reverse-skill
A skills router for authorized reverse engineering, pentest, CTF and threat analysis: it picks a methodology for the task and checks available tools
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Includes offensive techniques: exploit development, EDR bypass and attack chains
- Runs external reverse-engineering and network tools on hosts and operates against test targets
Install
Manual install
git clone https://github.com/zhaoxuya520/reverse-skill.git
bash reverse-skill/skills/scripts/refresh-tool-index.shOn Windows run skills/scripts/refresh-tool-index.ps1; on Kali use kali/scripts/refresh-tool-index.sh. After installing, open RULES.md and skills/MASTER-ROUTING.md.
This is third-party code. Review the repository files before installing.
What it does
The pack turns an agent's security work into a repeatable process. When the agent is handed an APK, a binary, encrypted frontend parameters, a PCAP, a CTF challenge or a pentest target, the router uses one configuration to pick the right module, checks the index of installed tools and runs a step-by-step workflow instead of guessing commands. The set has dozens of specialized modules: APK, iOS and mobile reversing, work with IDA Pro, radare2, Binary Ninja, .NET, JS reversing, malware analysis and YARA, pentest tooling, attack chains, exploit development, firmware and IoT, EDR bypass, API security, supply chain and LLM security. Before acting on a target the router requires recording authorization and scope in a scope file, and results follow an evidence, finding, path structure. It supports Claude Code, Codex, Cursor and OpenCode, with a separate adapter plugin for Codex.
Who it is for. For security professionals: reverse engineers, pentesters, CTF players and analysts working in AI coding clients.
Good fit when
- You have an APK, a binary, a PCAP or a CTF task and need to choose a methodology and tools
- You need a repeatable authorized pentest process with recorded scope and evidence
- You need to route scattered reverse-engineering tools and MCP servers into one workflow
Not a fit when
- You have no written authorization for the target
- You need one-off advice without installing the pack and external tools
- The task is not about security or reversing
Example request
I have an APK for authorized analysis, pick a route and walk through it step by stepLimitations
The pack is intended only for lawful research, education, CTF and testing of systems you own or are authorized to assess. The pack itself is methodology, a router and scripts; the actual work is done by external tools such as jadx, apktool, Frida, IDA Pro, radare2, nmap and Burp Suite, which you install separately. It needs Java, Node.js 22.12+ and Python. Some subfolders and dependencies carry other licenses: CTF-Sandbox-Orchestrator under GPLv3 and individual tools under their own licenses. The user is fully responsible for the legality of use.
How to disable. Delete the cloned repository folder from your project. If you added the Codex adapter, remove it via your client's plugin settings.
Security check
- Includes offensive techniques: exploit development, EDR bypass and attack chains
- Runs external reverse-engineering and network tools on hosts and operates against test targets
README in short
The README describes a security skills router for AI coding clients. When the agent meets an APK, a binary, encrypted JS, a PCAP or a CTF task, the pack uses routing rules to select a module, checks the tool index and runs a repeatable process. It lists dozens of modules and one routing configuration, cross-platform CI on Windows and Ubuntu, and routing regression tests. Installation is via git clone plus a tool-index refresh script; for Codex there is an adapter plugin that delegates to the shared router. The core is not tied to a specific client. MIT license, with some subfolders under other licenses.
SKILL.md
--- name: reverse-skill-router description: Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear. --- # Reverse Engineering Skills Master Control This directory collects a set of reverse-engineering skill modules; each subdirectory is a standalone module with its own SKILL.md describing scope, toolchain and workflow. ## Routing execution contract After reading this file, do not just reply acknowledged. Execute in order: 1. NOW: run the platform-native router (master-route.ps1 on Windows; master-route.sh on Linux/macOS/Kali) to pick PRIMARY from config/routing.json. 2. NOW: run the platform-native case-init to create work/<case>/scope.md; do not ACT on a target until authorization is granted. 3. ACT: open the PRIMARY SKILL.md and follow its ACTION REQUIRED. 4. NEXT: resolve tool paths only via tool-index.md; if a tool is missing, bootstrap from the manifest. 5. Report conclusions as Evidence, Finding, Path.
FAQ
Is this legal?
The pack targets lawful research, education, CTF and testing of authorized systems. The router requires recording scope in a scope file and does not start target actions without confirmed authorization.
Does the pack install tools itself?
No. It keeps an index of installed tools and points out what is missing, but you install jadx, Frida, IDA Pro, nmap and the rest yourself.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents