Agent skill

CTF ZIP Archive Key Recovery

by zhaoxuya520 in zhaoxuya520/reverse-skill

Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.

MITAuto-check passedSecurity

Install CTF ZIP Archive Key Recovery

skills CLI
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .claude/skills/competition-zip-archive && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
competition-zip-archive
GitHub stars
41k
Used in
1 other repo
Token cost
~1.5k tokens
SKILL.md length
666 words
Files
3 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.

  • Works in 4 steps: Establish Archive Truth → Recover Keys With Known Plaintext → Unlock And Validate → …
  • Solving a CTF challenge built around a ZipCrypto-encrypted archive
  • SKILL.md covers Quick Start, Tool Setup, Workflow and Evidence To Preserve
  • Calls bash

What it does

This runs only after a separate orchestrator skill has already set up sandbox assumptions and routed the case here, and only when the decisive path is an encrypted ZIP or PKZIP archive rather than an upload parser or another crypto puzzle. It starts by hashing and copying the original archive, listing its entries, and confirming the entry actually uses legacy ZipCrypto rather than a modern scheme that the chosen tool cannot recover.

A usable known-plaintext candidate needs at least 12 known bytes including 8 contiguous ones, drawn from a predictable file, header or template inside the challenge archive. After recovering the keys it produces and extracts an unencrypted copy, and keeps a record of the command used, entry names, the plaintext source, the recovered keys, the output hash and the final flag as evidence. It replies in Simplified Chinese unless asked otherwise.

When your agent uses it

  • Solving a CTF challenge built around a ZipCrypto-encrypted archive
  • Identifying whether a ZIP entry uses legacy ZipCrypto or a modern cipher
  • Recovering ZIP keys from a known file prefix instead of guessing passwords

Example prompts

  • “This CTF archive has a known PNG header inside, recover the keys from it.”
  • “Check whether this archive's entries use ZipCrypto before we try anything else.”
  • “Extract the flag file once the ZIP keys are recovered.”

Requirements

  • bkcrack
  • An active CTF-sandbox-orchestrator session

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Establish Archive Truth
  2. Recover Keys With Known Plaintext
  3. Unlock And Validate
  4. Re-route When Preconditions Fail

What it can do on your machine

Read from SKILL.md and the folder at commit cab634b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CTF ZIP Archive Key Recovery loads about 1.5k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 139 tokens; SKILL.md has 666 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhaoxuya520/reverse-skill at commit cab634b, republished under its MIT licence (© zhaoxuya520). 666 words, ~1,458 tokens.

Download SKILL.mdSave it as .claude/skills/competition-zip-archive/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
competition-zip-archive
description
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for ZIP and PKZIP archive challenges, legacy ZipCrypto identification, known-plaintext recovery with bkcrack, key-based decryption, and reproducible extraction. Use when the user asks to solve an encrypted ZIP challenge, inspect ZipCrypto metadata, recover keys from a known file prefix, or unlock an archive without starting with password brute force. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

Competition ZIP Archive

Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is active and has established sandbox assumptions, evidence priorities, and the analysis project root. If that has not happened yet, return to $ctf-sandbox-orchestrator first.

Use this skill when the decisive path is an encrypted ZIP/PKZIP archive rather than an upload parser or a generic crypto blob. Prefer the legacy ZipCrypto known-plaintext path when the challenge gives a predictable file, format header, template, or other recoverable plaintext. Do not begin with blind password brute force.

Reply in Simplified Chinese unless the user explicitly requests English. Keep commands and tool output in their original form.

Quick Start

  1. Preserve the original archive, compute a hash, and work on a copy under the analysis project's work/<case>/ directory.
  2. Confirm the actual archive format and list entries before attempting a password attack.
  3. Determine whether the entry uses legacy ZipCrypto. bkcrack does not recover WinZip AES or other modern encryption.
  4. Build an exact known-plaintext candidate. The attack needs at least 12 known plaintext bytes, including at least 8 contiguous bytes.
  5. Recover the internal keys with bkcrack, then create an unencrypted copy and extract it.
  6. Preserve the command, entry names, known-plaintext source, recovered keys, output hash, and final flag as evidence.

