CTF Key Recovery
SkillWeb & browsingLets your agent recover keys, serials, and flags in CTF reverse challenges using XOR analysis, SMT solving, and brute force.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the CTF Key Recovery skill
About this skill
Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. Use when a reverse challenge requests a key or serial and the verifier or encrypted target bytes can be recovered statically
What this skill tells your AI
The instructions your AI receives, as published by manyuegong33/r0crawl_skills in skills/ctf-key-recovery/SKILL.md and read by ahel’s review.
Reconstruct the exact verifier
Write down input normalization, encoding, required length, transforms, comparison bytes, success condition, and retry behavior. Separate presentation decoding from authentication logic; similar XOR loops may use different keys.
Use the cheapest invertible relation
For repeating XOR with period p:
cipher[i] = plain[i] XOR key[i mod p]
key[i mod p] = cipher[i] XOR plain[i]
Recover every key position from known plaintext and reject inconsistent positions. Run scripts/recover_repeating_xor.py for a reproducible derivation.
Escalate only as needed:
- algebraic inversion
- known-plaintext constraints
- printable/format constraints
- SMT solver
- bounded brute force
See references/verifier-checklist.md before declaring success.
Validate twice
- Re-encrypt or replay the recovered key against the reconstructed verifier.
- Run the original challenge through its real input path and observe the success branch.
Record the raw key separately from any platform wrapper such as flag{...}.
Quality gates
- Do not treat a plaintext-looking substring as the answer without verifier parity.
- Do not mix display constants with comparison constants.
- Preserve byte order, signedness, encoding, and terminators.
- Test wrong length, one-byte mutation, and the recovered key.
Signals
- GitHub stars
- 285
- Forks
- 100
- Last commit
- Sep 2026
ahel review
K6low
bundled executables the agent is told to run
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Catalog kind
- skill
- Key
ctf-key-recovery- Source
- github.com/manyuegong33/r0crawl_skills