Reverse Flow
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent.
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MuWinds/BUUCTF_Agent misc --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/misc .claude/skills/misc && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .claude/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/miscType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MuWinds/BUUCTF_Agent misc --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/misc .agents/skills/misc && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .agents/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MuWinds/BUUCTF_Agent misc --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/misc .cursor/skills/misc && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .cursor/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MuWinds/BUUCTF_Agent.git --path skills/misc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MuWinds/BUUCTF_Agent misc --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/misc .gemini/skills/misc && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .gemini/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MuWinds/BUUCTF_Agent miscInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/misc .github/skills/misc && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .github/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MuWinds/BUUCTF_Agent --skill misc -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MuWinds/BUUCTF_Agent misc --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/misc .opencode/skills/misc && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "misc" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/misc into .opencode/skills/misc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "misc", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
misc杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent.
Misc is an agent skill from MuWinds/BUUCTF_Agent. 杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类。
Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Capture the flag. The repository describes itself as: 专为CTF设计的可扩展AI Agent,可自动解CTF题,也能与用户协作交互解题~. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 95cc9e0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Misc loads about 504 tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 126 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MuWinds/BUUCTF_Agent at commit 95cc9e0, republished under its Apache-2.0 licence (© MuWinds). 126 words, ~504 tokens.
.claude/skills/misc/SKILL.md (or your agent's skills folder).file、exiftool 查看元数据、strings 搜索隐藏文本stegsolve 查看各 bit plane、zsteg 自动检测binwalk -e 提取嵌入文件、foremost 文件恢复identify 分解帧Audacity 或 sox 查看频谱,可能隐藏图像RX-SSTV 解码Statistics -> Protocol HierarchyStatistics -> ConversationsStrings (Ctrl+F) 搜索 flag、password 等关键字File -> Export Objects -> HTTP/DNS/SMBftp-data 传输的文件内容tshark -r capture.pcap # 命令行 Wireshark
tshark -r cap.pcap -Y "http" # 过滤 HTTP
tcpflow -r capture.pcap # TCP 流重组
NetworkMiner # 网络取证工具photorec、testdiskfls、mactimeimageinfo:识别操作系统pslist/psscan:进程列表filescan/dumpfiles:文件恢复hashdump:提取密码哈希clipboard:剪贴板内容.evtx)、注册表、Prefetch/var/log/、.bash_history、/etc/passwd. - 编码exiftool 提取 GPS 坐标、设备信息© MuWinds, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/misc of MuWinds/BUUCTF_Agent.
Open the folder on GitHubat commit 95cc9e0
Misc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Misc this skillMuWinds/BUUCTF_Agent | 267 | — | ~504 | Automated safety check: Pass | Apache-2.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 936 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Helloctf SkillProbiusOfficial/Hello-CTF | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | |
| Alibabacloud Ecs Sec Kernelaliyun/alibabacloud-ecs-troubleshoot-skills | 148 | 1 repos | ~2.4k | Automated safety check: Notes | Apache-2.0 |
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
ProbiusOfficial/Hello-CTF
Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
MuWinds/BUUCTF_Agent
磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent.
MuWinds/BUUCTF_Agent
Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.
Categories
杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent. Misc is an agent skill from MuWinds/BUUCTF_Agent.
Misc fits situations like: tasks that involve Capture the flag.
Run `npx skills add MuWinds/BUUCTF_Agent --skill misc -a claude-code`. Or copy the skill folder (skills/misc in MuWinds/BUUCTF_Agent) into .claude/skills/misc in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MuWinds/BUUCTF_Agent --skill misc -a codex`. Or copy the skill folder (skills/misc in MuWinds/BUUCTF_Agent) into .agents/skills/misc in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MuWinds/BUUCTF_Agent --skill misc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/misc, .gemini/skills/misc, .github/skills/misc and .opencode/skills/misc in your project.
SKILL.md names no scripts, command-line tools or credentials: Misc is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Misc is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 504 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Misc: Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars), Ctf Osint (ljagiello/ctf-skills, 3.4k stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars) and Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MuWinds (a GitHub user) maintains it in MuWinds/BUUCTF_Agent, which has 267 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 5, 2026.
Source: MuWinds/BUUCTF_Agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.