CTF Key Recovery

SkillWeb & browsing

Lets your agent recover keys, serials, and flags in CTF reverse challenges using XOR analysis, SMT solving, and brute force.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the CTF Key Recovery skill

About this skill

Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. Use when a reverse challenge requests a key or serial and the verifier or encrypted target bytes can be recovered statically

What this skill tells your AI

The instructions your AI receives, as published by manyuegong33/r0crawl_skills in skills/ctf-key-recovery/SKILL.md and read by ahel’s review.

Reconstruct the exact verifier

Write down input normalization, encoding, required length, transforms, comparison bytes, success condition, and retry behavior. Separate presentation decoding from authentication logic; similar XOR loops may use different keys.

Use the cheapest invertible relation

For repeating XOR with period p:

cipher[i] = plain[i] XOR key[i mod p]
key[i mod p] = cipher[i] XOR plain[i]

Recover every key position from known plaintext and reject inconsistent positions. Run scripts/recover_repeating_xor.py for a reproducible derivation.

Escalate only as needed:

  1. algebraic inversion
  2. known-plaintext constraints
  3. printable/format constraints
  4. SMT solver
  5. bounded brute force

See references/verifier-checklist.md before declaring success.

Validate twice

  1. Re-encrypt or replay the recovered key against the reconstructed verifier.
  2. Run the original challenge through its real input path and observe the success branch.

Record the raw key separately from any platform wrapper such as flag{...}.

Quality gates

  • Do not treat a plaintext-looking substring as the answer without verifier parity.
  • Do not mix display constants with comparison constants.
  • Preserve byte order, signedness, encoding, and terminators.
  • Test wrong length, one-byte mutation, and the recovered key.

Signals

GitHub stars
285
Forks
100
Last commit
Sep 2026

ahel review

  • K6low
    bundled executables the agent is told to run

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Catalog kind
skill
Key
ctf-key-recovery
Source
github.com/manyuegong33/r0crawl_skills