Skip to content

Latest commit

ย 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

CTF-SecIDE

A Local-First AI-Powered IDE for CTF Learning & Security Education

Built with โค๏ธ by two middle school students (Grade 8), driven by curiosity and a passion for cybersecurity.

Version License Platform Tech Educational Use Only

Official Website: https://thomas-ai.space/ ๏ฝœ GitHub: https://github.com/lindenthomaslin/CTF-SeclIDE


Table of Contents


๐Ÿ’ก Introduction

CTF-SecIDE is a local-first, AI-assisted desktop IDE designed for Capture-The-Flag (CTF) contest learning and cybersecurity education.

It combines four core experiences into a single, offline-capable desktop application:

  1. AI-Powered Learning Assistant โ€” describe a learning objective in natural language, and an AI assistant explains the underlying vulnerability principles, detection techniques, and defensive countermeasures.
  2. Built-in Browser โ€” a full browser controlled over Chrome DevTools Protocol (CDP) for inspecting web applications inside the IDE.
  3. Security Tool Reference Library โ€” a curated collection of educational references and small utility scripts across web, network, and cryptography topics.
  4. Local Practice Targets โ€” two pre-built vulnerable web servers for safe, hands-on practice on your own machine.

โš ๏ธ This software is for EDUCATIONAL purposes only. It must only be used against systems you own, systems you have explicit written permission to test, or in authorized CTF competition environments. See Usage Guidelines & Compliance.


๐ŸŽฏ Why "LITE Edition"?

The publicly released version of this project is the LITE (lightweight / "ๆฎ‹่ก€็‰ˆ") edition โ€” not the full-featured version.

Why is the full version not released?

Out of respect for government regulations and applicable laws governing cybersecurity tools, the advanced attack-chain tooling that exists in the full internal version has been intentionally omitted from this public repository.

Specifically, the following were removed or replaced in the LITE edition:

Area Full Version (Internal) LITE Edition (Public)
Reverse shells / webshells Executable payloads included Removed โ€” replaced with concept explanations & defense guidance only
Attack payload dictionaries (SQLi / XSS / SSRF / etc.) Full payload libraries Removed โ€” replaced with principle documents
Weak-credential wordlists Included Removed
AI prompt templates Offensive ("attack mode") orientation Rewritten to a strictly educational ("learning mode") orientation
danger_mode bypass Configurable Hard-locked to false โ€” the interface remains, but it can never be enabled

This ensures the public project remains a legitimate learning platform, not a weapon. We believe strongly that knowledge should be shared โ€” but capability should come with responsibility.


๐Ÿง‘โ€๐ŸŽ“ A Note from the Developers

We are middle school students.

This project is developed by two Grade 8 students (aged 14โ€“15):

Role Name Notes
Founder & Core Developer linden_thomas_lin 15 years old, self-taught in programming & security
Co-founder & Core Developer soodok 14 years old, self-taught in programming & security

We started this project out of curiosity and a desire to learn โ€” we love CTF competitions, reverse engineering, and understanding how systems work (and fail). We taught ourselves Rust, Tauri, JavaScript, and cybersecurity fundamentals to build this IDE.

A few honest words from us:

  • This is a student learning project. It is not a commercial product, and there is no dedicated development team behind it.
  • We may make mistakes โ€” in code, in design, or in judgment. We welcome feedback, corrections, and mentorship from the security community. ๐Ÿ™
  • We want to grow into defenders, not attackers. That is why the LITE edition exists, and that is why we work hard to keep this project legal and educational.
  • If you are also a young person interested in security: always practice on systems you own, or in authorized CTF environments. Never touch systems without permission โ€” it is not only illegal, it is the wrong way to learn.

We are extremely grateful to the open-source community โ€” this project builds on countless open-source tools and learning resources. Thank you. โค๏ธ


๐ŸŒŸ Features

๐Ÿค– AI-Powered Learning Assistant

  • Describe a learning target in natural language; the AI breaks it down step by step
  • Explains vulnerability principles, detection approaches, and defensive countermeasures
  • Newcomer-friendly: every step is explained in plain terms
  • Slash commands: /analysis, /recon, /difficulty, /make-plugin, and more
  • Guarded prompt engine that keeps all AI interaction inside an educational scope

๐ŸŒ Built-in Browser (CDP)

  • Full browser control over Chrome DevTools Protocol
  • Live iframe preview mode + screenshot mode (switchable)
  • Address bar auto-syncs with the current page URL (2s polling)
  • Automation primitives: navigate, click, type, evaluate JS, read DOM, manage cookies
  • Console log capture & page fingerprinting

๐Ÿ“š Security Tool Reference Library (ctf_scripts/)

