# Ctf-super-hub is a 35 skill router whose safety rules are prose, not controls

> Ctf-super-hub bundles CTF and reverse engineering skills for AI coding assistants and routes a challenge to the right one through a single main entry point. It states two contracts that keep it from running away, and both of them live inside a skill file rather than in any permission check, allowlist or stop control.

**asdfgh1445/ctf-super-hub** —  面向小白用户的 CTF / 逆向 Skills 整合包：自动分流、头脑风暴、教学模式、比赛模式、只提示模式

- Repository: https://github.com/asdfgh1445/ctf-super-hub
- Stars: 826 · Forks: 104
- Language: JavaScript
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/asdfgh1445-ctf-super-hub

## The two contracts are instructions to a model

The page names two rules that are supposed to stop the router from misbehaving, and they are worth reading closely because of what kind of thing they are.

The first is a handoff contract. A skill's task is not finished until it is, it does not discuss where to go next when it finishes, and control only returns to the orchestrator when the person explicitly asks what is next. The stated purpose is to stop it volunteering to run a whole chain of skills on its own. The second is install-aware routing: on every run the orchestrator first scans the machine for skills that are actually installed, and anything absent is not a candidate. The stated purpose is to stop it recommending something you do not have.

Both rules live in a skill file, which means both are requests to the model rather than constraints on it. There is no permission boundary here, no target allowlist, no dry run and no switch that stops a run. Whether the scan in the second contract can even happen depends on whether the host assistant has a way to enumerate what is installed. A well written instruction is a real improvement over no instruction, and it is not a control.

## The enhancement layer expands its own target range

The scope question is the one to settle before anything else, and the answer is that nothing in the design addresses it. The main entry classifies a challenge, optionally brainstorms first, then dispatches. The second layer, the skills prefixed `strix-`, is described as an enhancement used for web, interface and vulnerability verification actions rather than a second system.

That layer is where the range expands. The bundled skills cover the usual web vulnerability classes, and they include wrappers for enumeration and fuzzing tools: a content discovery fuzzer, an HTTP probing tool, a crawler, a template scanner and an injection testing tool, plus a quick-start and a standard entry. Tools in that family are designed to take a seed and go, which is exactly the behaviour that turns an authorisation scoped to one host or one programme into activity against systems nobody agreed to.

So the honest way to read this repository is: it is fine on a challenge you own, in a lab, or inside a scope you have written down. It is not fine pointed at a third party's infrastructure, because nothing in the router asks whether the current target is inside a boundary. The page does not describe a per-target confirmation, a dry run mode, or a way to interrupt a chain once it has started.

## Three of the four install paths are the same three lines

Four assistants are supported and the documentation spends most of its length on them. One uses a script. Three use the same manual copy with the path swapped.

The Codex path runs an included shell script, `./install-to-codex.sh`, optionally with a target directory as its argument. The page says it creates the destination, backs up any skill of the same name that is already there, and copies the relevant skills across. The other three are one command each, differing only in the directory:

```bash
mkdir -p ~/.claude/skills
cp -R brainstorming solve-challenge ctf-* strix-* ~/.claude/skills/
```

The same pair with `~/.gemini/skills` and again with `~/.opencode/skills` completes the list. So the backup behaviour exists in one of four paths and not in the other three. Reinstalling over an existing skill with the manual commands overwrites it silently, which for a bundle whose skills carry routing logic means a stale router can survive an upgrade with no warning.

The OpenCode entry is hedged more than the others. Its skills directory is described as possibly differing between versions and distributions, so the documented path is a guess, and the instruction is simply to substitute your real directory at the end of the command.

## The documented copy command fails loudly under zsh

The manual install depends on shell globbing, and the page documents the failure mode itself. If you are not in the repository root, the `ctf-*` pattern matches nothing, and zsh reports:

```bash
no matches found: ctf-*
```

The page treats this as the single most common beginner error and tells the reader to change into the repository directory and try again. That diagnosis is right, and it also shows a difference between shells that the page does not draw out. In zsh an unmatched glob is an error that stops the command. In bash it is passed through literally, so the copy is attempted with the string `ctf-*` as a filename and fails with an unrelated error, or in some shapes quietly does less than intended.

The verification section offers three checks, and the first is the cheapest: list the installed directory and look for `SKILL.md` inside the main entry. The second sends a fixed test prompt asking the assistant to confirm it has entered the working style without solving anything. The third is the troubleshooting list, which ends with the directory check above.

A fourth entry, the beginner variant, exists as a separate skill with routing rules from the same source and gentler wording, including a plain language explanation of every term.

## Three output styles, and one of them protects the answer

The modes are a difficulty dial, which is unusual for this kind of bundle. Three styles are available: a teaching style that walks through the problem, a competition style, and a hints-only style. The hints-only mode is instructed not to expand the full solution and instead to say what to look at next and why, which is the only mode in the repository with a property that matters beyond convenience. It is the mode that keeps a challenge solvable by the person rather than by the assistant.

