CTF Super Hub

A pack of CTF skills: one entry point classifies a challenge and routes it to a focused skill for crypto, forensics, pwn, reverse and OSINT

Skill

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Covers offensive security techniques: pwn, reverse, attacks on crypto
  • Can cause harm if used against third-party resources
All reasons and checks

asdfgh1445/ctf-super-hub

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/ctf-super-hub

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add asdfgh1445/ctf-super-hub --skill ctf-super-hub ctf-beginner-hub brainstorming solve-challenge ctf-ai-ml ctf-crypto ctf-forensics ctf-malware ctf-misc ctf-osint ctf-pwn ctf-reverse ctf-web ctf-writeup strix-authentication-jwt strix-beginner-hub strix-broken-function-level-authorization strix-business-logic strix-csrf strix-ffuf strix-httpx strix-idor strix-information-disclosure strix-insecure-file-uploads strix-katana strix-nuclei strix-open-redirect strix-path-traversal-lfi-rfi strix-quick strix-rce strix-sql-injection strix-sqlmap strix-ssrf strix-standard strix-xss -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 26, 2026, commit 16926d6.

Text for your agent

Clone the repository and run install-to-codex.sh to install into ~/.codex/skills, or manually copy the needed skill folders into your agent's skills directory.

Other ways from the author
git clone https://github.com/asdfgh1445/ctf-super-hub.git
cd ctf-super-hub
./install-to-codex.sh

The script installs skills into ~/.codex/skills; a custom directory can be passed as an argument.

This is third-party code. Review the repository files before installing.

What it does

The pack organizes CTF skills around one question: where to start once you have a challenge. A shared entry point classifies the task, a brainstorming mode helps when you are stuck, then it auto-routes to a focused skill. Sections cover cryptography, forensics, pwn, reverse engineering, OSINT, web and machine learning attacks. It has a teaching mode and a hints-only mode for those who prefer to work it out.

Who it is for. For CTF players and people learning security by working through challenges.

Good fit when

  • You have a CTF challenge but are unsure of its category
  • You want step-by-step hints for crypto, forensics, pwn or reverse
  • You want a teaching walkthrough rather than a ready answer

Not a fit when

  • The task is not a challenge but an attack on someone else's resource without permission
  • You want ready-made intrusion tooling rather than a technique walkthrough

Example request

Help me work through this CTF challenge: classify it and suggest the first step, do not give the answer outright

Limitations

The pack targets CTF and learning. Use it only on your own systems, in competitions and on ranges with explicit permission, never against third-party resources. Some material is in Chinese and English, with no single language. The skill gives walkthroughs and hints but does not guarantee a solution for every task.

How to disable. Remove the copied skill folders from your agent's skills directory, for example ~/.codex/skills or ~/.claude/skills.

Security check

  • Covers offensive security techniques: pwn, reverse, attacks on crypto
  • Can cause harm if used against third-party resources

README in short

The README frames the pack as one entry point into CTF and reverse for beginners: classify the task, brainstorm when stuck, then move to a focused skill. It describes teaching, contest and hints-only modes. Installation uses the install-to-codex.sh script or a manual copy of folders into the agent's skills directory. The repository gathers sections on crypto, forensics, pwn, reverse, OSINT, web and model attacks.

FAQ

Is this an intrusion toolkit?

No. These are educational CTF skills that help classify a task and walk through it, with teaching and hints modes.

How do I pick the right section?

Through the shared entry point: it classifies the task and routes to a focused skill for crypto, forensics, pwn, reverse or OSINT.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AICTF Super Hub

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.