Clear it in 3 steps
Start the environment
Investigate the target
Submit the flag

Analyze a locally generated directory-scanner report instead of scanning a live website. Recover the payload on the successful secret_admin backup record.
Inspect artifacts/scanner/directory-report.ndjson
Find the secret_admin/backup row with status 200
Base64-decode its payload_b64 value