ljagiello/ctf-skills: 11 Agent Skills
Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
| Repository | ljagiello/ctf-skills · website |
|---|---|
| GitHub stars | 3,411 |
| Skills | 11 |
| Category | DevOps, cloud and security |
| License | MIT |
| Last updated | Sep 13, 2026 |
| Install counts | ljagiello/ctf-skills on skills.sh, Vercel's skills directory, which shows installs and security audits per skill |
Install ljagiello/ctf-skills
| All skills, any agent | npx skills add ljagiello/ctf-skills |
|---|---|
| One skill | npx skills add ljagiello/ctf-skills --skill ctf-ai-ml |
| Only for Claude Code | npx skills add ljagiello/ctf-skills -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project) |
npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.
Skills in ljagiello/ctf-skills
| Skill | What it does |
|---|---|
| ctf-ai-ml | Provides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network analysis, LoRA adapter exploitation,… |
| ctf-crypto | Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block… |
| ctf-forensics | Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power… |
| ctf-malware | Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility… |
| ctf-misc | Provides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game theory, unusual sandbox escapes, and… |
| ctf-osint | Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes… |
| ctf-pwn | Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc,… |
| ctf-reverse | Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, game clients, malware-like loaders,… |
| ctf-web | Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling,… |
| ctf-writeup | Generates a single standardized submission-style CTF writeup for competition handoff and organizer review. Use after solving a CTF challenge to document the solution steps, tools used, and lessons learned in a structured format. |
| solve-challenge | Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine… |
Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.
More devops, cloud and security skill packs
| # | Skill pack | Skills | GitHub stars | Updated |
|---|---|---|---|---|
| 1 |
vercel-labs/agent-skills Vercel's official collection of agent skills
|
9 | 32.1K | 2026-08-28 |
| 2 |
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
|
5 | 18.1K | 2026-10-06 |
| 3 |
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
|
79 | 7,352 | 2026-09-19 |
| 4 |
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
|
83 | 4,807 | 2026-10-08 |
| 5 |
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
|
205 | 3,094 | 2026-10-08 |
| 6 |
jeremylongshore/tons-of-skills-marketplace Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explor…
|
6123 | 2,823 | 2026-10-08 |