Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Ctf Flag Discipline

ASecurity

Flag handling and anti-guessing discipline for CTF. Load whenever a candidate flag is produced or a challenge nears solving. Enforces the flag format, forbids guessing or brute-forcing flag text, and defines what counts as a proven solve versus an assumption.

2 stars
0 votes
0 copies
0 views
Added 9/28/2026
securityrust

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add bilal-spotted/claude-code-ctf-rig --skill ctf-flag-discipline --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ctf Flag Discipline?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Ctf Flag Discipline
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/bilal-spotted-ctf-flag-discipline/badge)](https://www.skillsdirectory.com/skills/bilal-spotted-ctf-flag-discipline)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: ctf-flag-discipline
description: Flag handling and anti-guessing discipline for CTF. Load whenever a candidate flag is produced or a challenge nears solving. Enforces the flag format, forbids guessing or brute-forcing flag text, and defines what counts as a proven solve versus an assumption.
---

# CTF Flag Discipline

## Format
Expected: the format set in CLAUDE.md for this event (e.g. FLAG{...}) unless the challenge explicitly states another
format. If a recovered string does not match the expected shape, it is
probably not the flag, keep working, do not submit it hopefully.

## Hard rules
- NEVER guess flag contents. Never brute-force or fuzz the flag text
  itself against a checker.
- A flag is only real if it came from the intended solve path: the
  exploit ran, the decryption verified, the binary emitted it, the
  hidden data decoded to it.
- If you have a vulnerability but no flag, you have NOT solved it. Say so.

## Proven vs assumed
- Proven: exploit.py ran against the live target and printed the flag; or
  solve.py decrypted ciphertext to a string in the expected flag format (e.g. FLAG{...}); or the binary
  printed it on the success path with the recovered input.
- Assumed (NOT a solve): "this should give the flag", "the vuln is here
  so the flag is probably X", any flag not produced by a working artifact.

## Surface every candidate instantly (dynamic scoring)
- The instant ANY string matching the flag format appears, whether from the
  full solve, an intermediate step, a decode, a config default, or something
  you suspect is a decoy or red herring, print it at once on its own line as
  `FLAG: <string>`. Scoring weights submission time: surface first, bookkeep
  after.
- For every candidate give one line: confidence (high / medium / low) and
  exactly how it was obtained.
- Report EVERY format-matching candidate, never silently drop one you judge a
  decoy. Author creativity means your 99%-confident pick can be wrong and a
  "decoy" can be the real flag; the human decides what to submit.
- Surfacing candidates does NOT mean stopping. This never licenses guessing:
  keep digging to the end of the challenge until you reach the flag you judge
  actually accurate, surfacing each real match the moment you see it.

## On submission
- The human submits flags on the competition platform. Present the exact flag string,
  clearly, and note how it was obtained so the human can trust it.
- Record the final flag in SUMMARY.md verbatim.

## If stuck near the end
- Do not paper over a gap by guessing the flag. Return to the last
  verified step, state exactly what is missing (a leak, an offset, a
  key bit, a decode step), and solve that, or ask the human.

Attribution

bilal-spottedbilal-spotted
View sourceMore from bilal-spotted →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

813270 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

813270 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

813270 votes
View all in security →