reverse-skill

A skills router for authorized reverse engineering, pentest, CTF and threat analysis: it picks a methodology for the task and checks available tools

Skill

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Includes offensive techniques: exploit development, EDR bypass and attack chains
  • Runs external reverse-engineering and network tools on hosts and operates against test targets
All reasons and checks

zhaoxuya520/reverse-skill

Install

Manual install

git clone https://github.com/zhaoxuya520/reverse-skill.git
bash reverse-skill/skills/scripts/refresh-tool-index.sh

On Windows run skills/scripts/refresh-tool-index.ps1; on Kali use kali/scripts/refresh-tool-index.sh. After installing, open RULES.md and skills/MASTER-ROUTING.md.

This is third-party code. Review the repository files before installing.

What it does

The pack turns an agent's security work into a repeatable process. When the agent is handed an APK, a binary, encrypted frontend parameters, a PCAP, a CTF challenge or a pentest target, the router uses one configuration to pick the right module, checks the index of installed tools and runs a step-by-step workflow instead of guessing commands. The set has dozens of specialized modules: APK, iOS and mobile reversing, work with IDA Pro, radare2, Binary Ninja, .NET, JS reversing, malware analysis and YARA, pentest tooling, attack chains, exploit development, firmware and IoT, EDR bypass, API security, supply chain and LLM security. Before acting on a target the router requires recording authorization and scope in a scope file, and results follow an evidence, finding, path structure. It supports Claude Code, Codex, Cursor and OpenCode, with a separate adapter plugin for Codex.

Who it is for. For security professionals: reverse engineers, pentesters, CTF players and analysts working in AI coding clients.

Good fit when

  • You have an APK, a binary, a PCAP or a CTF task and need to choose a methodology and tools
  • You need a repeatable authorized pentest process with recorded scope and evidence
  • You need to route scattered reverse-engineering tools and MCP servers into one workflow

Not a fit when

  • You have no written authorization for the target
  • You need one-off advice without installing the pack and external tools
  • The task is not about security or reversing

Example request

I have an APK for authorized analysis, pick a route and walk through it step by step

Limitations

The pack is intended only for lawful research, education, CTF and testing of systems you own or are authorized to assess. The pack itself is methodology, a router and scripts; the actual work is done by external tools such as jadx, apktool, Frida, IDA Pro, radare2, nmap and Burp Suite, which you install separately. It needs Java, Node.js 22.12+ and Python. Some subfolders and dependencies carry other licenses: CTF-Sandbox-Orchestrator under GPLv3 and individual tools under their own licenses. The user is fully responsible for the legality of use.

How to disable. Delete the cloned repository folder from your project. If you added the Codex adapter, remove it via your client's plugin settings.

Security check

  • Includes offensive techniques: exploit development, EDR bypass and attack chains
  • Runs external reverse-engineering and network tools on hosts and operates against test targets

README in short

The README describes a security skills router for AI coding clients. When the agent meets an APK, a binary, encrypted JS, a PCAP or a CTF task, the pack uses routing rules to select a module, checks the tool index and runs a repeatable process. It lists dozens of modules and one routing configuration, cross-platform CI on Windows and Ubuntu, and routing regression tests. Installation is via git clone plus a tool-index refresh script; for Codex there is an adapter plugin that delegates to the shared router. The core is not tied to a specific client. MIT license, with some subfolders under other licenses.

SKILL.md

---
name: reverse-skill-router
description: Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
---
# Reverse Engineering Skills Master Control

This directory collects a set of reverse-engineering skill modules; each subdirectory is a standalone module with its own SKILL.md describing scope, toolchain and workflow.

## Routing execution contract

After reading this file, do not just reply acknowledged. Execute in order:

1. NOW: run the platform-native router (master-route.ps1 on Windows; master-route.sh on Linux/macOS/Kali) to pick PRIMARY from config/routing.json.
2. NOW: run the platform-native case-init to create work/<case>/scope.md; do not ACT on a target until authorization is granted.
3. ACT: open the PRIMARY SKILL.md and follow its ACTION REQUIRED.
4. NEXT: resolve tool paths only via tool-index.md; if a tool is missing, bootstrap from the manifest.
5. Report conclusions as Evidence, Finding, Path.

FAQ

Is this legal?

The pack targets lawful research, education, CTF and testing of authorized systems. The router requires recording scope in a scope file and does not start target actions without confirmed authorization.

Does the pack install tools itself?

No. It keeps an index of installed tools and points out what is missing, but you install jadx, Frida, IDA Pro, nmap and the rest yourself.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIreverse-skill

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.