CTFd MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CTFD_URL | No | The URL of the CTFd server (e.g. https://ctfd.example.com) | |
| CTFD_TOKEN | No | User token for authentication (not admin token) | |
| CTFD_SESSION | No | Session cookie if tokens are disabled | |
| CTFD_TIMEOUT | No | Total timeout in seconds (default: 20s) | |
| CTFD_PASSWORD | No | Your CTFd password for login authentication | |
| CTFD_USERNAME | No | Your CTFd username for login authentication | |
| CTFD_CSRF_TOKEN | No | Optional CSRF token, only if the server/plugin requires CSRF for ctfd-owl | |
| CTFD_READ_TIMEOUT | No | Read timeout in seconds (default: 15s) | |
| CTFD_CONNECT_TIMEOUT | No | Connect timeout in seconds (default: 10s) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_challengesB | List visible challenges. Optional filter by category and unsolved only. |
| challenge_detailsA | Get challenge details (description, files, meta) by ID. |
| submit_flagC | Submit a flag for a challenge ID. |
| start_containerB | Unified start: detects plugin (whale/ctfd-owl/k8s) and starts container. |
| stop_containerC | Unified stop: whale requires container_id; ctfd-owl/k8s require challenge_id. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool targets a distinct action: starting/stopping containers, listing challenges, viewing details, and submitting flags. There is no overlap between the five tools.
Tool names follow a consistent verb_noun pattern (start_container, list_challenges, challenge_details, submit_flag, stop_container). 'challenge_details' is a noun phrase rather than a verb_noun like 'get_challenge', but the pattern is still clear and predictable.
Five tools is well-scoped for a CTFd server: it covers the core user-facing actions of browsing challenges, getting details, submitting flags, and managing challenge containers. Each tool earns its place.
The surface covers the main CTF participant workflow: list challenges, view details, start/stop containers, and submit flags. Minor gaps exist such as no tool for viewing container status or listing active containers, but agents can work around these with the provided tools.