  • Web: SQLi / XSS / SSRF / SSTI / XXE / command injection / deserialization โ€” concept documents + small Python analysis utilities (e.g., time-based blind SQLi detector, JWT analyzer)
  • Network: subdomain enumeration, port scanning examples, fingerprinting, DNS zone-transfer tester
  • Cryptography: XOR brute-forcing, MT19937 prediction, RSA Wiener attack, Padding Oracle, hash identification, classic ciphers
  • Exploit (educational only): principle explanations & defense guidance โ€” no executable payloads

๐ŸŽฎ Local Lab (Built-in Vulnerable Targets)

Two intentionally vulnerable web servers that run locally on your machine โ€” perfect for safe, authorized practice:

Target Port Topics
VulnTarget v1 8888 SQL Injection, weak secrets, command injection, file upload, XSS
VulnTarget v2 8889 SQL Injection, IDOR, XSS, LFI, SSRF, deserialization, JWT

๐Ÿ“Š Learning Dashboard

  • Visualizes task status and learning progress
  • AI-provided success-probability extracted and shown per task
  • Long-conversation performance mode to keep CPU usage low

๐Ÿ“ฑ APK Static Analysis

  • Parse Android Binary XML (AXML) manifests โ€” no third-party dependency
  • Extract components, permissions, exported components, and certificate info
  • Scan DEX strings for secrets (API keys, URLs, tokens)
  • Optional jadx integration for full decompilation

๐Ÿ› ๏ธ Workspace & Command Sandbox

  • Per-session isolated file workspace
  • Execute commands inside the sandbox with a three-layer safety filter (hard block / dangerous / GUI-launcher detection)
  • AI can read/write files and run commands in the sandbox through the tool registry

๐Ÿงฉ Extensible Tool System

  • Built-in CTF tool registry (pure functions)
  • Custom tools: define JSON descriptors, or let the AI generate them via /make-plugin
  • MCP (Model Context Protocol) server support

๐ŸŽจ Apple-Inspired UI

  • Light theme, clean spacing, large rounded corners, restrained color palette
  • Unified design language across sidebar, browser, dashboard, and settings
  • Performance mode: one-click disable of backdrop blur, dynamic wallpapers, and light effects

๐Ÿ”’ Local-First & Private

  • Built on Tauri 2 + Rust
  • API keys and learning records stored only on your machine
  • No mandatory external backend; works offline (except AI chat, which needs your own LLM API key)

๐Ÿงฑ Tech Stack

Layer Technology Version Notes
Desktop framework Tauri 2.x custom protocol + macOS private API
Backend language Rust edition 2021 all business logic in Rust
HTTP client reqwest 0.12 rustls-tls, SSE streaming
WebSocket tokio-tungstenite 0.24 CDP communication
Async runtime tokio 1.x time / sync / macros / net
Serialization serde / serde_json 1.x IPC & config
Config parsing serde_yaml 0.9 Prompt Engine rule files
Frontend Vanilla JS / CSS โ€” no framework, single-page architecture
Dialog plugin tauri-plugin-dialog 2.x native file dialogs

Design choices:

  • No HTTP server inside the WebView โ€” frontend talks to Rust directly over Tauri IPC (no ports, no CORS)
  • rustls-tls instead of OpenSSL โ€” smaller binaries, fewer system dependencies
  • Zero frontend dependencies โ€” fast startup, fully offline-capable

๐Ÿ“ฆ Repository Structure

CTF-SeclIDE/
โ”œโ”€โ”€ README.md                 # This file
โ”œโ”€โ”€ DEVELOPMENT.md            # Technical developer documentation
โ”œโ”€โ”€ PROMPT_ENGINE.md          # Prompt Engine design document
โ”œโ”€โ”€ DISCLAIMER.md             # Disclaimer
โ”œโ”€โ”€ SECURITY.md               # Security & responsible-use guidelines
โ”œโ”€โ”€ LICENSE                   # MIT License (with educational-use restriction)
โ”‚
โ”œโ”€โ”€ prompt_engine/            # AI prompt engine (rules + templates)
โ”‚   โ”œโ”€โ”€ rules/                # YAML rule files (modules, params, targets, tasksโ€ฆ)
โ”‚   โ””โ”€โ”€ templates/            # Prompt templates (learning-mode oriented)
โ”‚
โ”œโ”€โ”€ ctf_scripts/              # Security tool reference library
โ”‚   โ”œโ”€โ”€ web/                  #   Web security learning (docs + Python tools)
โ”‚   โ”œโ”€โ”€ network/              #   Network recon (scripts + cheat sheets)
โ”‚   โ”œโ”€โ”€ crypto/               #   Cryptography (XOR / RSA / Padding Oracleโ€ฆ)
โ”‚   โ”œโ”€โ”€ exploit/              #   Concept explanations & defense only (no payloads)
โ”‚   โ””โ”€โ”€ wordlist/             #   Placeholder only (offensive dictionaries removed)
โ”‚
โ”œโ”€โ”€ target/                   # Local vulnerable lab
โ”‚   โ”œโ”€โ”€ vuln_server.py        #   Target v1 (port 8888)
โ”‚   โ””โ”€โ”€ vuln_server2.py       #   Target v2 (port 8889)
โ”‚
โ””โ”€โ”€ desktop/                  # Tauri desktop application
    โ”œโ”€โ”€ ui/                   # Frontend (index.html / app.js / style.css)
    โ””โ”€โ”€ src-tauri/            # Rust backend
        โ””โ”€โ”€ src/              # lib.rs, backend.rs, prompt_engine.rs, browser.rs,
                              # workspace.rs, network.rs, apk.rs, decoder.rs,
                              # ctf_tools.rs, ctf_plan.rs, emulator.rs

