zhaoxuya520/reverse-skill: Trending on GitHub
reverse-skill
Cybersecurity Skills Router · 逆向技能路由包
Navigate the dark waters, sail against the stream.
About · Getting Started · Usage · Fast route · Routing · Ops contracts · AI Bootstrap · Sponsors · Contributing
🌐 中文
About
If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.
When an AI agent (Claude Code, Codex CLI, Cursor, etc.) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.
User task → RULES.md → MASTER-ROUTING / master-route.ps1 (PRIMARY) → case-init / scope.md (auth + network_profile; no target ACT until ready) → Scenario skill → tools / MCP / scripts → timeline + Evidence→Finding→Path → report + field-journal
Why this exists:
AI agents don't know whether to use jadx, apktool, Frida, IDA, or BurpSuite for a given task
APK, ELF, JS, PCAP, and CTF tasks each need different playbooks
Tools, MCP servers, and scripts are scattered across machines
The same mistakes get repeated because experience isn't reused
PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/
(back to top)
Built With
IDA Pro · radare2 · Ghidra
(back to top)
Getting Started
Prerequisites
Java / JDK — for jadx and apktool
Node.js 22.12+ — for JS toolchain and MCP servers
Python 3.x — for Frida and helper scripts
A code AI client — Claude Code, Codex CLI, Cursor, etc.
Installation
git clone https://github.com/zhaoxuya520/reverse-skill.git
Then refresh the tool index per platform:
Platform Command
Windows powershell -File skills/scripts/refresh-tool-index.ps1
Linux / macOS bash skills/scripts/refresh-tool-index.sh
Kali Linux bash kali/scripts/refresh-tool-index.sh
Check skills/tool-index.md to see detected tools.
Platform-specific docs:
Kali Linux → kali/README-kali.md
Ubuntu/Debian → docs/platforms/linux.md
macOS → docs/platforms/macos.md
(back to top)
Usage
Supported scenarios
Scenario Entry
APK / Android analysis skills/apk-reverse/
iOS / mobile skills/mobile-reverse/
Binary reverse (exe/dll/so/elf) skills/ida-reverse/ / skills/radare2/
.NET / C# skills/dotnet-reverse/
Frontend JS / encrypted params skills/js-reverse/
DSL VM / custom JS opcode VM skills/reverse-engineering/dsl-vm-reverse/
HTTP capture / request replay anything-analyzer, Reqable MCP + js-reverse/
Malware / YARA skills/malware-analysis/
Penetration testing / scanning skills/pentest-tools/
Attack chain / red-team orchestration skills/attack-chain/
CTF competition CTF-Sandbox-Orchestrator/ (40+ sub-skills)
Firmware / IoT skills/firmware-pentest/
Patch diff / N-day skills/patch-diff-exploit/
Pwn / exploit development skills/pwn-chain/
EDR bypass skills/edr-bypass-re/
API / GraphQL skills/api-security/
Supply chain / SBOM skills/supply-chain-security/
LLM / AI security skills/llm-security/
OLLVM deobfuscation skills/reverse-engineering/references/ollvm-deobfuscation.md
Diagrams / reports skills/diagram-generator/ / skills/docs-generator/
Key files
File Purpose
README_AI.md AI agent bootstrap and configuration
RULES.md Global routing rules (scope gate before ACT)
skills/MASTER-ROUTING.md PRIMARY fast ladder
skills/routing.md Task → skill routing matrix
skills/SKILL.md Master entry point
skills/tool-index.md Local tool status (auto-generated)
skills/scripts/master-route.ps1 One-shot PRIMARY triage
skills/scripts/case-init.ps1 Case dir: scope / timeline / workitems
skills/ops/ Scope, Evidence chain, roles, timeline (skill-router form)
Repository layout
. ├── README.md / README_zh.md / README_AI.md ├── RULES.md / RULES_zh.md ├── skills/ │ ├── MASTER-ROUTING.md / SKILL.md / routing.md │ ├── ops/ # ops contracts │ ├── scripts/ # master-route, case-init, bootstrap, verify │ ├── field-journal/ │ ├── apk-reverse/ mobile-reverse/ js-reverse/ dotnet-reverse/ │ ├── ida-reverse/ radare2/ reverse-engineering/ malware-analysis/ │ ├── pentest-tools/ attack-chain/ pwn-chain/ firmware-pentest/ │ ├── api-security/ supply-chain-security/ llm-security/ │ └── ... ├── CTF-Sandbox-Orchestrator/ ├── docs/ ├── kali/ # see kali/README-kali.md └── work/ # local cases (gitignored)
(back to top)
Sponsors
For sponsorship or business inquiries:
(back to top)
Contributing
Contributions are welcome! Fork the repo, create a feature branch, and open a PR.
Fork the Project
git checkout -b feature/AmazingFeature
git commit -m 'Add some AmazingFeature'
git push origin feature/AmazingFeature
Open a Pull Request
Contributors
(back to top)
License
This project (reverse-skill) is primarily licensed under the MIT License (see LICENSE).
Submodule and third-party dependencies:
CTF-Sandbox-Orchestrator/: GNU GPLv3
Pentest Swarm AI: Original project is AGPL-3.0. This repo only invokes it via CLI or MCP and does not include its source code
Other tools (jadx, frida, nmap, burpsuite-mcp, etc.) are subject to their respective official licenses
(back to top)
Acknowledgments
Thanks to all open-source tool authors. This project integrates tools across reverse engineering, penetration testing, CTF, and security analysis — every tool is the fruit of community effort.
Special thanks to the OLLVM deobfuscation ecosystem contributors and everyone who submitted test samples, issues, and PRs.
(back to top)
Contact
Email: 24781737@qq.com
Discord: reverse-skill




