Topic · Security
Best capture the flag skills for Claude Code, Codex and other agents.
- skills
- 45
Capture the flag skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts. | lingbol088-spec/ | 936 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 2 | Provides open source intelligence techniques for CTF challenges. | ljagiello/ | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | 24 days ago |
| 3 | Polymarket integration for prediction market trading on Polygon. | Polymarket/ | 191 | 2 repos | ~2k | Automated safety check: Pass | No licence | 7 mo ago |
| 4 | Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. | lingbol088-spec/ | 222 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 5 | Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。 | ProbiusOfficial/ | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | today |
| 6 | Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. | aliyun/ | 148 | 1 repo | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 7 | Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | 1 repo | ~2.1k | Automated safety check: Notes | MIT | 24 days ago |
| 8 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 9 | 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. | tanweai/ | 185 | — | ~847 | Automated safety check: Pass | No licence | 8 mo ago |
| 10 | Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force. | zhaoxuya520/ | 40k | 2 repos | ~1.5k | Automated safety check: Pass | MIT | 16 days ago |
| 12 | A skill for running Yamagi Quake II savegame code generators (mmgen, fngen, mmproto, mmtable, fngenprotos, fngentables scripts). | yquake2/ | 113 | — | ~634 | Automated safety check: Pass | Unknown | today |
| 13 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 14 | Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill. | ljagiello/ | 3.4k | — | ~2.3k | Automated safety check: Notes | MIT | 24 days ago |
| 15 | 15.Misc 杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~504 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. | manyuegong33/ | 306 | — | ~434 | Automated safety check: Pass | No licence | 17 days ago |
| 17 | 17.Ctf Crypto Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills. | ljagiello/ | 3.4k | — | ~11k | Automated safety check: Notes | MIT | 24 days ago |
| 18 | Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | 1 repo | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 19 | This skill provides guidance for cracking 7z archive password hashes. | lazyFrogLOL/ | 128 | — | ~1.3k | Automated safety check: Pass | No licence | 4 mo ago |
| 20 | 20.Ctf Writeup Generates a single standardized submission-style CTF writeup for competition handoff and organizer review. | ljagiello/ | 3.4k | — | ~1.2k | Automated safety check: Notes | MIT | 24 days ago |
| 21 | Provides digital forensics and signal analysis techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~9.2k | Automated safety check: Warn | MIT | 24 days ago |
| 22 | 面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。 | manyuegong33/ | 306 | — | ~1.2k | Automated safety check: Pass | No licence | 17 days ago |
| 23 | Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 8 days ago |
| 24 | 24.Wargame Multi-turn adversary simulation. An agent skill from NovusEdge/palpatine. | NovusEdge/ | 110 | — | ~1.1k | Automated safety check: Pass | Unknown | 23 days ago |
| 25 | Screen a person or organisation for adverse media coverage, PEP status, and sanctions exposure — corroboration-gated, returns "review" never "guilty". | sickn33/ | 47k | 1 repo | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 26 | Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. | wshobson/ | 40k | — | ~980 | Automated safety check: Pass | MIT | 3 days ago |
| 27 | 27.Yoink Play Yoink capture-the-flag game on Base - yoink the flag, check scores, compete for trophy | alsk1992/ | 2.9k | — | ~299 | Automated safety check: Pass | MIT | 5 days ago |
| 28 | 28.Recon Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs. | briiirussell/ | 413 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 29 | PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC. | langbyyi/ | 134 | 1 repo | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 30 | Polymarket exchange mechanics — on-chain Polygon CTF, Gamma/CLOB/Data APIs, EIP-712 auth, identifier model, WebSocket, settlement, and geo/KYC constraint | agiprolabs/ | 410 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Transform predictable story elements into fresh, original versions. | jwynia/ | 166 | — | ~4.4k | Automated safety check: Pass | MIT | 7 mo ago |
| 32 | Classical cipher analysis playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~4.8k | Automated safety check: Pass | MIT | 24 days ago |
| 33 | RSA attack playbook for CTF and real-world cryptanalysis. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.9k | Automated safety check: Pass | MIT | 24 days ago |
| 34 | Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3k | Automated safety check: Pass | MIT | 24 days ago |
| 35 | 35.Hackthebox HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions | transilienceai/ | 562 | — | ~697 | Automated safety check: Pass | MIT | 2 mo ago |
| 36 | Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | 37.Ctf AI ML CTF AI/ML 攻击技术。当挑战涉及 AI 模型攻击、对抗样本生成、模型提取、Prompt 注入/越狱、LoRA 权重操纵、LLM Token 走私、成员推理攻击、训练数据投毒、神经网络分析时使用。覆盖 FGSM/PGD/C&W 对抗攻击、模型反演、模型权重扰动还原、LLM 工具链劫持、上下文窗口操纵等 AI 安全全链路攻防技术 | wgpsec/ | 1.8k | — | ~533 | Automated safety check: Pass | No licence | 4 days ago |
| 38 | CTF 挑战中的 Flag 搜索策略。当通过 RCE/LFI/SQLi/webshell 等方式获得目标访问权限后、使用常规 ls/cat 命令找不到 flag 时使用。覆盖文件系统、数据库、环境变量、源码、内存等所有 flag 可能的存储位置。按成功率排序的搜索优先级——先试标准路径,再搜索全盘 | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Notes | No licence | 4 days ago |
| 39 | CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | 4 days ago |
| 40 | 40.Ctf Osint CTF 开源情报(OSINT)技术。当挑战要求从公开信息中找线索——如给定用户名/邮箱追踪身份、给定照片进行地理定位、从历史网页快照中恢复数据时使用。覆盖社交媒体调查、Google Dorking、反向图片搜索、Wayback Machine、DNS 侦察、Tor 中继查询、元数据提取 | wgpsec/ | 1.8k | — | ~530 | Automated safety check: Pass | No licence | 4 days ago |
| 41 | CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | 4 days ago |
| 42 | CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL… | wgpsec/ | 1.8k | — | ~644 | Automated safety check: Pass | No licence | 4 days ago |
| 43 | CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取 | wgpsec/ | 1.8k | — | ~624 | Automated safety check: Notes | No licence | 4 days ago |
| 44 | 44.Yoink Play Yoink, an onchain capture-the-flag game on Base. An agent skill from BankrBot/skills. | BankrBot/ | 1.2k | — | ~773 | Automated safety check: Pass | No licence | 2 days ago |
| 45 | A skill your agent uses when anticipating likely referee objections for a Journal of Risk and Uncertainty (JRU) manuscript before submission. | brycewang-stanford/ | 1.2k | — | ~1.7k | Automated safety check: Pass | MIT | 10 days ago |
Questions, answered from the data.
What is the best capture the flag skill?
Reverse Flow from lingbol088-spec/reverse-flow-skill ranks first of the 45 capture the flag skills listed here, with the highest score: its repository has 936 GitHub stars, its SKILL.md loads about 2.4k tokens and it passes the automated safety check with no findings. Next come Ctf Osint and Web3 Polymarket.
Which capture the flag skills are official?
None yet. All 45 capture the flag skills listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Mobile application security42
- Access reviews and audit trails38