Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for CTF web, API, SSR, frontend, queue-backed app, and routing challenges. Use when the user asks to inspect a site or API, follow real browser requests, debug auth or session flow, trace uploads or workers, find hidden routes, or explain why frontend and backend behavior diverge under sandbox-internal routing. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
70
85%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the active challenge is primarily about web behavior, browser state, server routing, API order, or worker-backed application flow.
Reply in Simplified Chinese unless the user explicitly requests English.
references/routing-runtime.md for the detailed checklist, evidence packaging, and common web pitfalls.$competition-template-render-path.$competition-bundle-sourcemap-recovery.$competition-graphql-rpc-drift.$competition-ssrf-metadata-pivot.$competition-race-condition-state-drift.$competition-request-normalization-smuggling.$competition-browser-persistence.$competition-oauth-oidc-chain.kid, alg, issuer or audience confusion, prefer $competition-jwt-claim-confusion.$competition-file-parser-chain.$competition-queue-worker-drift.$competition-websocket-runtime.$competition-runtime-routing.$competition-pcap-protocol.6aa1362
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.