🌐
QualityPython

CTF Web Exploitation

by ljagiello

CTF Web Exploitation is a Quality skill for Claude Code, published by ljagiello in ctf-skills.

3K stars353 forkson ljagiello/ctf-skillsAdded 2026/08/17+1% in starsRepository updated 2026/07/31
agent-skillsclaude-codeclaude-code-skillscodexcodex-clictfctf-challengesctf-toolsgeminigemini-cliopencodesecurity
Install in seconds
Install CTF Web Exploitation
Copy CTF Web Exploitation into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/ljagiello/ctf-skills/tree/main/ctf-web ~/.claude/skills/ctf-web

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/ljagiello/ctf-skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
ctf-web/SKILL.md in ljagiello/ctf-skills
Installs to
~/.claude/skills/ctf-web
Collection
One of 11 skills cataloged from this repository
Category
Quality1354 skills

What CTF Web Exploitation does

CTF Web Exploitation provides techniques for web exploitation in CTF challenges, covering XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling, OAuth/OIDC, SAML, prototype pollution, and similar web bugs. Use it when the target is an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface.

CTF Web Exploitation is cataloged under Quality on DirSkills. CTF Web Exploitation comes from a repository tagged agent-skills, claude-code, claude-code-skills, codex and codex-cli.

Documentation

README

CTF Web Exploitation

Use this skill as a routing and execution guide for web-heavy challenges. Keep the first pass short: map the app, confirm the trust boundary, and only then dive into the detailed technique notes.

Prerequisites

Python packages (all platforms):

pip install sqlmap flask-unsign requests

Linux (apt):

apt install hashcat jq curl

macOS (Homebrew):

brew install hashcat jq curl

Go tools (all platforms, requires Go):

go install github.com/ffuf/ffuf/v2@latest

Manual install:

  • ysoserial — GitHub, requires Java (Java deserialization payloads)

This is the opening of the README. Read the full README on GitHub.

Commands CTF Web Exploitation provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /ctf-reverse
  • /ctf-pwn
  • /ctf-crypto
  • /ctf-forensics
  • /ctf-osint
  • /robots
  • /sitemap
  • /admin
  • /debug
  • /flag

Frequently asked about CTF Web Exploitation

  • What else does ljagiello publish alongside CTF Web Exploitation?

    CTF Web Exploitation is one of 11 skills that DirSkills catalogs from ljagiello/ctf-skills, the repository it ships in. Its siblings there include CTF AI/ML, CTF Binary Exploitation and CTF Challenge Solver. Each one is a separate skill with its own page in this directory, installs the same way CTF Web Exploitation does, and is maintained by ljagiello in that same repository. The rest of the collection is listed on the ljagiello/ctf-skills page.

  • How does CTF Web Exploitation compare to other Quality skills?

    CTF Web Exploitation ranks #435 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of CTF Web Exploitation against them. Open each page to compare what they document and how they install.

More from ljagiello/ctf-skills

CTF Web Exploitation is one of 11 skills cataloged on DirSkills from ljagiello/ctf-skills.

See all 11 skills
🧠
2w ago

CTF AI/ML

CTF AI/ML provides techniques for attacking machine learning models and LLMs in capture-the-flag challenges, including adversarial examples, model extraction, prompt injection, and jailbreaking.
AI Engineering
3K353
🔓
2w ago

CTF Binary Exploitation

CTF Binary Exploitation provides binary exploitation techniques for CTF challenges, covering buffer overflows, ROP, heap attacks, format strings, kernel exploitation, and seccomp bypass. Use when you have a vulnerable native target and need to turn memory corruption into code execution.
AI Engineering
3K353
🚩
2w ago

CTF Challenge Solver

CTF Challenge Solver performs first-pass triage on CTF challenge bundles, files, or services to identify the dominant category and route execution to the right specialized ctf-* skill. Use it when starting a challenge with an unclear category or when you need to determine where to begin.
AI Engineering
3K353
🔐
2w ago

CTF Cryptography

CTF Cryptography provides cryptography attack techniques for CTF challenges. Use it for attacking encryption, hashing, signatures, ZKP, PRNG, and mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, and more.
Automation
3K353
🔍
2w ago

CTF Forensics

CTF Forensics provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, network captures, steganography, and more.
Data
3K353
🦠
2w ago

CTF Malware Analysis

CTF Malware Analysis provides techniques for analyzing malware and network traffic in CTF challenges, including obfuscated scripts, PE/.NET binaries, C2 protocols, and anti-analysis tricks.
Quality
3K353