CTF Key Recovery

SkillWeb & browsing

Lets your agent recover keys, serials, and flags from CTF challenges using known plaintext, XOR, and brute force.

Use CTF Key Recovery in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add CTF Key Recovery and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the CTF Key Recovery skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

CTF Key RecoveryStart free
About this skill

Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. Use when a reverse challenge requests a key or serial and the verifier or encrypted target bytes can be recovered statically

What this skill tells your AI

The instructions your AI receives, as published by manyuegong33/r0crawl_skills in skills/ctf-key-recovery/SKILL.md and read by ahel’s review.

Reconstruct the exact verifier

Write down input normalization, encoding, required length, transforms, comparison bytes, success condition, and retry behavior. Separate presentation decoding from authentication logic; similar XOR loops may use different keys.

Use the cheapest invertible relation

For repeating XOR with period p:

cipher[i] = plain[i] XOR key[i mod p]
key[i mod p] = cipher[i] XOR plain[i]

Recover every key position from known plaintext and reject inconsistent positions. Run scripts/recover_repeating_xor.py for a reproducible derivation.

Escalate only as needed:

  1. algebraic inversion
  2. known-plaintext constraints
  3. printable/format constraints
  4. SMT solver
  5. bounded brute force

See references/verifier-checklist.md before declaring success.

Validate twice

  1. Re-encrypt or replay the recovered key against the reconstructed verifier.
  2. Run the original challenge through its real input path and observe the success branch.

Record the raw key separately from any platform wrapper such as flag{...}.

Quality gates

  • Do not treat a plaintext-looking substring as the answer without verifier parity.
  • Do not mix display constants with comparison constants.
  • Preserve byte order, signedness, encoding, and terminators.
  • Test wrong length, one-byte mutation, and the recovered key.

Signals

GitHub stars
294
Forks
103
Last commit
Sep 2026

ahel review

  • K6low
    bundled executables the agent is told to run

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
ctf-key-recovery
Source
github.com/manyuegong33/r0crawl_skills