Wild West API

Understand a CTF challenge you are stuck on, after the event

You gave up on a challenge during a CTF and the event is now over. Apex Flash can act as a tutor: it gives hints in stages, explains the technique when you want it, and helps you turn what you learnt into your own writeup.

Set it up

  1. Confirm the event has ended and its rules allow outside help afterwards.
  2. Write down the challenge text, what you tried and where you got stuck.
  3. Ask apex-flash for hints in stages, starting with the smallest.
  4. Try each hint yourself in your own lab copy of the challenge.
  5. Ask for the full explanation only after you have tried.
  6. Write the solution in your own words and note what you would do differently.

Authorisation boundary

Only use this for challenges that are over, practice platforms that allow it, or retired lab machines, run in your own environment. Do not use AI against a live competition whose rules forbid it, and do not point any technique at systems that are not part of the CTF.

Sanitised sample input

Challenge (web, 100 pts, event ended): "Guest Pass".
A site gives you a session cookie after login as guest.
Cookie value: eyJ1c2VyIjoiZ3Vlc3QiLCJhZG1pbiI6ZmFsc2V9
I decoded it by eye as base64 but I don't know what to do next.
Goal given in the text: read the admin page.

The prompt and the call

Ask for a ladder, not the answer. The hint ladder keeps you learning.

I am practising on a finished CTF challenge in my own lab copy. Act as a tutor.
Give me hints in three levels and stop after each one: level 1 a nudge on what to look at, level 2 the technique name and why it applies, level 3 the general steps. Do not give the flag or a complete solution until I write "full explanation".
After the full explanation, tell me how a developer should fix the underlying flaw.

<challenge>
...text and what I tried...
</challenge>
import os
from openai import OpenAI

client = OpenAI(base_url="https://wildwestapi.com/v1",
                api_key=os.environ["WILDWEST_API_KEY"])

resp = client.chat.completions.create(
    model="apex-flash",
    temperature=0.2,
    messages=[
        {"role": "system", "content": "You are a patient CTF tutor for finished challenges."},
        {"role": "user", "content": open("ctf_prompt.txt", encoding="utf-8").read()},
    ],
)
print(resp.choices[0].message.content)

Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.

What the learning looks like

For the sample, base64 decoding the cookie gives a small JSON object whose fields include "admin":false. The lesson at level 2 is that the server trusts data the client holds. At the full explanation the model should say you edit the value in your own lab copy and that the real fix is to sign the cookie or keep the role server-side. The fix section matters most: it links the exercise to OWASP A01 Broken Access Control and A08 Software and Data Integrity Failures.

What to check

  • Run each hint in your lab copy. If it does not work, tell the model what happened rather than accepting it.
  • Technique names are real and apply to the challenge version you have.
  • You can explain the solution without the chat open. If not, redo it.
  • Your writeup states what you tried and failed too. That is the useful part for readers.

Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. If a legitimate practice question is refused on another service, outlaw-1 is a separate uncensored product here.

Where this fits

The skills carry over to reverse engineering and code review. See the use cases index and red team tools for lab tooling.

FAQ

Can I use it during a live CTF?

Only if the rules allow it. Many events forbid outside AI help. Use it after the event or on practice platforms.

Will it give me flags?

Ask for hints first. It can explain solutions to finished challenges, but flags only matter inside your own lab copy.

How do I write a good writeup?

State the goal, your failed attempts, the key insight and the fix. Write it yourself; use the model to check clarity.

Related

Uncensored AI models on one key

OpenAI and Anthropic compatible, pay as you go. New to it? Start with uncensored AI, explained.