)
  • .py, .sage, .txt with numbers -> crypto
  • .apk, .wasm, .pyc -> reverse
  • .safetensors, .pt, .pth, .bin, .onnx -> ai-ml
  • Web URL or source code with HTML/JS/PHP/templates -> web
  • Images, audio, PDFs with no obvious content -> forensics (steganography)

By challenge description keywords:

  • "buffer overflow", "ROP", "shellcode", "libc", "heap" -> pwn
  • "RSA", "AES", "cipher", "encrypt", "prime", "modulus", "lattice", "LWE", "GCM" -> crypto
  • "XSS", "SQL", "injection", "cookie", "JWT", "SSRF" -> web
  • "disk image", "memory dump", "packet capture", "registry", "power trace", "side-channel", "spectrogram", "audio tracks", "MKV" -> forensics
  • "find", "locate", "identify", "who", "where" -> osint
  • "obfuscated", "packed", "C2", "malware", "beacon" -> malware
  • "prompt injection", "LoRA", "adversarial", "model weights", "embedding" -> ai-ml
  • "jail", "sandbox", "escape", "encoding", "signal", "game", "Nim", "commitment", "Gray code" -> misc

By service behavior:

  • Port with interactive prompt, crash on long input -> pwn
  • HTTP service -> web
  • netcat with math/crypto puzzles -> crypto
  • netcat with restricted shell or eval -> misc (jail)
Step 3: Invoke the Category Skill

Once you identify the category, invoke the matching skill to get specialized techniques:

CategoryInvokeWhen to Use
Web/ctf-webXSS, SQLi, SSTI, SSRF, JWT, file uploads, prototype pollution
Pwn/ctf-pwnBuffer overflow, format string, heap, ROP, sandbox escape
Crypto/ctf-cryptoRSA, AES, ECC, PRNG, ZKP, classical ciphers
Reverse/ctf-reverseBinary analysis, game clients, VMs, obfuscated code
Forensics/ctf-forensicsDisk images, memory dumps, event logs, stego, network captures
OSINT/ctf-osintSocial media, geolocation, DNS, public records
Malware/ctf-malwareObfuscated scripts, C2 traffic, PE/.NET analysis
AI/ML/ctf-ai-mlModel weights (.safetensors, .pt, .pth, .bin, .onnx), prompt injection, LoRA adapters, adversarial examples
Misc/ctf-miscJails, encodings, RF/SDR, esoteric languages, constraint solving

You can also invoke /ctf-<category> to load the full skill instructions with detailed techniques.

Show full SKILL.md (362 more words)Show less
Step 4: Pivot When Stuck

If your first approach doesn't work:

  1. Re-examine assumptions -- Is this really the category you think? A "web" challenge might need crypto for JWT forgery. A "forensics" PCAP might contain a pwn exploit to replay.
  2. Try a different category skill -- Many challenges span multiple categories. Invoke a second skill for the cross-cutting technique.
  3. Look for what you missed -- Hidden files, alternate ports, response headers, comments in source, metadata in images.
  4. Simplify -- If an exploit is too complex, check if there's a simpler path (default creds, known CVE, logic bug).
  5. Check edge cases -- Off-by-one, race conditions, integer overflow, encoding mismatches.

Common multi-category patterns:

  • Forensics + Crypto: encrypted data in PCAP/disk image, need crypto to decrypt
  • Web + Reverse: WASM or obfuscated JS in web challenge
  • Web + Crypto: JWT forgery, custom MAC/signature schemes
  • Reverse + Pwn: reverse the binary first, then exploit the vulnerability
  • Forensics + OSINT: recover data from dump, then trace it via public sources
  • Misc + Crypto: jail escape requires building crypto primitives under constraints
  • OSINT + Stego: social media posts with unicode homoglyph steganography (Cyrillic lookalikes encode bits)
  • Web + Forensics: paywall bypass (curl reveals content hidden by CSS overlays)
  • Misc + Crypto + Game Theory: multi-phase interactive challenges with AES decryption → HMAC commitment → combinatorial game solving (GF(256) Nim)
  • Crypto + Geometry + Lattice: multi-layer challenges progressing from spatial reconstruction → subspace recovery → LWE solving → AES-GCM decryption
  • Forensics + Signal Processing: power traces / side-channel analysis requiring statistical analysis of measurement data
  • Forensics + Network + Encoding: timing-based encoding in PCAP (inter-packet intervals encode binary data)
Step 5: Generate Write-up

After solving the challenge, invoke /ctf-writeup to generate a standardized submission-style writeup — concise, reproducible, and ready for competition organizers or teammates to validate.

