Skip to content
FunCoding

Search

Search docs, Skills and MCP

asdfgh1445/ctf-super-hub

30 Skills.

头脑风暴
asdfgh1445/ctf-super-hub834

头脑风暴

用于在正式动手前先澄清目标、约束、边界与方案,适合需要先理清问题再决定后续 skill 或实现路径的场景;触发名:brainstorming

Security

CTF•AI/ML 攻防
asdfgh1445/ctf-super-hub834

CTF•AI/ML 攻防

用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml

Security

CTF•新手入口
asdfgh1445/ctf-super-hub834

CTF•新手入口

面向中文用户和新手的统一入口,保持原有两种模式:1) 自动分流,2) 先头脑风暴再分流。分流目标既可以是 ctf-*,也可以在 Web/接口/漏洞验证阶段增强到 strix-*;适合不知道该用哪个 skill、想先理清题意、又不想自己先判断何时该切到工具链或漏洞专项的场景;触发名:ctf-beginner-hub

Security

CTF•密码学
asdfgh1445/ctf-super-hub834

CTF•密码学

用于 RSA、AES、ECC、格攻击、LWE、CVP、Coppersmith、Pollard、Wiener、填充预言机、GCM、KDF、伪随机数与零知识证明等密码学和数学类 CTF 题;触发名:ctf-crypto

Security

CTF•数字取证
asdfgh1445/ctf-super-hub834

CTF•数字取证

用于磁盘镜像、内存转储、事件日志、PCAP、隐写分析、Windows 注册表、音频信号、Docker 镜像、coredump 以及已删除文件与凭据恢复等取证类 CTF 题;触发名:ctf-forensics

Security

CTF•恶意软件分析
asdfgh1445/ctf-super-hub834

CTF•恶意软件分析

用于混淆脚本、恶意样本、自定义加密协议、C2 流量、PE/.NET 二进制、RC4/AES 通信、YARA、shellcode、进程注入与反分析等恶意软件类 CTF 题;触发名:ctf-malware

Security

CTF•杂项
asdfgh1445/ctf-super-hub834

CTF•杂项

用于编码题、pyjail、bash jail、RF/SDR、DNS 异常、Unicode、奇特语言、QR、音频、约束求解、博弈论与沙箱逃逸等跨类或边缘 CTF 题;触发名:ctf-misc

Security

CTF•开源情报
asdfgh1445/ctf-super-hub834

CTF•开源情报

用于公开资料检索、社交媒体分析、地理定位、DNS、用户名枚举、反向图片搜索、历史快照、公开记录与坐标识别等 OSINT 类 CTF 题;触发名:ctf-osint

Security

CTF•二进制利用
asdfgh1445/ctf-super-hub834

CTF•二进制利用

用于缓冲区溢出、格式化字符串、堆利用、ROP、ret2libc、shellcode、内核利用、seccomp 绕过与沙箱逃逸等 pwn 类 CTF 题;触发名:ctf-pwn

Security

CTF•逆向工程
asdfgh1445/ctf-super-hub834

CTF•逆向工程

用于二进制、APK、WASM、固件、自定义虚拟机、字节码、游戏客户端、类恶意加载器以及反调试/反分析逻辑等逆向类 CTF 题;触发名:ctf-reverse

Security

CTF•超级总控
asdfgh1445/ctf-super-hub834

CTF•超级总控

面向 CTF 新手与综合题的统一总控 skill。保持原有两种主模式:1) 自动分流,2) 先头脑风暴再分流。分流目标既可以是 ctf-*,也可以在 Web/接口/漏洞验证阶段增强到 strix-*;适合不知道该用哪个 skill、想边做边学、又不想自己先判断何时切换到工具链或漏洞专项的场景;触发名:ctf-super-hub

Security

CTF•Web 漏洞
asdfgh1445/ctf-super-hub834

CTF•Web 漏洞

用于 XSS、SQL 注入、SSTI、SSRF、XXE、JWT、鉴权绕过、文件上传、请求走私、OAuth/OIDC、SAML 与原型污染等 Web 类 CTF 题;触发名:ctf-web

Databases & data

CTF•题解写作
asdfgh1445/ctf-super-hub834

CTF•题解写作

用于把已经完成的解题过程整理成结构化、可复现、可提交的 CTF 题解文档,适合赛后复盘、队内同步与对外提交说明;触发名:ctf-writeup

Security

CTF•挑战调度器
asdfgh1445/ctf-super-hub834

CTF•挑战调度器

用于在 CTF 挑战开始时做首轮分类、轻量 triage 与 skill 路由,识别主导类别后转到对应 ctf-* skill,类别已明确时也可直接作为入口;触发名:solve-challenge

