A Local-First AI-Powered IDE for CTF Learning & Security Education
Built with โค๏ธ by two middle school students (Grade 8), driven by curiosity and a passion for cybersecurity.
Official Website: https://thomas-ai.space/ ๏ฝ GitHub: https://github.com/lindenthomaslin/CTF-SeclIDE
- Introduction
- Why "LITE Edition"?
- A Note from the Developers
- Features
- Tech Stack
- Repository Structure
- Quick Start
- Local Lab (Built-in Targets)
- Usage Guidelines & Compliance
- Contributing
- Roadmap
- License & Disclaimer
CTF-SecIDE is a local-first, AI-assisted desktop IDE designed for Capture-The-Flag (CTF) contest learning and cybersecurity education.
It combines four core experiences into a single, offline-capable desktop application:
- AI-Powered Learning Assistant โ describe a learning objective in natural language, and an AI assistant explains the underlying vulnerability principles, detection techniques, and defensive countermeasures.
- Built-in Browser โ a full browser controlled over Chrome DevTools Protocol (CDP) for inspecting web applications inside the IDE.
- Security Tool Reference Library โ a curated collection of educational references and small utility scripts across web, network, and cryptography topics.
- Local Practice Targets โ two pre-built vulnerable web servers for safe, hands-on practice on your own machine.
โ ๏ธ This software is for EDUCATIONAL purposes only. It must only be used against systems you own, systems you have explicit written permission to test, or in authorized CTF competition environments. See Usage Guidelines & Compliance.
The publicly released version of this project is the LITE (lightweight / "ๆฎ่ก็") edition โ not the full-featured version.
Why is the full version not released?
Out of respect for government regulations and applicable laws governing cybersecurity tools, the advanced attack-chain tooling that exists in the full internal version has been intentionally omitted from this public repository.
Specifically, the following were removed or replaced in the LITE edition:
| Area | Full Version (Internal) | LITE Edition (Public) |
|---|---|---|
| Reverse shells / webshells | Executable payloads included | Removed โ replaced with concept explanations & defense guidance only |
| Attack payload dictionaries (SQLi / XSS / SSRF / etc.) | Full payload libraries | Removed โ replaced with principle documents |
| Weak-credential wordlists | Included | Removed |
| AI prompt templates | Offensive ("attack mode") orientation | Rewritten to a strictly educational ("learning mode") orientation |
danger_mode bypass |
Configurable | Hard-locked to false โ the interface remains, but it can never be enabled |
This ensures the public project remains a legitimate learning platform, not a weapon. We believe strongly that knowledge should be shared โ but capability should come with responsibility.
We are middle school students.
This project is developed by two Grade 8 students (aged 14โ15):
| Role | Name | Notes |
|---|---|---|
| Founder & Core Developer | linden_thomas_lin | 15 years old, self-taught in programming & security |
| Co-founder & Core Developer | soodok | 14 years old, self-taught in programming & security |
We started this project out of curiosity and a desire to learn โ we love CTF competitions, reverse engineering, and understanding how systems work (and fail). We taught ourselves Rust, Tauri, JavaScript, and cybersecurity fundamentals to build this IDE.
A few honest words from us:
- This is a student learning project. It is not a commercial product, and there is no dedicated development team behind it.
- We may make mistakes โ in code, in design, or in judgment. We welcome feedback, corrections, and mentorship from the security community. ๐
- We want to grow into defenders, not attackers. That is why the LITE edition exists, and that is why we work hard to keep this project legal and educational.
- If you are also a young person interested in security: always practice on systems you own, or in authorized CTF environments. Never touch systems without permission โ it is not only illegal, it is the wrong way to learn.
