Skip to main content
Glama
umbra2728

CTFd MCP Server

by umbra2728

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
CTFD_URLNoThe URL of the CTFd server (e.g. https://ctfd.example.com)
CTFD_TOKENNoUser token for authentication (not admin token)
CTFD_SESSIONNoSession cookie if tokens are disabled
CTFD_TIMEOUTNoTotal timeout in seconds (default: 20s)
CTFD_PASSWORDNoYour CTFd password for login authentication
CTFD_USERNAMENoYour CTFd username for login authentication
CTFD_CSRF_TOKENNoOptional CSRF token, only if the server/plugin requires CSRF for ctfd-owl
CTFD_READ_TIMEOUTNoRead timeout in seconds (default: 15s)
CTFD_CONNECT_TIMEOUTNoConnect timeout in seconds (default: 10s)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_challengesB

List visible challenges. Optional filter by category and unsolved only.

challenge_detailsA

Get challenge details (description, files, meta) by ID.

submit_flagC

Submit a flag for a challenge ID.

start_containerB

Unified start: detects plugin (whale/ctfd-owl/k8s) and starts container.

stop_containerC

Unified stop: whale requires container_id; ctfd-owl/k8s require challenge_id.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.2/5.0

Scored across 5 tools

Disambiguation5/5

Each tool targets a distinct action: starting/stopping containers, listing challenges, viewing details, and submitting flags. There is no overlap between the five tools.

Naming Consistency4/5

Tool names follow a consistent verb_noun pattern (start_container, list_challenges, challenge_details, submit_flag, stop_container). 'challenge_details' is a noun phrase rather than a verb_noun like 'get_challenge', but the pattern is still clear and predictable.

Tool Count5/5

Five tools is well-scoped for a CTFd server: it covers the core user-facing actions of browsing challenges, getting details, submitting flags, and managing challenge containers. Each tool earns its place.

Completeness4/5

The surface covers the main CTF participant workflow: list challenges, view details, start/stop containers, and submit flags. Minor gaps exist such as no tool for viewing container status or listing active containers, but agents can work around these with the provided tools.

Maintenance

ActivityInactive
ResponsivenessNo issues