Security

Strix•JWT 身份认证测试
asdfgh1445/ctf-super-hub834

Strix•JWT 身份认证测试

Strix JWT 与 OIDC 安全测试手册,覆盖令牌伪造、算法混淆与声明篡改;触发名:strix-authentication-jwt

Security

Strix•新手入口
asdfgh1445/ctf-super-hub834

Strix•新手入口

给中文用户和新手用的 Strix Lite 统一入口:先判断该用哪一个 strix-* 工具或漏洞测试 skill,再给最小化起手步骤;适合在 Web 安全测试、工具链使用、漏洞验证时不知道先用哪个 Strix skill 的场景;触发名:strix-beginner-hub

Security

Strix•功能级授权缺陷
asdfgh1445/ctf-super-hub834

Strix•功能级授权缺陷

Strix 功能级授权缺陷测试手册,覆盖操作级权限失效、管理功能越权与 API 操作绕过;触发名:strix-broken-function-level-authorization

Security

Strix•业务逻辑漏洞
asdfgh1445/ctf-super-hub834

Strix•业务逻辑漏洞

Strix 业务逻辑漏洞测试手册,覆盖流程绕过、状态操控与领域约束破坏;触发名:strix-business-logic

Security

Strix•CSRF 测试
asdfgh1445/ctf-super-hub834

Strix•CSRF 测试

Strix CSRF 测试手册,覆盖 token 绕过、SameSite、CORS 误配与状态变更滥用;触发名:strix-csrf

Security

Strix•ffuf 用法
asdfgh1445/ctf-super-hub834

Strix•ffuf 用法

Strix ffuf 模糊测试命令手册,覆盖匹配器、过滤器与自动化友好参数;触发名:strix-ffuf

Security

Strix•httpx 用法
asdfgh1445/ctf-super-hub834

Strix•httpx 用法

Strix httpx 探测命令手册,覆盖探针参数、输出格式与自动化安全用法;触发名:strix-httpx

Security

Strix•IDOR 测试
asdfgh1445/ctf-super-hub834

Strix•IDOR 测试

Strix IDOR/BOLA 测试手册,覆盖对象级授权失效与跨账户数据访问;触发名:strix-idor

Security

Strix•信息泄露测试
asdfgh1445/ctf-super-hub834

Strix•信息泄露测试

Strix 信息泄露测试手册,覆盖报错、调试端点、元数据泄露与源码暴露;触发名:strix-information-disclosure

Security

Strix•不安全文件上传
asdfgh1445/ctf-super-hub834

Strix•不安全文件上传

Strix 文件上传安全测试手册,覆盖扩展名绕过、Content-Type 操控与路径穿越;触发名:strix-insecure-file-uploads

Security

Strix•Katana 用法
asdfgh1445/ctf-super-hub834

Strix•Katana 用法

Strix Katana 爬虫命令手册,覆盖深度、JS 抓取与稳定并发控制;触发名:strix-katana

Security

Strix•Nuclei 用法
asdfgh1445/ctf-super-hub834

Strix•Nuclei 用法

Strix Nuclei 命令手册,覆盖模板选择、高吞吐执行与自动化边界控制;触发名:strix-nuclei

Security

Strix•开放重定向
asdfgh1445/ctf-super-hub834

Strix•开放重定向

Strix 开放重定向测试手册,覆盖钓鱼跳转、OAuth 令牌窃取与白名单绕过;触发名:strix-open-redirect

Security

Strix•路径穿越与文件包含
asdfgh1445/ctf-super-hub834

Strix•路径穿越与文件包含

Strix 路径穿越与文件包含测试手册,覆盖本地/远程文件访问与代码执行链;触发名:strix-path-traversal-lfi-rfi

Security

Strix•快速扫描
asdfgh1445/ctf-super-hub834

Strix•快速扫描

Strix 快速安全评估模式,面向高影响漏洞的限时测试;触发名:strix-quick

Security

Strix•远程代码执行
asdfgh1445/ctf-super-hub834

Strix•远程代码执行

Strix RCE 测试手册,覆盖命令注入、反序列化、模板注入与代码求值;触发名:strix-rce

Security