Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
ljagiello avatar

Ctf Web

  • 6.7k installs
  • 2.9k repo stars
  • Updated July 31, 2026
  • ljagiello/ctf-skills

A structured agent skill that routes web CTF exploitation work across injection, auth, client-side, and deserialization technique libraries with recon workflows and tool commands.

About

ctf-web is a routing and execution skill for web-heavy CTF challenges, directing an agent through reconnaissance, bug classification, and exploit construction across HTTP applications, APIs, browser clients, template engines, auth flows, and smart-contract frontends. Developers and security researchers invoke it when the primary attack surface is web-based, spanning injection classes (SQLi, SSTI, SSRF, XXE, command injection), client-side flaws (XSS, CSP bypass, prototype pollution, request smuggling), and auth/identity weaknesses (JWT manipulation, OAuth/OIDC, SAML, IDOR). The skill organises work into a five-step first-pass workflow: map the trust boundary, capture baseline requests, enumerate hidden functionality, classify the bug family, and build the smallest primitive before chaining. It delegates to roughly 20 referenced sub-documents covering Java/PHP/Python deserialization, race conditions, Node.js sandbox escapes, Web3, and CVE-shaped playbooks, and provides pivot rules to companion skills (ctf-pwn, ctf-crypto, ctf-reverse, ctf-forensics, ctf-osint) when the web vector is not the primary path.

  • Routes between 20+ sub-documents covering SQLi, SSTI, SSRF, XSS, XXE, deserialization, JWT, OAuth/SAML, prototype pollut
  • Provides quick-start commands for sqlmap, ffuf, flask-unsign, curl-based SSTI probes, and JWT base64 decode without veri
  • Defines explicit pivot rules to ctf-pwn, ctf-crypto, ctf-reverse, ctf-forensics, and ctf-osint when the web bug is not t
  • Lists common exploit chain shapes: SSRF to credential leak to RCE, XSS to admin bot to secret leak, SQLi to session forg
  • Covers CVE-tagged techniques including CVE-2024-28184 (WeasyPrint SSRF) and CVE-2025-55182 (React Server Components Flig

Ctf Web by the numbers

  • 6,663 all-time installs (skills.sh)
  • +173 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #98 of 2,203 Security skills by installs in the Skillselion catalog
  • Security screen: CRITICAL risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

ctf-web capabilities & compatibility

Capabilities
sql injection · xss · ssti · ssrf · jwt manipulation · oauth oidc abuse · deserialization · prototype pollution · file upload rce · command injection
Works with
chrome · openai
Use cases
security audit · debugging · web scraping · research
Platforms
macOS · Linux · WSL · Windows
Runs
Runs locally
Pricing
Free
From the docs

What ctf-web says it does

Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend s
SKILL.md
If the target is a native binary, custom VM, or firmware image, switch to `/ctf-reverse` first.
SKILL.md
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
SKILL.md
Use [field-notes.md](field-notes.md) once you have confirmed the challenge is truly web-heavy and you need the long exploit catalog.
SKILL.md
npx skills add https://github.com/ljagiello/ctf-skills --skill ctf-web

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs6.7k
repo stars2.9k
Security audit0 / 3 scanners passed
Last updatedJuly 31, 2026
Repositoryljagiello/ctf-skills

What it does

Guide an AI agent through web exploitation techniques for CTF challenges covering XSS, SQLi, SSTI, SSRF, JWT, auth bypass, deserialization, and similar HTTP/browser/API bug classes.

Who is it for?

Security researchers and developers solving web CTF challenges or practising web exploitation across HTTP, API, and browser attack surfaces.

Skip if: Native binary memory corruption, standalone executable reverse engineering, disk/memory forensics, or pure cryptanalysis challenges.

When should I use this skill?

The CTF target is an HTTP application, REST/GraphQL API, browser client, template engine, identity flow, or smart-contract frontend/backend.

What you get

Agent identifies the bug class, selects the relevant technique sub-document, builds the smallest exploit primitive, and chains it to capture the flag.

  • Identified bug class and relevant technique sub-document
  • Working exploit primitive (file read, token forge, or SSRF callback)
  • Full exploit chain to flag capture

By the numbers

  • 20+ referenced technique sub-documents covering distinct web bug classes
  • Covers CVEs including CVE-2024-28184 and CVE-2025-55182
  • 5-step first-pass workflow with 5 pivot rules to companion skills

Files

SKILL.mdMarkdownGitHub ↗

CTF Web Exploitation

Use this skill as a routing and execution guide for web-heavy challenges. Keep the first pass short: map the app, confirm the trust boundary, and only then dive into the detailed technique notes.

