sahuang/ctf-agent: The Autonomous Swarm Hacking CTFs

By pitting Claude and GPT against each other in a parallel race for root, this framework replaces the lone AI hacker with a ruthless, self-coordinating team.

7 min read • View on GitHub • More from sahuang

A mechanical greyhound race track where metallic dogs of different designs chase a mechanical rabbit. The track is built from overlapping rings of code and terminal windows, representing the parallel execution of multiple LLMs.
Instead of relying on a single model to sequentially logic its way through a vulnerability, ctf-agent spawns a swarm of different models and forces them to race.
Key Takeaways

The Reckoning Point for Competitive Hacking

Human root blood times in Capture The Flag (CTF) competitions have plummeted. Autonomous systems are no longer just participating in these events; they are winning them outright. Traditional human-only infrastructure is struggling to keep up with the speed of agentic exploitation frameworks.

Jacob’s research into over 500 Hack The Box machines revealed a startling trend: a roughly 17% year-over-year decrease in "Root First Blood" times [02:16].

Jacob Krell, Penetration Tester and Researcher, Suzu Labs · Simply Offensive Podcast

Enter sahuang/ctf-agent. Built by members of a top-tier US CTF team, this project is a high-concurrency, multi-model autonomous agent. It approaches vulnerabilities not as a sequential puzzle, but as an industrial race.

The Swarm Architecture

Most AI agents operate sequentially. They read, they think, they act, and they read again. If they hallucinate a bad strategy, the entire execution chain is compromised. The Coordinator in ctf-agent solves this by spawning a ChallengeSwarm for every target. It runs multiple models, typically GPT-5.4 and Claude Opus, in parallel.

The Coordinator manages the race, shares hints, and immediately terminates losing nodes to save API costs.

Cross-Model Collaboration

The true power of the Swarm is not just parallel execution. It is shared state managed by the do_bump_agent function. If Claude discovers an open port but fails to exploit it, the Coordinator extracts that finding and injects it directly into GPT's context window. This mimics a human CTF team sharing findings in a Discord channel.

Two distinct robotic arms working at separate, side-by-side workbenches. A mechanical sorting overhead crane takes a single glowing gear from the left workbench and drops it onto the right workbench.
The Coordinator extracts discoveries from one model and injects them into the context window of another.

The Fortified Sandbox

Writing an exploit is only half the battle. Executing it safely is the other. The models do not just output text. They write and execute Python scripts and shell commands inside a heavily fortified Docker container. This sandbox is pre-loaded with massive security arrays, including pwntools, GDB, and angr.

Surviving Rate Limits

In a high-stakes race, API rate limits are fatal. The system utilizes a sophisticated QUOTA_FALLBACK dictionary. If a primary model hits a rate limit during a critical exploit chain, the system automatically fails over to API-backed equivalents (like AWS Bedrock or Azure) mid-exploit without dropping state.

Parallel Swarms vs. Sequential Agents

When compared to sequential agents that rely on step-by-step reasoning, the parallel swarm architecture trades raw compute for speed and reliability. By utilizing diverse models simultaneously, it avoids the bottleneck of a single model's context window limitations.

FeatureParallel Swarm (ctf-agent)Sequential Agents
Execution ModelParallel racing with multiple LLMsStep-by-step monolithic reasoning
State ManagementShared via Coordinator hintsIsolated to a single context window
Failure ModeOne model fails, others continueHallucination breaks the entire chain
Cost StrategyRuthless termination of losersLinear token consumption