# Security & Privacy — MDRSS feed

> Offensive research, defensive engineering and privacy practice. Page 1 of 2; 75 matching cards.
> Canonical feed: https://mdrss.com/s/security

## Cards (50)

### [reverse-skill / README_AI.md — Bootstrap file for AI agents only; human readers are redirected to README](https://mdrss.com/security/forensics-and-reverse-engineering/901521/901521.md)

Bootstrap file for AI agents only; human readers are redirected to README.md. Contains the execute-immediately first instruction, the platform deployment routing table, an example report format, dependency tables, and quick-start paths for wiring any code CLI into the router.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T15:51:47.283Z · Version: 1

### [reverse-skill / README-kali.md — Root-level Kali Linux shortcut entry](https://mdrss.com/security/forensics-and-reverse-engineering/901520/901520.md)

Root-level Kali Linux shortcut entry. Defers to kali/README-kali.md as the source of truth; gives an AI read-then-execute path and a 30-second human quick start, and explains this file's relationship to the main package.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T15:51:42.399Z · Version: 1

### [reverse-skill / README_zh.md — Chinese-language project overview and the most detailed human documentation in the repo](https://mdrss.com/security/forensics-and-reverse-engineering/901519/901519.md)

Chinese-language project overview and the most detailed human documentation in the repo. Mirrors README.md (about, quick start, installation, usage, supported scenarios, key files, repository layout) with fuller explanations. Primary reference for Chinese-speaking users.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T15:51:37.760Z · Version: 1

### [reverse-skill / README.md — Human-facing project overview and quick start for reverse-skill, a cybersecurity skills router](https://mdrss.com/security/forensics-and-reverse-engineering/901518/901518.md)

Human-facing project overview and quick start for reverse-skill, a cybersecurity skills router. Covers About, Built With, Getting Started (prerequisites, installation), Usage with supported scenarios, key files, repository layout and license. The entry point for human contributors.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T15:51:32.951Z · Version: 1

### [reverse-skill / skills/routing_zh.md — Chinese edition of the routing matrix (by target type, by user intent, route-not-matched handling, cr](https://mdrss.com/security/forensics-and-reverse-engineering/901517/901517.md)

Chinese edition of the routing matrix (by target type, by user intent, route-not-matched handling, cross-module path crossing). Same enforced protocol: complete routing before acting, output the routing rationale, and pass case-init/scope.md before ACT on a target.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:43:36.269Z · Version: 1

### [reverse-skill / skills/routing.md — Full task-to-skill routing matrix](https://mdrss.com/security/forensics-and-reverse-engineering/901516/901516.md)

Full task-to-skill routing matrix. Routes by target type, user intent and toolchain; includes CTF wording normalization, ambiguous-intent recovery, route-not-matched handling and cross-module path crossing. Enforced, not advisory: routing must complete before execution.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:43:31.280Z · Version: 1

### [reverse-skill / skills/MASTER-ROUTING.md — PRIMARY fast-path routing ladder, kept in sync with scripts/master-route](https://mdrss.com/security/forensics-and-reverse-engineering/901515/901515.md)

PRIMARY fast-path routing ladder, kept in sync with scripts/master-route.ps1. Defines the route-before-acting execution contract, the priority order, the scope gate before ACT, evidence append and the reading order. The first file an agent consults.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:43:26.411Z · Version: 1

### [reverse-skill / skills/SKILL.md — Master controller and entry point for the skills tree](https://mdrss.com/security/forensics-and-reverse-engineering/901514/901514.md)

Master controller and entry point for the skills tree. YAML frontmatter declares the routing scope; the body defines the routing execution contract, RFC-2119 instruction levels, the unified entry, the next-step menu pattern, the precedent library and auto-evolution.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:43:21.008Z · Version: 1

### [reverse-skill / RULES_zh.md — Chinese edition of RULES](https://mdrss.com/security/application-security-and-threat-modeling/901513/901513.md)

Chinese edition of RULES.md: the same authorization gates and canonical behavior chain (trigger keywords, routing entry, execution principles, security boundaries, completion checklist). The largest file in the navigation set; it drives routing for Chinese-language prompts.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-05T14:43:16.103Z · Version: 1

### [reverse-skill / RULES.md — The single source of truth for the behavior chain and authorization gates](https://mdrss.com/security/application-security-and-threat-modeling/901512/901512.md)

The single source of truth for the behavior chain and authorization gates. Defines the execute-immediately mandate, global config injection on first use, bilingual trigger keywords, the routing entry, execution principles, the canonical behavior chain and a completion checklist.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-05T14:43:11.098Z · Version: 1

### [reverse-skill / CLAUDE.md — Root-level file that Claude Code auto-loads](https://mdrss.com/security/forensics-and-reverse-engineering/901511/901511.md)

Root-level file that Claude Code auto-loads. Declares the repository a task skill router for authorized reverse engineering and security work, names RULES.md as the single source of truth, and fixes the routing order, with per-OS first-run setup and a coherence check.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:43:06.283Z · Version: 1

### [reverse-skill / skills/CONTRIBUTING.md — Guide for adding a new skill module to the pack](https://mdrss.com/security/forensics-and-reverse-engineering/901509/901509.md)

Guide for adding a new skill module to the pack. Defines the standard flow: compliance-engineering constraints, when to add a skill, the directory-structure template, and the mandatory SKILL.md contents including the strong-execution skeleton that forces agents to act rather than merely acknowledge.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:42:56.693Z · Version: 1

### [reverse-skill / CHANGELOG.md — Keep a Changelog / SemVer changelog](https://mdrss.com/security/forensics-and-reverse-engineering/901508/901508.md)

Keep a Changelog / SemVer changelog. Documents the 1.0.0 release (2026-07-18): the ops/combat-contract layer, PRIMARY routing and case tooling, core skills and localization, plus an Unreleased section with Fixed, Security, Added and Removed changes.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:42:51.682Z · Version: 1

### [reverse-skill: the .md map — humans and agents, separated](https://mdrss.com/security/forensics-and-reverse-engineering/901503/901503.md)

Navigation across the markdown files of zhaoxuya520/reverse-skill with measured metrics: 402 .md files, 83 SKILL.md, all in git mode 100644. Documentation is split by audience — 46 KB for humans, 157 KB for agents. Covers the routing chain and three license zones (MIT / GPL-3.0 / third-party MIT).

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-05T14:11:43.216Z · Version: 1

### [Signed Audit Trails for Claude Code Tool Calls](https://mdrss.com/security/cryptography-privacy-and-compliance/901436/901436.md)

Cookbook-style walkthrough for cryptographically signed receipts on every Claude Code tool call. This is the teaching skill. For the runtime implementation, install the protect-mcp plugin. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Review](https://mdrss.com/security/application-security-and-threat-modeling/901434/901434.md)

You are a Senior Code Reviewer with 30 years of experience in software quality, security analysis, and architectural compliance. You are objective, constructive, and precise. You explain the why behind every finding. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Threat-mitigation mapping — templates and worked examples](https://mdrss.com/security/application-security-and-threat-modeling/901427/901427.md)

Threat-mitigation mapping — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [stride-analysis-patterns — templates and worked examples](https://mdrss.com/security/application-security-and-threat-modeling/901426/901426.md)

User  --  Web App  --  API Gateway  --  Backend Services  | v  Database . Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [security-requirement-extraction — templates and worked examples](https://mdrss.com/security/application-security-and-threat-modeling/901425/901425.md)

security-requirement-extraction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [attack-tree-construction — templates and worked examples](https://mdrss.com/security/application-security-and-threat-modeling/901424/901424.md)

attack-tree-construction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [SAST Security Plugin](https://mdrss.com/security/application-security-and-threat-modeling/901423/901423.md)

Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Security Hardening Orchestrator](https://mdrss.com/security/application-security-and-threat-modeling/901422/901422.md)

You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Dependency Vulnerability Scanning](https://mdrss.com/security/application-security-and-threat-modeling/901421/901421.md)

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Protocol Reverse Engineering](https://mdrss.com/security/forensics-and-reverse-engineering/901419/901419.md)

Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Memory Forensics](https://mdrss.com/security/forensics-and-reverse-engineering/901418/901418.md)

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Binary Analysis Patterns](https://mdrss.com/security/forensics-and-reverse-engineering/901417/901417.md)

Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [anti-reversing-techniques — detailed patterns and worked examples](https://mdrss.com/security/forensics-and-reverse-engineering/901416/901416.md)

For advanced VM detection (RDTSC delta calibration, VMware backdoor port, hypervisor leaf enumeration, guest driver artifact checks), see references/advanced-techniques.md. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Reverse engineer](https://mdrss.com/security/forensics-and-reverse-engineering/901415/901415.md)

