CTF Key Recovery
SkillWeb & browsingLets your agent recover keys, serials, and flags from CTF challenges using known plaintext, XOR, and brute force.
Use CTF Key Recovery in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add CTF Key Recovery and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the CTF Key Recovery skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. Use when a reverse challenge requests a key or serial and the verifier or encrypted target bytes can be recovered statically
What this skill tells your AI
The instructions your AI receives, as published by manyuegong33/r0crawl_skills in skills/ctf-key-recovery/SKILL.md and read by ahel’s review.
Reconstruct the exact verifier
Write down input normalization, encoding, required length, transforms, comparison bytes, success condition, and retry behavior. Separate presentation decoding from authentication logic; similar XOR loops may use different keys.
Use the cheapest invertible relation
For repeating XOR with period p:
cipher[i] = plain[i] XOR key[i mod p]
key[i mod p] = cipher[i] XOR plain[i]
Recover every key position from known plaintext and reject inconsistent positions. Run scripts/recover_repeating_xor.py for a reproducible derivation.
Escalate only as needed:
- algebraic inversion
- known-plaintext constraints
- printable/format constraints
- SMT solver
- bounded brute force
See references/verifier-checklist.md before declaring success.
Validate twice
- Re-encrypt or replay the recovered key against the reconstructed verifier.
- Run the original challenge through its real input path and observe the success branch.
Record the raw key separately from any platform wrapper such as flag{...}.
Quality gates
- Do not treat a plaintext-looking substring as the answer without verifier parity.
- Do not mix display constants with comparison constants.
- Preserve byte order, signedness, encoding, and terminators.
- Test wrong length, one-byte mutation, and the recovered key.
Signals
- GitHub stars
- 294
- Forks
- 103
- Last commit
- Sep 2026
ahel review
K6low
bundled executables the agent is told to run
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
ctf-key-recovery- Source
- github.com/manyuegong33/r0crawl_skills
github.com/manyuegong33/r0crawl_skills
Related picks
Skill · wshobson
The pick for Pythonpython-pro
Skill · jeffallan
The pick for Pythonbrowser-use
Skill · browser-use
More in Web & browsingwebapp-testing
Skill · anthropics
More in Web & browsingplaywright-cli
Skill · microsoft
More in Web & browsingbenchmark
Skill · affaan-m
More in Web & browsing