๐Ÿš€ Quick Start

Prerequisites

Requirement Version Purpose
macOS 12+ or Windows 10+ โ€” Tauri 2 supported platforms
Rust toolchain 1.75+ Rust backend
Node.js 18+ Frontend resource tooling
Python 3 โ€” Local lab (optional)
Chrome / Chromium โ€” Built-in browser (CDP)
jadx โ€” APK decompilation (optional enhancement)

Step 1 โ€” Clone

git clone https://github.com/lindenthomaslin/CTF-SeclIDE.git
cd CTF-SeclIDE

Step 2 โ€” Start the local lab (optional)

python3 target/vuln_server.py      # Target v1 โ†’ http://localhost:8888
python3 target/vuln_server2.py     # Target v2 โ†’ http://localhost:8889

Step 3 โ€” Run the desktop app (dev mode)

cd desktop/src-tauri
cargo tauri dev

Step 4 โ€” Build a release

# macOS: build .app only (avoids sandbox restrictions that break DMG packaging)
cd desktop
./node_modules/.bin/tauri build --bundles app

# Windows (optional)
npx tauri build

macOS note: Chrome 128+ requires the --disable-features=DevToolsTabTarget launch flag to restore CDP connectivity.


๐ŸŽฎ Local Lab (Built-in Targets)

The lab servers are intentionally vulnerable. Run them only on your own machine for learning purposes.

Target v1:  http://localhost:8888   (SQLi, weak secrets, command injection, file upload, XSS)
Target v2:  http://localhost:8889   (SQLi, IDOR, XSS, LFI, SSRF, deserialization, JWT)

Use the built-in browser or your own browser to explore these targets and learn how each vulnerability works โ€” and how to fix it.


๐Ÿ›ก๏ธ Usage Guidelines & Compliance

Golden rules:

  1. Authorized targets only. Use this software only against systems you own, systems with explicit written authorization, or official CTF competition environments.
  2. No real-world attacks. Never use this tool against any third-party system without permission.
  3. Local lab first. When learning, prefer the built-in targets (8888 / 8889).
  4. Respect the law. You are solely responsible for complying with the laws of your country/region.

Built-in safeguards in this project:

  • danger_mode is permanently locked to false (interface kept, but it can never be enabled)
  • Prompt Engine Guard rejects inputs outside the educational scope
  • The public repo contains no executable attack payloads (no reverse shells, webshells, or attack dictionaries)
  • Workspace command execution applies a three-layer safety filter

Full details:


๐Ÿค Contributing

We are students, and we welcome help from the community! โค๏ธ

Ways to contribute:

  • Report issues โ€” bugs, typos, documentation improvements
  • Suggest features โ€” open an issue with a clear description
  • Submit PRs โ€” code, docs, or educational content
  • Mentor us โ€” security professionals: your guidance is invaluable to young learners

Please keep all contributions educational and legal. Content must not include real-world attack payloads or materials usable for unauthorized activity.


๐Ÿ—บ๏ธ Roadmap

  • LITE-edition compliance refactor (payload removal, learning-mode prompts, danger_mode lock)
  • Professional English documentation
  • More educational lab targets (reverse engineering, cryptography challenges)
  • Built-in CTF practice question bank with auto-grading
  • Better mobile security (emulator / ADB integration)
  • Internationalization improvements
  • Community-translated documentation

This roadmap is maintained by two students โ€” contributions and suggestions are very welcome.


๐Ÿ“„ License & Disclaimer

License: MIT License with an additional educational-use restriction clause.

Copyright (c) 2026 linden_thomas_lin & soodok

Disclaimer: This open-source project is intended solely for CTF contest learning and security education. Security testing is permitted only with the target owner's written consent. Any unauthorized use is entirely the user's own responsibility; the developers and contributors assume no liability. See DISCLAIMER.md for full terms.


โญ Star this repository if you find it useful for learning! โญ

Made with โค๏ธ by middle school students, for the security-learning community.

About

CTF-SecIDE is a lightweight desktop security IDE built with Tauri, designed specifically for CTF competitions and penetration testing scenarios.

Resources

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages