OpenCROW Web Toolbox
Use this skill for web CTF work that starts from discovery and fuzzing rather than browser automation: sqlmap, gobuster, ffuf, dirb, and wfuzz. The full installer profile also tracks manual acquisition steps for Burp Suite Community and OWASP ZAP.
Quick Start
Start the MCP server from the installed CLI:
opencrow-web-mcp
Verify the mapped stack:
python ~/.codex/skills/opencrow-web-toolbox/scripts/verify_toolkit.py
Workflow
- Start with endpoint and content discovery using
ffuf,gobuster, ordirb. - Use
wfuzzwhen the problem is parameter fuzzing or more custom request mutation. - Use
sqlmapwhen the challenge is plausibly SQLi-driven and the target is stable enough for automation. - Use
playwrightseparately when the task needs a real browser or a JS-heavy flow. - If a full profile was installed, use the manual Burp/ZAP links from the installer summary for GUI-heavy workflows.
- Prefer the MCP server operations first:
toolbox_info,toolbox_verify,toolbox_capabilities,web_discover,web_fuzz, andweb_sqlmap_scan.
Tool Selection
- Use
ffuffor fast fuzzing against paths, parameters, or virtual hosts. - Use
gobusterfor straightforward wordlist-driven discovery. - Use
dirbwhen a challenge guide or prior workflow already assumes DIRB-style usage. - Use
wfuzzwhen request templating matters more than raw speed. - Use
sqlmapwhen the target and request shape are stable enough to automate.
Resources
opencrow-web-mcp: stdio MCP server for typed discovery, fuzzing, and sqlmap workflows.scripts/verify_toolkit.py: confirm that the mapped web discovery tools are installed.references/tooling.md: quick selection notes for web workflows.