Prerequisites

Python packages (all platforms):

pip install sqlmap flask-unsign requests

Linux (apt):

apt install hashcat jq curl

macOS (Homebrew):

brew install hashcat jq curl

Go tools (all platforms, requires Go):

go install github.com/ffuf/ffuf/v2@latest

Manual install:

  • ysoserial — GitHub, requires Java (Java deserialization payloads)

Additional Resources

  • sql-injection.md - SQL injection techniques: auth bypass, UNION extraction, filter bypasses, second-order SQLi, truncation, race-assisted leaks, INSERT ON DUPLICATE KEY UPDATE password overwrite, innodb_table_stats WAF bypass
  • server-side.md - PHP type juggling, php://filter LFI, Python str.format traversal, SSTI (Jinja2, Twig, ERB, Mako, EJS, Vue.js, Smarty), SSRF (Host header, DNS rebinding, curl redirect, unescaped-dot regex, SNI FTP smuggling, mod_vhost_alias), PHP hash_hmac NULL
  • server-side-2.md - XXE (basic, OOB, DOCX upload), XML injection via X-Forwarded-For, PHP variable variables, PHP uniqid predictable filename, sequential regex replacement bypass, command injection (newline, blocklist, sendmail CGI, multi-barcode, git CLI), GraphQL injection (introspection, batching, interpolation)
  • server-side-exec.md - Direct code execution paths, upload-to-RCE, deserialization-adjacent execution, LaTeX injection, header and API abuses
  • server-side-exec-2.md - More execution chains: SQLi fragmentation, path parser tricks, polyglot uploads, wrapper abuse, filename injection, BMP pixel webshell with filename truncation
  • server-side-deser.md - Java/Python/PHP deserialization and race-condition playbooks, PHP SoapClient CRLF SSRF via deserialization
  • server-side-advanced.md - Advanced SSRF, traversal, archive, parser, framework, and modern app-server issues, Nginx alias traversal
  • server-side-advanced-2.md - Docker API SSRF, Castor/XML, Apache expression reads, parser discrepancies, Windows path tricks, rogue MySQL server file read
  • server-side-advanced-3.md - Part 3 (CSAW/35C3/ASIS/PlaidCTF 2018): WAV polyglot upload, multi-slash URL path.startswith bypass, Xalan XSLT math:random() seed guess, SoapClient _user_agent CRLF method smuggling, gopher:/// no-host URL scheme bypass, SSRF credential leak via attacker-specified outbound URL
  • server-side-advanced-4.md - Part 4: WeasyPrint SSRF/file read (CVE-2024-28184), MongoDB regex/$where blind oracle, Pongo2 Go template injection, ZIP PHP webshell, basename() bypass, wget CRLF SSRF→SMTP, Gopher SSRF to MySQL blind SQLi, React Server Components Flight RCE (CVE-2025-55182), AMQP/TLS interception via sslsplit+arpspoof, CairoSVG XXE, Bazaar repo reconstruction
  • client-side.md - XSS, CSRF, cache poisoning, DOM tricks, admin bot abuse, request smuggling, paywall bypass
  • client-side-advanced.md - CSP bypasses, Unicode tricks, XSSI, CSS exfiltration, browser normalization quirks, postMessage null origin bypass
  • auth-and-access.md - Auth/authz bypasses, hidden endpoints, IDOR, redirect chains, subdomain takeover, AI chatbot jailbreaks
  • auth-and-access-2.md - Part 2 (2018-era): std::unordered_set bucket collision auth bypass, nodeprep.prepare Unicode homograph username collision, SRP A=0/A=N auth bypass, ArangoDB AQL MERGE privilege escalation
  • auth-jwt.md - JWT/JWE manipulation, weak secrets, header injection, key confusion, replay
  • auth-infra.md - OAuth/OIDC, SAML, CORS, CI/CD secrets, IdP abuse, login poisoning
  • node-and-prototype.md - Prototype pollution, JS sandbox escape, Node.js attack chains
  • web3.md - Solidity and Web3 challenge notes
  • cves.md - CVE-driven techniques you can match against challenge banners, headers, dependency leaks, or version strings
  • field-notes.md - Long-form exploit notes: quick references for SQLi, XSS, LFI, JWT, SSTI, SSRF, command injection, XXE, deserialization, race conditions, auth bypass, and multi-stage chains

When to Pivot

  • If the target is a native binary, custom VM, or firmware image, switch to /ctf-reverse first.
  • If the HTTP bug only gives you code execution and the hard part becomes memory corruption or seccomp escape, switch to /ctf-pwn.
  • If the "web" challenge really turns on JWT math, custom MACs, or crypto primitives, switch to /ctf-crypto.
  • If the web challenge involves analyzing logs, PCAPs, or recovering artifacts from a web server, switch to /ctf-forensics.
  • If the challenge requires gathering intelligence from public web sources, DNS records, or social media before exploitation, switch to /ctf-osint.

First-Pass Workflow

1. Identify the real boundary: browser only, backend only, mixed app, or auth flow. 2. Capture one normal request/response pair for every major feature before fuzzing. 3. Enumerate hidden functionality from JS bundles, response headers, routes, and alternate methods. 4. Classify the likely bug family: injection, authz, parser mismatch, upload, trust proxy, state machine, or client-side execution. 5. Build the smallest proof first: leak, bypass, or primitive. Save full exploit chaining for later.

