Skip to content
Agents tracked: 283 Downloads (7d): 261M up 5.8% GitHub stars: 6.2M VS Code installs: 151M Releases (7d): 289 Agent status: 1 with issues Updated Oct 9, 2026

ljagiello/ctf-skills: 11 Agent Skills

Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more

Repositoryljagiello/ctf-skills · website
GitHub stars3,411
Skills11
CategoryDevOps, cloud and security
LicenseMIT
Last updatedSep 13, 2026
Install countsljagiello/ctf-skills on skills.sh, Vercel's skills directory, which shows installs and security audits per skill

Install ljagiello/ctf-skills

All skills, any agentnpx skills add ljagiello/ctf-skills
One skillnpx skills add ljagiello/ctf-skills --skill ctf-ai-ml
Only for Claude Codenpx skills add ljagiello/ctf-skills -a claude-code, or copy a skill folder to ~/.claude/skills/ (all projects) or .claude/skills/ (one project)

npx skills is the open-source skills CLI; it asks which agents to install for. Skills can include scripts that your agent will run: read a skill before installing it, as you would any code.

Skills in ljagiello/ctf-skills

SkillWhat it does
ctf-ai-mlProvides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network analysis, LoRA adapter exploitation,…
ctf-cryptoProvides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block…
ctf-forensicsProvides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power…
ctf-malwareProvides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility…
ctf-miscProvides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game theory, unusual sandbox escapes, and…
ctf-osintProvides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings, or identifying unknown data like hashes…
ctf-pwnProvides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc,…
ctf-reverseProvides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, game clients, malware-like loaders,…
ctf-webProvides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling,…
ctf-writeupGenerates a single standardized submission-style CTF writeup for competition handoff and organizer review. Use after solving a CTF challenge to document the solution steps, tools used, and lessons learned in a structured format.
solve-challengeSolves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine…

Names and descriptions come from each skill's SKILL.md and are written by the pack's authors.

More devops, cloud and security skill packs

All devops, cloud and security skills

# Skill pack Skills GitHub stars Updated
1
vercel-labs/agent-skills Vercel's official collection of agent skills
9 32.1K 2026-08-28
2
microsoft/SkillOpt SkillOpt is a text-space optimizer that trains reusable natural-language skills for frozen LLM agents through trajectory-driven e…
5 18.1K 2026-10-06
3
SnailSploit/Claude-Red claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SK…
79 7,352 2026-09-19
4
elementalsouls/Claude-BugHunter A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patter…
83 4,807 2026-10-08
5
microsoft/skills Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents
205 3,094 2026-10-08
6
jeremylongshore/tons-of-skills-marketplace Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explor…
6123 2,823 2026-10-08