competition-linux-credential-pivotlisted
Install: claude install-skill Saprophytic-seattle561/reverse-skill
# Competition Linux Credential Pivot
Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.
Use this skill when the decisive edge is Linux credential material and where that material is accepted.
Reply in Simplified Chinese unless the user explicitly requests English.
## Quick Start
1. Separate credential storage from accepted privilege.
2. Record user, process, namespace, socket, key file, and service trust boundary before conclusions.
3. Keep artifact recovery, replay path, and resulting capability in one chain.
4. Distinguish local escalation from lateral host pivot.
5. Reproduce one minimal artifact-to-accepted-access path.
## Workflow
### 1. Map Credential And Trust Artifacts
- Record SSH keys, agent sockets, kubeconfigs, cloud tokens, service-account secrets, env vars, config files, and process memory clues.
- Note sudoers rules, capabilities, setuid binaries, systemd unit context, and namespace boundaries.
- Keep each artifact tied to owner, scope, and expected accepting service.
### 2. Prove Replay And Pivot
- Show where key, token, socket, or secret is accepted: SSH, API, Unix socket, container runtime, or control-plane endpoint.
- Record host target, protocol, principal, and resulting session or privilege.
- Distinguish authentication success from useful