跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

CTF•新手入口

面向中文用户和新手的统一入口,保持原有两种模式:1) 自动分流,2) 先头脑风暴再分流。分流目标既可以是 ctf-*,也可以在 Web/接口/漏洞验证阶段增强到 strix-*;适合不知道该用哪个 skill、想先理清题意、又不想自己先判断何时该切到工具链或漏洞专项的场景;触发名:ctf-beginner-hub

安全834ctf-beginner-hub/SKILL.md

安装

把这段话发给 Claude Code、Codex 或 Cursor。智能体会先检查安全性,你确认后才安装。

读取 https://funcoding.ai/skills/asdfgh1445/ctf-super-hub/ctf-beginner-hub/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

CTF 新手入口

本 skill 是 ctf-super-hub(本仓库唯一编排中心)的新手变体。它不维护自己的 路由规则、strix 清单和结束条件——那些只有一份,在编排中心里,避免两处漂移。

执行方式

  1. 完整读取编排中心的规程并把它当作本次的编排规程执行:../ctf-super-hub/SKILL.md (仓库内同级的 ctf-super-hub/SKILL.md,或安装位置的 ~/.agents/skills/ctf-super-hub/SKILL.md)。 包括它的版本检查、模式判断、候选发现脚本、单/组合判断、交接契约、自检与停止条件。
  2. 在规程之上叠加本文剩下的两个新手差异。

新手差异 1:首次触发先给教程

用户第一次使用、或明确说「教我怎么用」时,先完整输出:

欢迎使用 CTF skill 套件。你不需要知道有哪些 skill——把题目材料直接发过来就行: 题面、附件路径、URL、服务地址、看不懂的报错,说得乱也没关系。

我会判断这题更像哪一类、单项能力够不够,需要组队时最多 1 个主 skill 加 2 个辅助, 然后给你可以直接执行的第一步,每一步都解释在干什么。

每次只处理一道题。解出之后如果你想复盘,我会再帮你整理成可提交的 writeup。

已有真实任务时,教程末尾说明材料已保留,等确认或直接进入编排。

新手差异 2:输出在编排中心契约上加码

  • 术语用一句人话解释——编排中心输出契约的第 6 项对新手是硬要求。
  • 每一步给具体命令或具体动作,不写「进行分析」这类空话。
  • 用户没有指定方向时的默认策略:已有附件/URL/服务 → 自动分流;只有模糊题面、 明显迷茫 → 先头脑风暴再分流;已确认 Web 题并进入验证阶段 → 允许增强到 strix-*。
  • 不展示完整 skill 目录,只说本轮用哪个、为什么。

相似的 Skill

security-and-hardening
addyosmani/agent-skills103k

security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.

安全

archify
tt-a1i/archify80k

archify

Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as explorable standalone HTML with inline SVG, dark/light themes, optional trace motion, and PNG/JPEG/WebP/SVG/WebM export. Accept plain-language requirements or pasted Mermaid flowchart, sequenceDiagram, and stateDiagram input; inspect repository evidence when the diagram must reflect real code. Use when the user asks to visualize system architecture, infrastructure, cloud/security/network topology, technical workflows, API call sequences, request lifecycles, data pipelines, ETL/ELT, data lineage, state machines, or to convert/beautify Mermaid. Also use for everyday subjects with steps, parts, relationships, or states: a leave or travel plan, an application or approval process, a back-and-forth such as renting, where money or documents go, or where an application or order stands. Not for numeric charts or dashboards.

安全

security-research
code-yeongyu/oh-my-openagent70k

security-research

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

安全

007
sickn33/agentic-awesome-skills47k

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

安全

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

安全

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

安全