
reverse-skill v1.0.0
面向逆向工程、渗透测试和安全研究的AI驱动技能路由包。将AI代理引导至正确的方法,并按需为APK、二进制文件、JS、固件和CTF任务启动工具链。
reverse-skill
Cybersecurity Skills Router · 逆向技能路由包
Navigate the dark waters, sail against the stream.
About · Getting Started · Usage · Fast route · Routing · Ops contracts · AI Bootstrap · Sponsors · Contributing
🌐 中文
About
If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.
When an AI agent (Claude Code, Codex, Cursor, OpenCode, or another compatible client) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.
User task
→ RULES.md
→ MASTER-ROUTING / master-route.ps1 (PRIMARY)
→ case-init / scope.md (auth + network_profile; no target ACT until ready)
→ Scenario skill → tools / MCP / scripts
→ timeline + Evidence→Finding→Path → report + field-journal
Why this exists:
- AI agents don't know whether to use jadx, apktool, Frida, IDA, or BurpSuite for a given task
- APK, ELF, JS, PCAP, and CTF tasks each need different playbooks
- Tools, MCP servers, and scripts are scattered across machines
- The same mistakes get repeated because experience isn't reused
Current status
| Routing rules | Regression benchmark | Core skill modules | CI platforms | Client model |
|---|---|---|---|---|
| 41 (R0–R40) | 163 cases | 42 tracked modules | Windows + Ubuntu | Client-neutral |
The routing core is driven by one structured configuration, validated by cross-platform CI, and kept separate from optional client adapters.
PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/
Built With
IDA Pro · radare2 · Ghidra
Getting Started
Prerequisites
- Java / JDK — for jadx and apktool
- Node.js 22.12+ — for JS toolchain and MCP servers
- Python 3.x — for Frida and helper scripts
- A code AI client — Claude Code, Codex, Cursor, OpenCode, or another compatible client
Installation
git clone https://github.com/zhaoxuya520/reverse-skill.git
Then refresh the tool index per platform:
| Platform | Command |
|---|---|
| Windows | powershell -File skills/scripts/refresh-tool-index.ps1 |
| Linux / macOS | bash skills/scripts/refresh-tool-index.sh |
| Kali Linux | bash kali/scripts/refresh-tool-index.sh |
Check skills/tool-index.md to see detected tools.
Platform-specific docs:
- Kali Linux → kali/README-kali.md
- Ubuntu/Debian → docs/platforms/linux.md
- macOS → docs/platforms/macos.md
Usage
Supported scenarios
| Scenario | Entry |
|---|---|
| APK / Android analysis | skills/apk-reverse/ |
| iOS / mobile | skills/mobile-reverse/ |
| Binary reverse (exe/dll/so/elf) | skills/ida-reverse/ / skills/radare2/ |
| .NET / C# | skills/dotnet-reverse/ |
| Frontend JS / encrypted params | skills/js-reverse/ |
| DSL VM / custom JS opcode VM | skills/reverse-engineering/dsl-vm-reverse/ |
| HTTP capture / request replay | anything-analyzer, Reqable MCP + js-reverse/ |
| Malware / YARA | skills/malware-analysis/ |
| Penetration testing / scanning | skills/pentest-tools/ |
| Attack chain / red-team orchestration | skills/attack-chain/ |
| Case evidence review / report handoff | skills/case-review/ |
| CTF competition | CTF-Sandbox-Orchestrator/ (42 sub-skills) |
| Firmware / IoT | skills/firmware-pentest/ |
| Patch diff / N-day | skills/patch-diff-exploit/ |
| Pwn / exploit development | skills/pwn-chain/ |
| EDR bypass | skills/edr-bypass-re/ |
| API / GraphQL | skills/api-security/ |
| Supply chain / SBOM | skills/supply-chain-security/ |
| LLM / AI security | skills/llm-security/ |
| OLLVM deobfuscation | skills/reverse-engineering/references/ollvm-deobfuscation.md |
| Diagrams / reports | skills/diagram-generator/ / skills/docs-generator/ |