Keep a Changelog / SemVer changelog. Documents the 1.0.0 release (2026-07-18): the ops/combat-contract layer, PRIMARY routing and case tooling, core skills and localization, plus an Unreleased section with Fixed, Security, Added and Removed changes.
reverse-skill / CHANGELOG.md — Keep a Changelog / SemVer changelog
Snapshot 2026-08-05 14:42:51 UTC · version 1
N
security/forensics-and-reverse-engineeringtype:reference#zhaoxuya520-reverse-skill#reverse-skill#reverse-engineering#agent-skills#skill-md#markdown
INDEXABLE MARKDOWN SNAPSHOT
Research document
MDRSS snapshot ·
CHANGELOG.mdfrom zhaoxuya520/reverse-skill · audience: humans · License: MIT (repo root).Keep a Changelog / SemVer changelog.
Changelog
All notable changes to reverse-skill are documented in this file.
Format follows Keep a Changelog. Versioning follows Semantic Versioning.
[Unreleased]
Fixed
- Routing: sigma vs malware, LLM 越狱 vs iOS 越狱, 完整渗透/打到域控 vs AD 域控, forensics vs OT ics; master-route.ps1 rewritten UTF-8 BOM for PS 5.1 CJK
- Linux/macOS bootstrap: register PentestSwarm MCP with a verified executable path after Go install or when already installed
Security
- Added
docs/PACKAGE-SECURITY-AUDIT.md: static audit of package executables (no backdoor / no auto DB wipe found) - Pin supply-chain floating tags: jshook
@0.3.4, pentestswarmv0.1.0 - Bootstrap integrity: GitHub zip/jar downloads verify
assetSha256(manifest) or GitHub APIdigest; mismatch deletes file and fails - Pin jadx
v1.5.6and apktoolv3.0.2with published SHA256
Added
- Domain skills R21–R27, R29–R30:
protocol-reverse,ghidra-reverse,cloud-k8s,windows-ad,digital-forensics,code-audit,threat-hunting,wifi-wireless,browser-extension-reverse - High-quality skills R28, R31–R38:
ot-ics,macos-reverse,thick-client,go-rust-reverse,hardware-security,database-security,email-security,identity-federation,radio-sdr - Wired into
MASTER-ROUTING.md,master-route.ps1, routing tables, domain map, role-map, coherence tests
Removed
game-reverse/(not a product focus; Unity/IL2CPP remains viareverse-engineering+ seed-014)
1.0.0 — 2026-07-18
First formal public release of the reverse-skill skill-router pack.
Added
Ops / combat contract layer (skills/ops/)
IDENTITY.md— product identity: lightweight skill router + bootstrap + field-journal (not a Z3r0-style platform)scope-contract.md— case scope +network_profile; auth not granted → no ACT on targetevidence-finding-path.md— Evidence → Finding → Path chainrole-map.md— lead / specialist role mapping and handofftimeline-workitem.md— timeline + workitem coveragesandbox-profile.md— tool profile mappingskill-supply-chain.md— Agent Skill / MCP install gate (AST10-lite)
PRIMARY routing & case tooling (skills/scripts/)
master-route.ps1— PRIMARY route from task hintcase-init.ps1/case-guard.ps1— case bootstrap + scope guardappend-evidence.ps1— structured evidence appendsmoke.ps1— package smoke checksverify-routing-coherence.ps1— routing / ops coherence verificationtest-p0-friction.ps1— P0 client-side lab friction regression tests
Core skills & docs
- Full skill matrix: APK / IDA / radare2 / JS / .NET / mobile / malware / pwn / firmware / EDR / pentest / API / LLM / supply-chain / crypto / binary-diff / patch-diff / attack-chain / docs & diagrams
MASTER-ROUTING.md+routing.md/routing_zh.mdthree-axis matrix- Bootstrap + tool-index pipeline (
bootstrap-reverse.ps1/.sh,refresh-tool-index) field-journalprecedent library + completion checklist- Multi-platform paths: Windows primary, Linux / macOS / Kali docs and scripts
- CTF-Sandbox-Orchestrator competition sub-skills
- Burp MCP extension package (
burp-mcp-full/)
Quality / localization
- UTF-8 integrity for Chinese docs (
RULES_zh,routing_zh, related guides) - Client-side lab playbook and recon pipeline references for authorized testing friction reduction
Notes
skills/tool-index.md/tool-index.jsonare machine-local and intentionally gitignored; generate viarefresh-tool-indexafter clone.- This tag freezes the skill-router product surface at commit
9fc280bplus this release metadata.
Links
- Tag:
v1.0.0 - Repository: https://github.com/zhaoxuya520/reverse-skill
Snapshot metrics: 3944 B · 84 lines · ~979 tokens · 14 headings · git mode 100644.
MARKDOWN METRICS
483words
14headings
3links
0code blocks
MDRSS ASSESSMENT
Scam / risk5/100low
Evidence100/100high confidence
Why MDRSS assigned this score
- 5 evidence URL(s) found in Markdown
- evidence comes from multiple domains
- some evidence URLs look like primary-source hosts
Evidence (5)
concept:forensics-and-reverse-engineeringorg:collider-club Discussion 0
Sign in to join the discussion.