competition-bundle-sourcemap-recovery Skill
ctf-sandbox-orchestrator 的内部下游技能。针对 source map、构建清单、chunk 注册表、产出的 bundle、混淆加载器流程及前端运行时还原的 CTF-sandbox 工作流。当用户要求重建所服务 JavaScript 的结构、检查 source map 或 chunk 映射、追踪 bundle 加载、从产物中还原隐藏路由或 API、或从构建后的前端产物解释运行时行为时使用。仅在 `$ctf-sandbox-orchestrator` 已建立沙箱假设并路由至此之后使用。
安装方式:把技能目录放入 ~/.claude/skills/(Claude Code)或在 claude.ai 设置中启用;也可复制右侧安装命令一键添加。
技能指令原文(SKILL.md)
Competition Bundle Sourcemap Recovery
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when runtime truth lives in built assets, source maps, chunk tables, or obfuscated loader flow rather than in checked-in source alone.
Reply in Simplified Chinese unless the user explicitly requests English.
Quick Start
- Start from the served artifact set: entry HTML, build manifest, bootstrap bundle, chunk map, and source maps.
- Record chunk ids, route chunks, loader functions, endpoint strings, and config keys before broad manual deobfuscation.
- Reconstruct the smallest runtime graph that explains which asset executes now.
- Keep served artifact truth separate from repository source unless parity is proven.
- Reproduce the smallest asset-to-runtime boundary that proves the decisive behavior.
Workflow
1. Map The Served Artifact Set
- Record entry HTML, script tags, preload hints, manifest files, asset map, chunk registry, and source map URLs.
- Note framework-specific artifacts such as route manifests, client reference manifests, or lazy-loader tables when present.
- Keep emitted filenames, hash suffixes, and route ownership tied together.
2. Reconstruct Runtime Structure
- Follow bootstrap code, chunk loaders, module registry, string decoders, and lazy import boundaries.
- Use source maps, manifest files, and stable symbol clusters to recover route names, API calls, feature flags, and hidden panels.
- Distinguish build-time intent from the bundle that is actively served now.
3. Reduce To The Decisive Bundle Path
- Compress the result to the smallest sequence: served asset -> loader path -> module or symbol -> runtime effect.
- State clearly whether the decisive weakness lives in manifest drift, chunk loading, hidden route code, string decoding, or stale source assumptions.
- If the task shifts from built assets to SSR or template enforcement, hand back to the tighter template-render skill.
Read This Reference
- Load
references/bundle-sourcemap-recovery.mdfor the artifact checklist, deobfuscation checklist, and evidence packaging.
What To Preserve
- Served filenames, chunk ids, manifest entries, source map paths, recovered symbols, and endpoint strings
- The exact executing bundle or module that proves the runtime branch
- One minimal asset-to-runtime sequence that reaches the decisive effect