We are extremely grateful to the open-source community โ this project builds on countless open-source tools and learning resources. Thank you. โค๏ธ
- Describe a learning target in natural language; the AI breaks it down step by step
- Explains vulnerability principles, detection approaches, and defensive countermeasures
- Newcomer-friendly: every step is explained in plain terms
- Slash commands:
/analysis,/recon,/difficulty,/make-plugin, and more - Guarded prompt engine that keeps all AI interaction inside an educational scope
- Full browser control over Chrome DevTools Protocol
- Live iframe preview mode + screenshot mode (switchable)
- Address bar auto-syncs with the current page URL (2s polling)
- Automation primitives: navigate, click, type, evaluate JS, read DOM, manage cookies
- Console log capture & page fingerprinting
- Web: SQLi / XSS / SSRF / SSTI / XXE / command injection / deserialization โ concept documents + small Python analysis utilities (e.g., time-based blind SQLi detector, JWT analyzer)
- Network: subdomain enumeration, port scanning examples, fingerprinting, DNS zone-transfer tester
- Cryptography: XOR brute-forcing, MT19937 prediction, RSA Wiener attack, Padding Oracle, hash identification, classic ciphers
- Exploit (educational only): principle explanations & defense guidance โ no executable payloads
Two intentionally vulnerable web servers that run locally on your machine โ perfect for safe, authorized practice:
| Target | Port | Topics |
|---|---|---|
| VulnTarget v1 | 8888 |
SQL Injection, weak secrets, command injection, file upload, XSS |
| VulnTarget v2 | 8889 |
SQL Injection, IDOR, XSS, LFI, SSRF, deserialization, JWT |
- Visualizes task status and learning progress
- AI-provided success-probability extracted and shown per task
- Long-conversation performance mode to keep CPU usage low
- Parse Android Binary XML (AXML) manifests โ no third-party dependency
- Extract components, permissions, exported components, and certificate info
- Scan DEX strings for secrets (API keys, URLs, tokens)
- Optional jadx integration for full decompilation
- Per-session isolated file workspace
- Execute commands inside the sandbox with a three-layer safety filter (hard block / dangerous / GUI-launcher detection)
- AI can read/write files and run commands in the sandbox through the tool registry
- Built-in CTF tool registry (pure functions)
- Custom tools: define JSON descriptors, or let the AI generate them via
/make-plugin - MCP (Model Context Protocol) server support
- Light theme, clean spacing, large rounded corners, restrained color palette
- Unified design language across sidebar, browser, dashboard, and settings
- Performance mode: one-click disable of backdrop blur, dynamic wallpapers, and light effects
- Built on Tauri 2 + Rust
- API keys and learning records stored only on your machine
- No mandatory external backend; works offline (except AI chat, which needs your own LLM API key)
| Layer | Technology | Version | Notes |
|---|---|---|---|
| Desktop framework | Tauri | 2.x | custom protocol + macOS private API |
| Backend language | Rust | edition 2021 | all business logic in Rust |
| HTTP client | reqwest | 0.12 | rustls-tls, SSE streaming |
| WebSocket | tokio-tungstenite | 0.24 | CDP communication |
| Async runtime | tokio | 1.x | time / sync / macros / net |
| Serialization | serde / serde_json | 1.x | IPC & config |
| Config parsing | serde_yaml | 0.9 | Prompt Engine rule files |
| Frontend | Vanilla JS / CSS | โ | no framework, single-page architecture |
| Dialog plugin | tauri-plugin-dialog | 2.x | native file dialogs |
Design choices:
- No HTTP server inside the WebView โ frontend talks to Rust directly over Tauri IPC (no ports, no CORS)
rustls-tlsinstead of OpenSSL โ smaller binaries, fewer system dependencies- Zero frontend dependencies โ fast startup, fully offline-capable
CTF-SeclIDE/
โโโ README.md # This file
โโโ DEVELOPMENT.md # Technical developer documentation
โโโ PROMPT_ENGINE.md # Prompt Engine design document
โโโ DISCLAIMER.md # Disclaimer
โโโ SECURITY.md # Security & responsible-use guidelines
โโโ LICENSE # MIT License (with educational-use restriction)
โ
โโโ prompt_engine/ # AI prompt engine (rules + templates)
โ โโโ rules/ # YAML rule files (modules, params, targets, tasksโฆ)
โ โโโ templates/ # Prompt templates (learning-mode oriented)
โ
โโโ ctf_scripts/ # Security tool reference library
โ โโโ web/ # Web security learning (docs + Python tools)
