返回更新列表
新发布Jul 26, 2026

reverse-skill v1.0.0

面向逆向工程、渗透测试和安全研究的AI驱动技能路由包。将AI代理引导至正确的方法,并按需为APK、二进制文件、JS、固件和CTF任务启动工具链。

分享

reverse-skill

reverse-skill

Cybersecurity Skills Router · 逆向技能路由包

Navigate the dark waters, sail against the stream.

release v1.0.1 stars forks issues license changelog

zhaoxuya520%2Freverse-skill | Trendshift zhaoxuya520%2Freverse-skill | Trendshift


About · Getting Started · Usage · Fast route · Routing · Ops contracts · AI Bootstrap · Sponsors · Contributing

🌐 中文


About

If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.

When an AI agent (Claude Code, Codex, Cursor, OpenCode, or another compatible client) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.

User task
  → RULES.md
  → MASTER-ROUTING / master-route.ps1 (PRIMARY)
  → case-init / scope.md (auth + network_profile; no target ACT until ready)
  → Scenario skill → tools / MCP / scripts
  → timeline + Evidence→Finding→Path → report + field-journal

Why this exists:

  • AI agents don't know whether to use jadx, apktool, Frida, IDA, or BurpSuite for a given task
  • APK, ELF, JS, PCAP, and CTF tasks each need different playbooks
  • Tools, MCP servers, and scripts are scattered across machines
  • The same mistakes get repeated because experience isn't reused

Current status

Routing rulesRegression benchmarkCore skill modulesCI platformsClient model
41 (R0–R40)163 cases42 tracked modulesWindows + UbuntuClient-neutral

The routing core is driven by one structured configuration, validated by cross-platform CI, and kept separate from optional client adapters.

PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/


star velocity

(back to top)

Built With


IDA Pro · radare2 · Ghidra

(back to top)

Getting Started

Prerequisites

  • Java / JDK — for jadx and apktool
  • Node.js 22.12+ — for JS toolchain and MCP servers
  • Python 3.x — for Frida and helper scripts
  • A code AI client — Claude Code, Codex, Cursor, OpenCode, or another compatible client

Installation

git clone https://github.com/zhaoxuya520/reverse-skill.git

Then refresh the tool index per platform:

PlatformCommand
Windowspowershell -File skills/scripts/refresh-tool-index.ps1
Linux / macOSbash skills/scripts/refresh-tool-index.sh
Kali Linuxbash kali/scripts/refresh-tool-index.sh

Check skills/tool-index.md to see detected tools.

Platform-specific docs:

(back to top)

Usage

Supported scenarios

ScenarioEntry
APK / Android analysisskills/apk-reverse/
iOS / mobileskills/mobile-reverse/
Binary reverse (exe/dll/so/elf)skills/ida-reverse/ / skills/radare2/
.NET / C#skills/dotnet-reverse/
Frontend JS / encrypted paramsskills/js-reverse/
DSL VM / custom JS opcode VMskills/reverse-engineering/dsl-vm-reverse/
HTTP capture / request replayanything-analyzer, Reqable MCP + js-reverse/
Malware / YARAskills/malware-analysis/
Penetration testing / scanningskills/pentest-tools/
Attack chain / red-team orchestrationskills/attack-chain/
Case evidence review / report handoffskills/case-review/
CTF competitionCTF-Sandbox-Orchestrator/ (42 sub-skills)
Firmware / IoTskills/firmware-pentest/
Patch diff / N-dayskills/patch-diff-exploit/
Pwn / exploit developmentskills/pwn-chain/
EDR bypassskills/edr-bypass-re/
API / GraphQLskills/api-security/
Supply chain / SBOMskills/supply-chain-security/
LLM / AI securityskills/llm-security/
OLLVM deobfuscationskills/reverse-engineering/references/ollvm-deobfuscation.md
Diagrams / reportsskills/diagram-generator/ / skills/docs-generator/

Key files

分类