AI, autonomous AI agents, agent frameworks, debuggers, fuzzers,
scripts, reverse engineering and other technical tools are allowed
against your local copy.
CTFd, the hosting provider, other users, network infrastructure
and every system other than the local sandbox are outside
the authorized offensive-testing scope.
The remote service is a verifier, not an attack target.
It may only be used manually to check a specific bypass
already developed locally.
Participation requirement
Participation requires acceptance of the
MAX Authorization Challenge Rules and Authorization Scope
during registration on CTFd.