4w zhaoxuya520

competition-crypto-mobile Skill

ctf-sandbox-orchestrator 的内部下游技能。针对密码学、编码、隐写术、APK、IPA 及移动信任边界挑战的 CTF-sandbox 工作流。当用户要求解码 blob、还原变换链或密钥、检查隐藏媒体载荷、hook APK 或 IPA 签名、检查应用存储、或重放移动端请求签名逻辑时使用。仅在 `$ctf-sandbox-orchestrator` 已建立沙箱假设并路由至此之后使用。

安装方式:把技能目录放入 ~/.claude/skills/(Claude Code)或在 claude.ai 设置中启用;也可复制右侧安装命令一键添加。

查看源码

技能指令原文(SKILL.md)

Competition Crypto Mobile

Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.

Use this skill when the active challenge depends on recovering a transform chain, hidden media payload, mobile signing path, or local trust boundary.

Reply in Simplified Chinese unless the user explicitly requests English.

Quick Start

  1. Decide whether the dominant path is crypto, stego, or mobile.
  2. Recover transforms in order; do not jump straight to the fanciest algorithm.
  3. Record exact parameters and boundaries that affect the result.
  4. Hook the narrowest mobile boundary that proves the behavior.
  5. Reproduce the plaintext, payload, signed request, or accepted branch.

Workflow

1. Crypto And Encoding

  • Reconstruct the chain step by step: container, compression, encoding, xor or substitution, crypto, integrity, final parse.
  • Keep exact keys, IVs, nonces, salts, tags, offsets, and byte order.

2. Stego

  • Inspect metadata, chunk layout, palettes, alpha planes, LSBs, thumbnails, trailers, and transcoding artifacts.
  • Rank decode attempts by evidence, not by brute-force curiosity.

3. Mobile

  • Start with manifest or plist, exported components, deeplinks, native libs, shared prefs, local DBs, and configs.
  • Trace signer logic, token storage, SSL pinning, protobuf or RPC boundaries, and native bridge calls.

Read This Reference

  • Load references/crypto-mobile.md for the transform checklist, hook targets, and evidence packaging.
  • If the task is specifically about Android dynamic tracing, signer hooks, JNI boundaries, or pinning checks, prefer $competition-android-hooking.
  • If the task is specifically about iOS runtime tracing, Keychain access, Objective-C or Swift hooks, or pinning checks inside an IPA, prefer $competition-ios-runtime.
  • If the task is specifically about media carriers, hidden channels, thumbnails, or appended trailers, prefer $competition-stego-media.

What To Preserve

  • Decisive bytes proving each decode stage
  • Hook points, signed strings, headers, and local storage paths
  • Component names, protobuf fields, channel-specific outputs, or trailer offsets