Tool Setup

Use the normal tool index and bootstrap path before guessing an executable location:

powershell
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/refresh-tool-index.ps1
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/bootstrap-reverse.ps1 -Capability bkcrack

On Kali, use the equivalent capability command:

bash
bash kali/scripts/bootstrap-reverse.sh bkcrack

The Windows capability is pinned to the v1.8.1 release and verifies the GitHub asset digest. If the tool is installed manually, refresh skills/tool-index.md afterward.

Workflow

1. Establish Archive Truth

Keep the original immutable and record:

bash
sha256sum challenge.zip
file challenge.zip
bkcrack -L challenge.zip

On Windows, use Get-FileHash in place of sha256sum. bkcrack -L shows entry names, compression methods, and encryption status. Do not infer the encryption type from the .zip extension alone.

Check the entry that will provide the known plaintext. A useful candidate is a stored or otherwise predictable file such as a PNG, PDF, text template, or challenge-generated configuration. A local ZIP header (PK\x03\x04) is metadata for the archive entry, not plaintext inside the encrypted member, so it is not by itself a useful known-plaintext sample.

Show full SKILL.md (312 more words)Show less
2. Recover Keys With Known Plaintext

When the ciphertext entry is flag.txt and a matching plaintext entry is available in known.zip:

bash
bkcrack -C challenge.zip -c flag.txt -P known.zip -p flag.txt

For raw ciphertext and plaintext files:

bash
bkcrack -c cipherfile -p plainfile

The plaintext must match the bytes represented in the encrypted entry. If the entry was deflated, an uncompressed copy of the file is not automatically the right input; use a matching ZIP fixture or the exact compressed bytes.

If the known bytes begin at an offset, add -o <offset>. If only 8-11 bytes are contiguous, combine them with other known bytes using sparse hints:

bash
bkcrack -c cipherfile -p plainfile -x 25 4b4f -x 30 21

The successful run yields three internal ZipCrypto keys. Record them exactly as printed; they are not the original password.

3. Unlock And Validate

Use the recovered keys to make a new archive, leaving the source untouched:

bash
bkcrack -C challenge.zip -k K0 K1 K2 -D unlocked.zip
7z t unlocked.zip
7z x unlocked.zip -ounpacked

Replace K0 K1 K2 with the hexadecimal values printed by bkcrack. Validate the output with the archive test command and a hash or exact flag comparison. If only one raw member is needed, -d can write its deciphered bytes; deflated raw data may need the inflate.py helper shipped with bkcrack.

4. Re-route When Preconditions Fail
  • WinZip AES or another modern encryption mode: stop this path and identify the challenge-specific primitive.
  • No reliable known plaintext: inspect filenames, metadata, compression choices, challenge source, and other entries before considering password recovery.
  • Known plaintext shorter than the requirement: locate more contiguous bytes or use evidence-backed sparse offsets.
  • The problem is an application upload/parser chain: hand off to $competition-file-parser-chain.
  • The problem is a generic ciphertext or custom cipher after archive extraction: hand off to $competition-crypto-mobile.

Evidence To Preserve

  • Original and working-copy paths plus SHA-256 hashes
  • bkcrack -L output and the selected encrypted member
  • Exact plaintext fixture, compression method, offsets, and sparse byte hints
  • Key recovery command and the three recovered internal keys
  • unlocked.zip validation output, extraction path, and final artifact hash

Read references/zip-archive.md for the decision table and evidence checklist.

© zhaoxuya520, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in CTF-Sandbox-Orchestrator/competition-zip-archive of zhaoxuya520/reverse-skill.

  • SKILL.md
  • agents/openai.yaml
  • references/zip-archive.md

Open the folder on GitHubat commit cab634b

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zhaoxuya520/reverse-skill, which our catalogue first saw on October 7, 2026.