Quick Start Commands

# Recon
curl -sI https://target.com
ffuf -u https://target.com/FUZZ -w wordlist.txt
curl -s https://target.com/robots.txt

# SQLi quick test
sqlmap -u "https://target.com/page?id=1" --batch --dbs

# JWT decode (no verification)
echo '<token>' | cut -d. -f2 | base64 -d 2>/dev/null | jq .

# Cookie decode (Flask)
flask-unsign --decode --cookie '<cookie>'
flask-unsign --unsign --cookie '<cookie>' --wordlist rockyou.txt

# SSTI probes
curl "https://target.com/page?name={{7*7}}"
curl "https://target.com/page?name={{config}}"

# Request inspection
curl -v -X POST https://target.com/api -H "Content-Type: application/json" -d '{}'

First Questions to Answer

  • Is the flag likely in the browser, an API response, a local file, a database row, or an internal service?
  • Does the app trust user-controlled data in templates, redirects, file paths, headers, serialized objects, or background jobs?
  • Are there multiple parsers disagreeing with each other: proxy vs app, URL parser vs fetcher, sanitizer vs browser, serializer vs filter?
  • Can you turn the bug into a smaller primitive first: read one file, forge one token, call one internal endpoint, trigger one bot visit?

High-Value Recon Checks

  • Read the HTML, inline scripts, and bundled JS before guessing the API surface.
  • Compare what the UI submits with what the backend accepts; optional JSON fields often unlock hidden paths.
  • Check obvious metadata and helper paths early: /robots.txt, /sitemap.xml, /.well-known/, /admin, /debug, /.git/, /.env.
  • Try alternate verbs and content types on interesting routes: GET, POST, PUT, PATCH, TRACE, JSON, form, multipart, XML.
  • Treat file upload, PDF/export, webhook, OAuth callback, and admin bot features as likely exploit multipliers.

Fast Pattern Map

  • SQL errors, odd filtering, or state-dependent DB behavior: start with sql-injection.md.
  • Templating, file reads, SSRF, command execution, XML, or parser bugs: start with server-side.md and server-side-exec.md.
  • XSS, CSP bypass, admin bot, client routing, DOM issues, or scriptless exfiltration: start with client-side.md.
  • Session forgery, hidden admin routes, JWT, OAuth, SAML, or weak trust boundaries: start with auth-and-access.md, auth-jwt.md, and auth-infra.md.
  • Node.js apps, prototype pollution, VM sandboxes, or SSRF into internal services: add node-and-prototype.md.
  • Smart contract frontends or blockchain-integrated apps: add web3.md.

Common Chain Shapes

  • Recon -> hidden route -> auth bypass -> internal file read -> token or flag
  • XSS or HTML injection -> admin bot -> privileged action -> secret leak
  • Traversal or upload -> config/source leak -> secret recovery -> session forgery
  • SSRF -> metadata or internal API -> credential leak -> code execution
  • SQLi or NoSQL injection -> credential bypass -> second-stage template or upload abuse

Deep-Dive Notes

Use field-notes.md once you have confirmed the challenge is truly web-heavy and you need the long exploit catalog.

  • Recon, SQLi, XSS, traversal, JWT, SSTI, SSRF, XXE, and command injection quick notes
  • Deserialization, race conditions, file upload to RCE, and multi-stage chain examples
  • Node, OAuth/SAML, CI/CD, Web3, bot abuse, CSP bypasses, and modern browser tricks
  • CVE-shaped playbooks and older challenge patterns that still show up in modern CTFs

Common Flag Locations

  • Files: /flag.txt, /flag, /app/flag.txt, /home/*/flag*
  • Environment: /proc/self/environ, process command line, debug config dumps
  • Database: tables named flag, flags, secret, or seeded challenge content
  • HTTP: custom headers, archived responses, hidden routes, admin exports
  • Browser: hidden DOM nodes, data-* attributes, inline state objects, source maps

Related skills

How it compares

Choose ctf-web for CTF-style offensive auth walkthroughs; use OWASP cheat sheets when you need production checklist guidance without exploit reproduction detail.

FAQ

When should I pivot away from ctf-web to another skill?

Pivot to ctf-pwn if the web bug leads to memory corruption, ctf-crypto if the challenge centres on JWT math or custom MACs, ctf-reverse for native binaries, ctf-forensics for PCAP/log analysis, and ctf-osint for public intelligence gathering.

What tools does this skill require?

Python packages sqlmap, flask-unsign, requests; system tools hashcat, jq, curl; Go tool ffuf; and optionally ysoserial (Java) for deserialization payloads. Requires a filesystem-based agent with bash, Python 3, and internet access.

How should an agent approach a new web challenge?

Follow the five-step first-pass: identify the trust boundary, capture baseline requests, enumerate hidden functionality from JS/headers/routes, classify the bug family, then build the smallest proof-of-concept primitive before chaining.

Is Ctf Web safe to install?

skills.sh reports 0 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappseccompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.