ctf-web

Identify and exploit web vulnerabilities like XSS, SQLi, and SSRF in CTF challenges.

Updated Apr 30, 2026
One-click install
npx skills add https://github.com/DexterJie/codex-skills --skill ctf-web-dexterjie
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ctf-web
Source: https://github.com/DexterJie/codex-skills/tree/main/ctf-web
Command: npx skills add https://github.com/DexterJie/codex-skills --skill ctf-web-dexterjie

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires sqlmap, flask-unsign, requests, hashcat, jq, curl, ffuf, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill empowers users with in-depth knowledge of web exploitation techniques to navigate CTF challenges and exploit web-based vulnerabilities efficiently.

Core Features & Use Cases

  • Web Vulnerability Mapping: Provides comprehensive guides for identifying and exploiting web vulnerabilities like XSS, SQLi, SSTI, SSRF, and others.
  • Technique Notes: Offers detailed instructions for exploiting web application flaws and extracting flags from a variety of web-based scenarios.
  • Quick Start Commands: Includes ready-to-use commands for reconnaissance, testing, and exploitation.

Quick Start

Activate the ctf-web skill and run the 'recon' command to begin exploring a new web-based CTF challenge.

Frequently Asked Questions about ctf-web

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify and exploit web vulnerabilities like XSS and SSRF in CTF challenges?

To identify and exploit web vulnerabilities like XSS and SSRF in CTF challenges, this skill provides comprehensive mapping guides and detailed technique notes for identifying and extracting flags from web application flaws efficiently.

What is the best way to start web exploitation reconnaissance for a new CTF target?

The best way to start web exploitation reconnaissance is to activate the skill and run the 'recon' command, which utilizes ready-to-use commands for initial testing and exploration of web-based CTF targets.

Does this web exploitation toolkit require specific dependencies like sqlmap and hashcat?

Yes, this web exploitation toolkit requires Python 3 and internet access to install specific dependencies including sqlmap, flask-unsign, requests, hashcat, jq, curl, and ffuf for comprehensive vulnerability analysis.

Can I use these CTF web exploitation techniques for SSTI and SQLi scenarios?

You can use these CTF web exploitation techniques for SSTI and SQLi scenarios because the skill focuses specifically on identifying and exploiting a wide range of web vulnerabilities including SSTI and SQLi.

Why do I need Python 3 and internet access to run these CTF web exploitation commands?

You need Python 3 and internet access to run these CTF web exploitation commands because the skill requires an active environment to install its underlying dependencies like sqlmap and ffuf for vulnerability analysis.