Compare with similar skills

CTF ZIP Archive Key Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CTF ZIP Archive Key Recovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CTF ZIP Archive Key Recovery this skillzhaoxuya520/reverse-skill41k1 repos~1.5kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
Helloctf SkillProbiusOfficial/Hello-CTF4.2k—~387Automated safety check: PassGPL-3.0
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone
Alibabacloud Ecs Sec Kernelaliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Helloctf Skill

    ProbiusOfficial/Hello-CTF

    Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。

    4.2k GitHub stars~387 tokensUpdated today
    SecurityAuto-check passed
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Alibabacloud Ecs Sec Kernel

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    SecurityAuto-check: notes

More from zhaoxuya520/reverse-skill

All 19 skills in this repo
  • Diagram Generator

    zhaoxuya520/reverse-skill

    Turns text, notes, code, schemas or tables into diagram source in Mermaid, Graphviz DOT, PlantUML or SVG, and renders files when you ask for an image or PDF.

    41k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check: warnings
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    41k GitHub starsUsed in 4 repos~953 tokens
    Auto-check: warnings
  • Dsl Vm Reverse

    zhaoxuya520/reverse-skill

    Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.

    41k GitHub starsUsed in 3 repos~2.3k tokens
    Auto-check passed
  • Browser Extension Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic…

    41k GitHub starsUsed in 2 repos~366 tokens
    Auto-check passed
  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    41k GitHub starsUsed in 2 repos~339 tokens
    Auto-check passed
  • Identity Federation

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.

    41k GitHub starsUsed in 2 repos~290 tokens
    Auto-check passed

Categories

Questions about CTF ZIP Archive Key Recovery

What does CTF ZIP Archive Key Recovery do?

Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force. This runs only after a separate orchestrator skill has already set up sandbox assumptions and routed the case here, and only when the decisive path is an encrypted ZIP or PKZIP archive rather than an upload parser or another crypto puzzle. It starts by hashing and copying the original archive, listing its entries, and confirming the entry actually uses legacy ZipCrypto rather than a modern scheme that the chosen tool cannot recover.

When should I use CTF ZIP Archive Key Recovery?

CTF ZIP Archive Key Recovery fits situations like: solving a CTF challenge built around a ZipCrypto-encrypted archive; identifying whether a ZIP entry uses legacy ZipCrypto or a modern cipher; recovering ZIP keys from a known file prefix instead of guessing passwords.

How do I install CTF ZIP Archive Key Recovery in Claude Code?

Run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a claude-code`. Or copy the skill folder (CTF-Sandbox-Orchestrator/competition-zip-archive in zhaoxuya520/reverse-skill) into .claude/skills/competition-zip-archive in your project. Claude Code loads it when a task matches its description.

How do I install CTF ZIP Archive Key Recovery in Codex?

Run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a codex`. Or copy the skill folder (CTF-Sandbox-Orchestrator/competition-zip-archive in zhaoxuya520/reverse-skill) into .agents/skills/competition-zip-archive in your project. Codex loads it when a task matches its description.

Can I use CTF ZIP Archive Key Recovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/competition-zip-archive, .gemini/skills/competition-zip-archive, .github/skills/competition-zip-archive and .opencode/skills/competition-zip-archive in your project.

What does CTF ZIP Archive Key Recovery need to run?

Going by SKILL.md and its folder, CTF ZIP Archive Key Recovery needs the command-line tools its instructions call (bash). Our summary lists: bkcrack; An active CTF-sandbox-orchestrator session.

Does CTF ZIP Archive Key Recovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is CTF ZIP Archive Key Recovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CTF ZIP Archive Key Recovery use?

CTF ZIP Archive Key Recovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CTF ZIP Archive Key Recovery use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 735 tokens, read only when the agent opens those files.

What are the alternatives to CTF ZIP Archive Key Recovery?

Skills that share tags, products or a category with CTF ZIP Archive Key Recovery: Ctf Osint (ljagiello/ctf-skills, 3.4k stars), Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CTF ZIP Archive Key Recovery?

zhaoxuya520 (a GitHub user) maintains it in zhaoxuya520/reverse-skill, which has 40,590 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on September 22, 2026.

Source: zhaoxuya520/reverse-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.