Skip to content
Back to skills

Competition Browser Persistence

ASecurity

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for browser cookies, localStorage, sessionStorage, IndexedDB, Cache Storage, service workers, offline caches, and client-side session persistence. Use when the user asks to inspect browser state, replay cached auth or session behavior, explain why a page behaves differently after load, or trace how stored client state changes requests, rendering, or access. Use only after `$ctf-sandbox-orchestrator` has already estab...

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsnodeapidatabasebackend

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add alicewe1/alice_skill --skill competition-browser-persistence --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Competition Browser Persistence?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Competition Browser Persistence
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-competition-browser-persistence/badge)](https://www.skillsdirectory.com/skills/alicewe1-competition-browser-persistence)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: competition-browser-persistence
description: Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for browser cookies, localStorage, sessionStorage, IndexedDB, Cache Storage, service workers, offline caches, and client-side session persistence. Use when the user asks to inspect browser state, replay cached auth or session behavior, explain why a page behaves differently after load, or trace how stored client state changes requests, rendering, or access. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
x-alice-class: assist
---

# Competition Browser Persistence

Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.

Use this skill when the decisive branch lives in browser-held state rather than only in visible HTML or backend source.

Reply in Simplified Chinese unless the user explicitly requests English.

## Quick Start

1. Identify the active persistence surface first: cookie jar, localStorage, sessionStorage, IndexedDB, Cache Storage, or service worker.
2. Record origin, scope, domain, path, expiry, and key names before mutating state.
3. Tie stored state to one concrete effect: request header, rendered branch, cached response, offline behavior, or hidden route access.
4. Separate boot-time state from runtime-mutated state.
5. Reproduce the smallest stateful sequence that reaches the decisive branch.

## Workflow

### 1. Map Browser State Surfaces

- Inspect cookies, storage buckets, service worker registrations, cache entries, and transient globals exposed during boot.
- Record which origin, host, route, or feature flag each state item actually applies to.
- Keep auth tokens, refresh material, CSRF state, cached responses, and feature toggles in separate evidence blocks.

### 2. Tie State To Runtime Behavior

- Show how stored state becomes request headers, role derivation, route visibility, cached API data, or offline fallback behavior.
- Compare clean-state and mutated-state runs with one variable changed at a time.
- Distinguish UI-only state from backend-accepted state.

### 3. Reduce To The Decisive Persistence Chain

- Compress the result to the smallest chain: initial page or login -> state persisted -> subsequent request or render branch -> resulting capability.
- Keep extracted storage, service worker scripts, and replay steps tied to the same origin and route.
- If the problem broadens into general web routing or worker behavior outside browser persistence, switch back to the broader web-runtime skill.

## Read This Reference

- Load `references/browser-persistence.md` for the browser-state checklist, service-worker checklist, and evidence packaging.

## What To Preserve

- Cookie attributes, storage keys, database names, cache keys, service worker scopes, and origin boundaries
- The exact request or render effect caused by each decisive state item
- Clean-state vs mutated-state reproduction steps for the smallest working path

Files in this skill

  • SKILL.md3.1 KB
  • agents/openai.yaml407 B
  • references/browser-persistence.md1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…