ctfd-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CTFD_URL | Yes | The URL of the CTFd instance, e.g. https://demo.ctfd.io | |
| CTFD_TOKEN | Yes | Your CTFd access token | |
| CTFD_TIMEOUT | No | Per-request timeout in seconds (default: 25) | 25 |
| CTFD_FILES_DIR | No | Download directory for challenge files (default: ctf_files) | ctf_files |
| CTFD_VERIFY_TLS | No | Set to 0 to disable TLS verification for self-signed lab CTFds (default: 1). Warning: the API token then rides an unverified connection, so use only on a trusted LAN. | |
| CTFD_ALLOW_PRIVATE_FETCH | No | Set to 0 to block fetch_url/downloads from reaching private/loopback hosts (default: 1). Cloud-metadata / link-local (169.254.x) is always blocked. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| ctf_listB | List challenges. unsolved=True hides solved; filter by category/name; easy-first (most solves). Returns id, name, category, value, solves, solved. |
| ctf_showA | Full details for one challenge (id or name): description, connection_info, files, hints, tags, value, solves. |
| ctf_downloadA | Download a challenge's CTFd-hosted files (id or name) into CTFD_FILES_DIR//. Returns dir + saved files + connection_info. |
| ctf_submitA | Submit a flag for a challenge (id or name). Returns {status: correct/incorrect/already_solved/paused/ratelimited, message}. |
| ctf_solvedA | List challenge names already solved by you / your team. |
| ctf_hintsA | List hints for a challenge (id or name). unlock=True spends points to reveal content (default: just list titles/costs). |
| ctf_scoreboardB | Live scoreboard: top N teams/users by score. |
| ctf_meA | Your own team (team mode) or user (user mode) info: name, score, place. Auto-detects the CTFd mode. |
| fetch_urlA | GET any URL (e.g. a challenge instance file http://host/files/x.pcap) and save it to CTFD_FILES_DIR/_fetched/. Returns path, size and a short text preview. For services that serve files off-CTFd. |
| whale_listA | [ctfd-whale] List your team's LIVE dynamic instances: challenge, category, access host, remaining seconds. Returns {error} if the CTF has no ctfd-whale plugin. |
| whale_startB | [ctfd-whale] Start a dynamic instance for a challenge (id or name). Returns {host, access, remaining_s} or {slots_full, detail}. |
| whale_stopA | [ctfd-whale] Stop/destroy the dynamic instance for a challenge you own (id or name). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
Most tools target distinct resources/actions (list, show, download, submit, hints, scoreboard, me, whale instances). Minor overlap between ctf_solved and ctf_list (which can hide solved), and ctf_me vs ctf_scoreboard, but descriptions clarify boundaries well.
Clean ctf_-prefixed verb/noun pattern across the core eight tools, with whale_* grouping the plugin tools consistently. fetch_url deviates from the prefix scheme but is a single understandable outlier.
12 tools is well-scoped for a CTFd client, covering the full player workflow plus dynamic instances without redundancy. Each tool earns its place.
Strong lifecycle coverage: discover, inspect, download, submit, hints, scoreboard, personal info, and whale instance control. Missing team join/create and some auth management, but core competitive workflows are covered.