github.com/zhaoxuya520/reverse-skill
| Skill | Added | Review |
|---|---|---|
competition-container-runtime CTF-Sandbox-Orchestrator/competition-container-runtime/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for live container runtime analysis, mounted secrets, sidecars, namespaces, init containers, entrypoint drift, and route-to-container resolution. Use when the user asks why a live container differs from manifests, where a mounted secret is consumed, how a sidecar or init container changes runtime state, or which route resolves to which live container. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 6aa1362 | |
competition-cloud-metadata-path CTF-Sandbox-Orchestrator/competition-cloud-metadata-path/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for cloud metadata services, instance identity, workload identity, link-local credential paths, role assumption, and metadata-to-privilege trust edges. Use when the user asks to inspect metadata-service access, instance credentials, pod or workload identity, link-local token paths, SSRF-to-metadata escalation, or explain how metadata-derived credentials turn into accepted cloud or control-plane privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 6aa1362 | |
competition-bundle-sourcemap-recovery CTF-Sandbox-Orchestrator/competition-bundle-sourcemap-recovery/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for source maps, build manifests, chunk registries, emitted bundles, obfuscated loader flow, and frontend runtime recovery. Use when the user asks to reconstruct served JavaScript structure, inspect source maps or chunk maps, trace bundle loading, recover hidden routes or APIs from emitted assets, or explain runtime behavior from built frontend artifacts. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 70 70 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 6aa1362 | |
competition-browser-persistence CTF-Sandbox-Orchestrator/competition-browser-persistence/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for browser cookies, localStorage, sessionStorage, IndexedDB, Cache Storage, service workers, offline caches, and client-side session persistence. Use when the user asks to inspect browser state, replay cached auth or session behavior, explain why a page behaves differently after load, or trace how stored client state changes requests, rendering, or access. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 80 80 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 6aa1362 | |
competition-android-hooking CTF-Sandbox-Orchestrator/competition-android-hooking/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI boundary inspection, and app trust-boundary analysis. Use when the user asks to hook an APK, inspect signer logic, trace Java or native boundaries, bypass pinning or root checks, inspect shared prefs or app databases, or replay accepted mobile requests. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 75 75 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 6aa1362 | |
competition-agent-cloud CTF-Sandbox-Orchestrator/competition-agent-cloud/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 6aa1362 | |
competition-ad-certificate-abuse CTF-Sandbox-Orchestrator/competition-ad-certificate-abuse/SKILL.md Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here. | 70 70 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 6aa1362 |