Ctf Osint
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .claude/skills/competition-zip-archive && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .claude/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archiveType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .agents/skills/competition-zip-archive && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .agents/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .cursor/skills/competition-zip-archive && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .cursor/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zhaoxuya520/reverse-skill.git --path CTF-Sandbox-Orchestrator/competition-zip-archive--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .gemini/skills/competition-zip-archive && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .gemini/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archiveInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .github/skills/competition-zip-archive && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .github/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zhaoxuya520/reverse-skill competition-zip-archive --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/CTF-Sandbox-Orchestrator/competition-zip-archive .opencode/skills/competition-zip-archive && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "competition-zip-archive" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/CTF-Sandbox-Orchestrator/competition-zip-archive into .opencode/skills/competition-zip-archive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "competition-zip-archive", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
competition-zip-archiveRecovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force.
This runs only after a separate orchestrator skill has already set up sandbox assumptions and routed the case here, and only when the decisive path is an encrypted ZIP or PKZIP archive rather than an upload parser or another crypto puzzle. It starts by hashing and copying the original archive, listing its entries, and confirming the entry actually uses legacy ZipCrypto rather than a modern scheme that the chosen tool cannot recover.
A usable known-plaintext candidate needs at least 12 known bytes including 8 contiguous ones, drawn from a predictable file, header or template inside the challenge archive. After recovering the keys it produces and extracts an unencrypted copy, and keeps a record of the command used, entry names, the plaintext source, the recovered keys, the output hash and the final flag as evidence. It replies in Simplified Chinese unless asked otherwise.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cab634b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CTF ZIP Archive Key Recovery loads about 1.5k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 139 tokens; SKILL.md has 666 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zhaoxuya520/reverse-skill at commit cab634b, republished under its MIT licence (© zhaoxuya520). 666 words, ~1,458 tokens.
.claude/skills/competition-zip-archive/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is active and has established sandbox assumptions, evidence priorities, and the analysis project root. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the decisive path is an encrypted ZIP/PKZIP archive rather than an upload parser or a generic crypto blob. Prefer the legacy ZipCrypto known-plaintext path when the challenge gives a predictable file, format header, template, or other recoverable plaintext. Do not begin with blind password brute force.
Reply in Simplified Chinese unless the user explicitly requests English. Keep commands and tool output in their original form.
work/<case>/ directory.bkcrack does not recover WinZip AES or other modern encryption.bkcrack, then create an unencrypted copy and extract it.Use the normal tool index and bootstrap path before guessing an executable location:
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/refresh-tool-index.ps1
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/bootstrap-reverse.ps1 -Capability bkcrackOn Kali, use the equivalent capability command:
bash kali/scripts/bootstrap-reverse.sh bkcrackThe Windows capability is pinned to the v1.8.1 release and verifies the GitHub asset digest. If the tool is installed manually, refresh skills/tool-index.md afterward.
Keep the original immutable and record:
sha256sum challenge.zip
file challenge.zip
bkcrack -L challenge.zipOn Windows, use Get-FileHash in place of sha256sum. bkcrack -L shows entry names, compression methods, and encryption status. Do not infer the encryption type from the .zip extension alone.
Check the entry that will provide the known plaintext. A useful candidate is a stored or otherwise predictable file such as a PNG, PDF, text template, or challenge-generated configuration. A local ZIP header (PK\x03\x04) is metadata for the archive entry, not plaintext inside the encrypted member, so it is not by itself a useful known-plaintext sample.
When the ciphertext entry is flag.txt and a matching plaintext entry is available in known.zip:
bkcrack -C challenge.zip -c flag.txt -P known.zip -p flag.txtFor raw ciphertext and plaintext files:
bkcrack -c cipherfile -p plainfileThe plaintext must match the bytes represented in the encrypted entry. If the entry was deflated, an uncompressed copy of the file is not automatically the right input; use a matching ZIP fixture or the exact compressed bytes.
