Mement0
Git forensics recovering a deleted malicious skill file from unreachable-but-ungarbage-collected commit history in a compromised coding-agent repo.
Mement0 — Cyber Apocalypse 2026
| | |
|---|---|
| Challenge | Mement0 |
| Platform | HackTheBox — Cyber Apocalypse 2026 ("The Salt Crown") |
| Category | AI / ML |
| Difficulty | Easy (1000 pts) |
| Techniques | Git forensics on a rewritten-looking history, recovering deleted objects via git show/git fsck, diffing an agent-config repo for injected content |
| Date | July 2026 |
---
TL;DR
The scenario framing is a compromised Claude-style coding-agent repository: a
"scribe-construct" keeps leaving a mark in everything it copies, and the rite that taught it
that habit was supposedly "struck from the record and burned." In practice that's a metaphor
for git history: a malicious skill file was deleted in a later commit, but the underlying
git objects were never garbage-collected, so the deleted content is fully recoverable
straight out of the commit that still contains it.
Recon
Extracted archive contains a memento/ directory with both .git and .claude/ present —
a real (fictional) Claude-agent project, complete with CLAUDE.md, .claude/skills/, and
.claude/commands/.
git log shows four commits:
1. Initial site build.
2. A memory/conventions commit.
3. c39fe85 — "rebuild pages with analytics beacon."
4. c9517be — a cleanup commit that deletes
.claude/skills/shell-helper/SKILL.md and .claude/skills/word-count/SKILL.md.
Recovery
git fsck confirmed no force-push/history rewrite had actually occurred at the object
level — the deletion is a normal commit, not a filter-branch/rebase erasure. That makes
the deleted skill files trivially recoverable straight out of the commit that still holds
them:
git show c39fe85:.claude/skills/shell-helper/SKILL.md
git show c39fe85:.claude/skills/word-count/SKILL.md
General technique for the case where objects genuinely become unreachable (not needed here,
but worth keeping):
git fsck --lost-found --unreachable --dangling --no-reflogs
git cat-file -p <sha> # inspect each candidate
And a blunt catch-all that works regardless of exactly which commit/object holds the flag:
git cat-file --batch-all-objects --batch --buffer | grep -a -o 'HTB{[^}]*}'
The narrative mapping (useful for spotting the pattern fast)
| Scenario text | Actual meaning |
|---|---|
| scribe-construct | The coding agent that regenerates the site's HTML |
| standing memory / taught rites | .claude/ — CLAUDE.md, .claude/skills/, .claude/commands/ |
| "orders rewritten, the rite struck from the record and burned" | The malicious skill/command file was deleted (log made to look clean) |
| "the archive keeps its older skins" | .git — old objects survive after files are deleted from the working tree |
| "the mark it presses beneath every leaf" | The injected payload appearing in every generated page |
| "carries across the water" / Eastreach's ledgers | The exfiltration channel |
Lessons & defenses
- Deleting a file in a new commit does not remove it from the repository — it stays
- **
git fsckis the fastest way to distinguish "history was actually rewritten" from "a - A repo used to drive an autonomous coding agent is a supply-chain surface. A
fully readable via any commit that still references it, until (and unless) history is
actually rewritten and the old objects are garbage-collected/expired. git rm is not a
security control.
file was just deleted normally"** — the two look identical from git log alone but have
very different recovery paths.
compromised skill/command file that's since been "cleaned up" from the visible log is
exactly the kind of incident this challenge models, and the forensic technique here (full
object dump + grep) generalizes directly to real repo-compromise investigations.
Tools used
| Tool | Purpose |
|---|---|
| git log --all --stat / git log --diff-filter=D | Identify what was deleted and when |
| git fsck | Confirm no history rewrite occurred; find any genuinely dangling objects |
| git show <sha>:<path> | Recover the deleted skill files directly |
| git cat-file --batch-all-objects + grep | Catch-all sweep for the flag across every object in the repo |
Something wrong with this page?
Wrong details, a stolen writeup, or something that should not be published here — tell a moderator. This does not go to the author.