Flag Formats

Flags vary by CTF. Common formats:

  • flag{...}, FLAG{...}, CTF{...}, TEAM{...}
  • Custom prefixes: check the challenge description or CTF rules for the format (e.g., ENO{...}, HTB{...}, picoCTF{...})
  • Sometimes just a plaintext string with no wrapper

Validation rule (important):

  • If you find multiple flag-like strings, treat them as candidates and validate before finalizing.
  • Prefer the token tied to the intended artifact/workflow (not random metadata noise or obvious decoys).
  • Do a corpus-wide uniqueness check and include the source file/path when reporting.
bash
# Search for common flag patterns in files
grep -rniE '(flag|ctf|eno|htb|pico)\{' .
# Search in binary/memory output
strings output.bin | grep -iE '\{.*\}'

Quick Reference

bash
# Recon
file *                                    # Identify file types
strings binary | grep -i flag             # Quick string search
xxd binary | head -20                     # Hex dump header
binwalk -e firmware.bin                   # Extract embedded files
checksec --file=binary                    # Check binary protections

# Connect
nc host port                              # Connect to challenge
echo -e "answer1\nanswer2" | nc host port # Scripted input
curl -v http://host:port/                 # HTTP recon

# Python exploit template
python3 -c "
from pwn import *
r = remote('host', port)
r.interactive()
"

Challenge

$ARGUMENTS

© ljagiello, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in solve-challenge of ljagiello/ctf-skills.

Open the folder on GitHubat commit c332c7b

Compare with similar skills

Solve Challenge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solve Challenge compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solve Challenge this skillljagiello/ctf-skills3.4k—~2.3kAutomated safety check: NotesMIT
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Penetration Flowlingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT
Helloctf SkillProbiusOfficial/Hello-CTF4.2k—~387Automated safety check: PassGPL-3.0
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone

Similar skills

  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Helloctf Skill

    ProbiusOfficial/Hello-CTF

    Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。

    4.2k GitHub stars~387 tokensUpdated today
    SecurityAuto-check passed
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Alibabacloud Ecs Sec Kernel

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from ljagiello/ctf-skills

  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check: notes
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Writeup

    ljagiello/ctf-skills

    Generates a single standardized submission-style CTF writeup for competition handoff and organizer review.

    3.4k GitHub stars~1.2k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Forensics

    ljagiello/ctf-skills

    Provides digital forensics and signal analysis techniques for CTF challenges.

    3.4k GitHub stars~9.2k tokensUpdated 26 days ago
    Auto-check: warnings

Categories

Questions about Solve Challenge

What does Solve Challenge do?

Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. Solve Challenge is an agent skill from ljagiello/ctf-skills. Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.

When should I use Solve Challenge?

Solve Challenge fits situations like: the user gives you a challenge bundle; A remote service; A suspicious file; only a vague challenge description and you must determine where to start.

How do I install Solve Challenge in Claude Code?

Run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a claude-code`. Or copy the skill folder (solve-challenge in ljagiello/ctf-skills) into .claude/skills/solve-challenge in your project. Claude Code loads it when a task matches its description.

How do I install Solve Challenge in Codex?

Run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a codex`. Or copy the skill folder (solve-challenge in ljagiello/ctf-skills) into .agents/skills/solve-challenge in your project. Codex loads it when a task matches its description.

Can I use Solve Challenge in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill solve-challenge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solve-challenge, .gemini/skills/solve-challenge, .github/skills/solve-challenge and .opencode/skills/solve-challenge in your project.

What does Solve Challenge need to run?

Going by SKILL.md and its folder, Solve Challenge needs the command-line tools its instructions call (bash, curl and python3) and credentials named CTF_TOKEN. Our summary lists: Python 3; A credential in CTF_TOKEN. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch, Skill. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access. Orchestrates other ctf-* skills..

Does Solve Challenge access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Solve Challenge safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Solve Challenge use?

Solve Challenge is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Solve Challenge use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Solve Challenge?

Skills that share tags, products or a category with Solve Challenge: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars), Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars) and Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solve Challenge?

ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,421 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.

Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.