If the known bytes begin at an offset, add -o <offset>. If only 8-11 bytes are contiguous, combine them with other known bytes using sparse hints:
bkcrack -c cipherfile -p plainfile -x 25 4b4f -x 30 21The successful run yields three internal ZipCrypto keys. Record them exactly as printed; they are not the original password.
Use the recovered keys to make a new archive, leaving the source untouched:
bkcrack -C challenge.zip -k K0 K1 K2 -D unlocked.zip
7z t unlocked.zip
7z x unlocked.zip -ounpackedReplace K0 K1 K2 with the hexadecimal values printed by bkcrack. Validate the output with the archive test command and a hash or exact flag comparison. If only one raw member is needed, -d can write its deciphered bytes; deflated raw data may need the inflate.py helper shipped with bkcrack.
$competition-file-parser-chain.$competition-crypto-mobile.bkcrack -L output and the selected encrypted memberunlocked.zip validation output, extraction path, and final artifact hashRead references/zip-archive.md for the decision table and evidence checklist.
© zhaoxuya520, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in CTF-Sandbox-Orchestrator/competition-zip-archive of zhaoxuya520/reverse-skill.
Open the folder on GitHubat commit cab634b
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zhaoxuya520/reverse-skill, which our catalogue first saw on October 7, 2026.
CTF ZIP Archive Key Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CTF ZIP Archive Key Recovery this skillzhaoxuya520/reverse-skill | 41k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Helloctf SkillProbiusOfficial/Hello-CTF | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None | |
| Alibabacloud Ecs Sec Kernelaliyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.4k | Automated safety check: Notes | Apache-2.0 |
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
ProbiusOfficial/Hello-CTF
Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
zhaoxuya520/reverse-skill
Turns text, notes, code, schemas or tables into diagram source in Mermaid, Graphviz DOT, PlantUML or SVG, and renders files when you ask for an image or PDF.
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
zhaoxuya520/reverse-skill
Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic…
zhaoxuya520/reverse-skill
A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
Categories
Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force. This runs only after a separate orchestrator skill has already set up sandbox assumptions and routed the case here, and only when the decisive path is an encrypted ZIP or PKZIP archive rather than an upload parser or another crypto puzzle. It starts by hashing and copying the original archive, listing its entries, and confirming the entry actually uses legacy ZipCrypto rather than a modern scheme that the chosen tool cannot recover.
CTF ZIP Archive Key Recovery fits situations like: solving a CTF challenge built around a ZipCrypto-encrypted archive; identifying whether a ZIP entry uses legacy ZipCrypto or a modern cipher; recovering ZIP keys from a known file prefix instead of guessing passwords.
Run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a claude-code`. Or copy the skill folder (CTF-Sandbox-Orchestrator/competition-zip-archive in zhaoxuya520/reverse-skill) into .claude/skills/competition-zip-archive in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a codex`. Or copy the skill folder (CTF-Sandbox-Orchestrator/competition-zip-archive in zhaoxuya520/reverse-skill) into .agents/skills/competition-zip-archive in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaoxuya520/reverse-skill --skill competition-zip-archive -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/competition-zip-archive, .gemini/skills/competition-zip-archive, .github/skills/competition-zip-archive and .opencode/skills/competition-zip-archive in your project.
Going by SKILL.md and its folder, CTF ZIP Archive Key Recovery needs the command-line tools its instructions call (bash). Our summary lists: bkcrack; An active CTF-sandbox-orchestrator session.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
CTF ZIP Archive Key Recovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 735 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with CTF ZIP Archive Key Recovery: Ctf Osint (ljagiello/ctf-skills, 3.4k stars), Helloctf Skill (ProbiusOfficial/Hello-CTF, 4.2k stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zhaoxuya520 (a GitHub user) maintains it in zhaoxuya520/reverse-skill, which has 40,590 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on September 22, 2026.
Source: zhaoxuya520/reverse-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.