The competition mode returns only the one to three steps most worth doing next, which is a different constraint: not withholding the solution but refusing to bury it under a plan. Routing is separate from style. The automatic mode assumes the material is in hand, a problem statement, an attachment, a URL, a host and port pair, source, or an executable, and it classifies, decides whether to switch to a more specific skill, and returns those next steps. The brainstorm mode is for when the inputs do not add up yet, and it works in the other order: clarify the goal, sort the clues and the gaps, then decide which skill to call.

Team use is bounded rather than open ended: one lead and at most two assistants, with the roles split. The page's own summary of the design is that it is not there to teach you the field, it is there to get you started on the problem in front of you.

## Thirty five skill directories and one glob that installs all of them

The repository root is the package. There are thirty five skill directories: twelve named `ctf-` prefixed covering super hub, a beginner variant, crypto, forensics, malware analysis, misc, osint, pwn, reverse, web, writeup and an AI and machine learning category, plus two general skills for brainstorming and solving a challenge, plus twenty one `strix-` prefixed skills.

Two of those category names are worth noting. A malware analysis category is defensive in the ordinary sense and fits a capture the flag round. An AI and machine learning category is not a classic flag category at all, which suggests the set is organised around what people are being asked rather than around a fixed taxonomy. The `opportunity-taxonomy`-style discipline is absent here; the classification is a router's judgement call.

The install glob is the practical consequence. `ctf-*` and `strix-*` in the copy command reach every one of those directories, so the documented install gives a user all thirty five skills or none, and there is no documented way to take a subset. For someone who wanted only the reverse engineering half, that means either editing the command by hand or installing everything and ignoring what is not wanted.

Around the skills sit the ordinary repository files: a start page, a skill index, user documentation, a community page, a licence file, a third party notices file, an update manifest, a scripts directory and an evaluations directory.

## Licensing is asserted nowhere on the page

Three facts about the repository's own paperwork are worth stating together. The repository records no licence value at all, which means the metadata cannot tell you what terms apply. A licence file sits at the root. A third party notices file sits beside it, which is what a bundle that redistributes or wraps other people's tools would need. And the README, which is otherwise thorough about installation and troubleshooting, never names a licence.

This is the one gap that cannot be resolved by inference. A licence file whose terms are unknown is not a weaker claim than an absent one, and for a bundle that wraps named third party tools, the notices file implies obligations that depend on identifying those terms. Anyone planning to redistribute this bundle, or use it inside an organisation with a policy review, has to open both files and read them; nothing on the page will do it for them.

Two smaller observations. There are no published releases, so the update manifest at the root is the only version signal, and the page promises sections on upgrading, version checking, quality assurance and verification in its table of contents. The recorded primary language is JavaScript, while the only executable file visible in the listing is the shell installer, which puts the JavaScript inside the scripts and skills directories rather than at the root.

## Conclusion

This is a routing and teaching layer rather than a toolkit, and it is useful in the situation it names: you have a challenge in front of you and no idea where to start. That framing also decides the scope question. The bundled enhancement skills wrap enumeration and fuzzing tools that reach outward on their own, and the page describes no per-target authorisation check, no dry run and no stop control, so this belongs on a machine pointed at challenges you are allowed to attack and nowhere else. Three things to check before using it. Read the two contracts and notice they are instructions to a model rather than enforcement. Decide whether you want the hints-only mode or the competition mode, since that choice is the difference between a hint and a spoiler. And settle the licensing question yourself, because the repository records no licence value while shipping both a license file and third party notices.

## FAQ

### What is ctf-super-hub?

It is a bundle of skills for AI coding assistants aimed at people new to capture the flag competitions. A single main entry point classifies a challenge and routes it to a category skill, with a beginner variant and an enhancement layer for web and vulnerability work.

### Which AI tools does ctf-super-hub install into?

Four paths are documented: Codex through an included shell script that backs up existing skills first, and Claude Code, Gemini CLI and OpenCode by creating a local skills directory and copying the skill folders into it. The page notes the OpenCode directory may differ between versions and distributions.

### Does ctf-super-hub restrict which targets its tools touch?

No such control is described. The page states two contracts, that a skill hands control back when its task is done and that the router only recommends skills actually installed, and both are written as instructions inside a skill file. No per-target authorisation check, dry run or stop control is mentioned.

### What is the difference between the hints-only and competition modes?

Hints-only is told not to expand the full solution and instead to say what to look at next and why. Competition mode returns only the one to three steps most worth doing next. Teaching is the third style, and routing either starts automatically from the inputs you have or brainstorms first when those inputs are unclear.

### Is ctf-super-hub licensed and released?

The repository records no licence value while a licence file and a third party notices file sit at its root, and the README does not name the terms. There are no published releases either, and an update manifest at the root is the only version signal.

## Sources

- [asdfgh1445/ctf-super-hub on GitHub](https://github.com/asdfgh1445/ctf-super-hub)
- [Issues](https://github.com/asdfgh1445/ctf-super-hub/issues)
- [README](https://github.com/asdfgh1445/ctf-super-hub/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/asdfgh1445-ctf-super-hub
