CATCH THE Shadow Puppets

A threat-hunting CTF — agentic AI attack surface, real datasets, no scripting required. Three hunts, three shadow puppets to catch.

What's in each tab

Workspace terminal

Your team's persistent terminal. Claude Code is loaded with skills (/dataset-explore, /audit-tool, /detect-hidden-prompts, more) and the four workshop datasets. Pinned to the right side of every workshop page.

Challenges 16 hunts

Three hunts, five stages each, plus a warm-up. Click a card to read the riddle and submit your flag. Solving a stage unlocks the next.

Scoreboard live

Live team rankings, refreshed as flags submit. The top three at the buzzer take the Shadow Catcher badge home.

Team roster

Members, score, solved challenges. Your username here is your individual identity; flags submit on behalf of the whole team.

How to play

  1. 01

    Register

    Use the registration code on your table card. Pick any username and password — they identify you, not your team.

  2. 02

    Join your team

    Choose Join Team. Enter the team name and team password from your card. You and your tablemates land in the same team.

  3. 03

    Hunt

    Open a challenge. Read the riddle. Ask Claude in your terminal sidebar — /dataset-explore, /audit-tool, or whichever skill fits.

  4. 04

    Submit

    Paste the flag. Watch the next stage unlock. Solve all sixteen to take the badge.

Research by Capsule Security·Infosec Europe 2026