โ โโโ network/ # Network recon (scripts + cheat sheets)
โ โโโ crypto/ # Cryptography (XOR / RSA / Padding Oracleโฆ)
โ โโโ exploit/ # Concept explanations & defense only (no payloads)
โ โโโ wordlist/ # Placeholder only (offensive dictionaries removed)
โ
โโโ target/ # Local vulnerable lab
โ โโโ vuln_server.py # Target v1 (port 8888)
โ โโโ vuln_server2.py # Target v2 (port 8889)
โ
โโโ desktop/ # Tauri desktop application
โโโ ui/ # Frontend (index.html / app.js / style.css)
โโโ src-tauri/ # Rust backend
โโโ src/ # lib.rs, backend.rs, prompt_engine.rs, browser.rs,
# workspace.rs, network.rs, apk.rs, decoder.rs,
# ctf_tools.rs, ctf_plan.rs, emulator.rs
| Requirement | Version | Purpose |
|---|---|---|
| macOS 12+ or Windows 10+ | โ | Tauri 2 supported platforms |
| Rust toolchain | 1.75+ | Rust backend |
| Node.js | 18+ | Frontend resource tooling |
| Python 3 | โ | Local lab (optional) |
| Chrome / Chromium | โ | Built-in browser (CDP) |
| jadx | โ | APK decompilation (optional enhancement) |
git clone https://github.com/lindenthomaslin/CTF-SeclIDE.git
cd CTF-SeclIDEpython3 target/vuln_server.py # Target v1 โ http://localhost:8888
python3 target/vuln_server2.py # Target v2 โ http://localhost:8889cd desktop/src-tauri
cargo tauri dev# macOS: build .app only (avoids sandbox restrictions that break DMG packaging)
cd desktop
./node_modules/.bin/tauri build --bundles app
# Windows (optional)
npx tauri buildmacOS note: Chrome 128+ requires the
--disable-features=DevToolsTabTargetlaunch flag to restore CDP connectivity.
The lab servers are intentionally vulnerable. Run them only on your own machine for learning purposes.
Target v1: http://localhost:8888 (SQLi, weak secrets, command injection, file upload, XSS)
Target v2: http://localhost:8889 (SQLi, IDOR, XSS, LFI, SSRF, deserialization, JWT)
Use the built-in browser or your own browser to explore these targets and learn how each vulnerability works โ and how to fix it.
Golden rules:
- Authorized targets only. Use this software only against systems you own, systems with explicit written authorization, or official CTF competition environments.
- No real-world attacks. Never use this tool against any third-party system without permission.
- Local lab first. When learning, prefer the built-in targets (
8888/8889). - Respect the law. You are solely responsible for complying with the laws of your country/region.
Built-in safeguards in this project:
danger_modeis permanently locked tofalse(interface kept, but it can never be enabled)- Prompt Engine Guard rejects inputs outside the educational scope
- The public repo contains no executable attack payloads (no reverse shells, webshells, or attack dictionaries)
- Workspace command execution applies a three-layer safety filter
Full details:
- SECURITY.md โ responsible-use and research guidelines
- DISCLAIMER.md โ full disclaimer
We are students, and we welcome help from the community! โค๏ธ
Ways to contribute:
- Report issues โ bugs, typos, documentation improvements
- Suggest features โ open an issue with a clear description
- Submit PRs โ code, docs, or educational content
- Mentor us โ security professionals: your guidance is invaluable to young learners
Please keep all contributions educational and legal. Content must not include real-world attack payloads or materials usable for unauthorized activity.
- LITE-edition compliance refactor (payload removal, learning-mode prompts, danger_mode lock)
- Professional English documentation
- More educational lab targets (reverse engineering, cryptography challenges)
- Built-in CTF practice question bank with auto-grading
- Better mobile security (emulator / ADB integration)
- Internationalization improvements
- Community-translated documentation
This roadmap is maintained by two students โ contributions and suggestions are very welcome.
License: MIT License with an additional educational-use restriction clause.
Copyright (c) 2026 linden_thomas_lin & soodok
Disclaimer: This open-source project is intended solely for CTF contest learning and security education. Security testing is permitted only with the target owner's written consent. Any unauthorized use is entirely the user's own responsibility; the developers and contributors assume no liability. See DISCLAIMER.md for full terms.
โญ Star this repository if you find it useful for learning! โญ
Made with โค๏ธ by middle school students, for the security-learning community.