You are an elite reverse engineer with deep expertise in software analysis, binary reverse engineering, and security research. You operate strictly within authorized contexts: security research, CTF competitions, authorized penetration testing, malware defense, and educational pu. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Malware analyst](https://mdrss.com/security/forensics-and-reverse-engineering/901414/901414.md)

You are an elite malware analyst focused on defensive security research. Your purpose is to help security professionals understand malicious software to protect systems and respond to incidents. You operate strictly within defensive and educational contexts. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Firmware analyst](https://mdrss.com/security/forensics-and-reverse-engineering/901413/901413.md)

You are an elite firmware analyst with deep expertise in embedded systems security, IoT device analysis, and hardware reverse engineering. You operate within authorized contexts: security research, penetration testing with authorization, CTF competitions, and educational purposes. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [on-call-handoff-patterns — templates and worked examples](https://mdrss.com/security/forensics-and-reverse-engineering/901323/901323.md)

1. API latency around 02:00-03:00 UTC (backup window) 2. Auth service memory (restart if 80%). Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident Runbook Templates](https://mdrss.com/security/forensics-and-reverse-engineering/901322/901322.md)

Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Intelligent Issue Resolution Orchestrator](https://mdrss.com/security/forensics-and-reverse-engineering/901321/901321.md)

You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident Response Orchestrator](https://mdrss.com/security/forensics-and-reverse-engineering/901320/901320.md)

You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Incident responder](https://mdrss.com/security/forensics-and-reverse-engineering/901319/901319.md)

You are an incident response specialist with comprehensive Site Reliability Engineering (SRE) expertise. When activated, you must act with urgency while maintaining precision and following modern incident management best practices. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [gdpr-data-handling — detailed worked examples](https://mdrss.com/security/cryptography-privacy-and-compliance/901318/901318.md)

gdpr-data-handling — detailed worked examples captures reusable agent playbook guidance for cryptography, privacy & compliance. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [employment-contract-templates — templates and worked examples](https://mdrss.com/security/cryptography-privacy-and-compliance/901317/901317.md)

employment-contract-templates — templates and worked examples captures reusable agent playbook guidance for cryptography, privacy & compliance. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [XSS Vulnerability Scanner for Frontend Code](https://mdrss.com/security/application-security-and-threat-modeling/901311/901311.md)

You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention. Analyze React, Vue, Angular, and vanilla JavaScript code to identify injection points, unsafe DOM manipulation, and improper sanitization. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Mobile security coder](https://mdrss.com/security/application-security-and-threat-modeling/901310/901310.md)

You are a mobile security coding expert specializing in secure mobile development practices, mobile-specific vulnerabilities, and secure mobile architecture patterns. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Frontend security coder](https://mdrss.com/security/application-security-and-threat-modeling/901309/901309.md)

You are a frontend security coding expert specializing in client-side security practices, XSS prevention, and secure user interface development. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [auth-implementation-patterns — detailed patterns and worked examples](https://mdrss.com/security/application-security-and-threat-modeling/901272/901272.md)

auth-implementation-patterns — detailed patterns and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Dependency Audit and Security Analysis](https://mdrss.com/security/application-security-and-threat-modeling/901238/901238.md)

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Backend security coder](https://mdrss.com/security/application-security-and-threat-modeling/901197/901197.md)

You are a backend security coding expert specializing in secure development practices, vulnerability prevention, and secure architecture implementation. Use it to give an agent explicit responsibilities, steps and constraints.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Cryptocoding: Secure Cryptography Engineering Practices](https://mdrss.com/security/cryptography-privacy-and-compliance/901124/901124.md)

This page lists "coding rules" for implementations of cryptographic operations, and more generally for operations involving secret or sensitive values. Use it to build a structured path from fundamentals to hands-on practice.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Awesome Post-Quantum](https://mdrss.com/security/cryptography-privacy-and-compliance/901123/901123.md)

A curated list of resources about post-quantum cryptography. Use it to build a structured path from fundamentals to hands-on practice.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Not so awesome Web3 Security Researcher roadmap](https://mdrss.com/security/application-security-and-threat-modeling/901121/901121.md)

Of course, this is not awesome. This is not the curated list of blue underlined words that you will click, read, and jump to the next one, hoping to finish as fast as possible, or maybe hoping not to finish at all. You are going to become a security RESEARCHER . Yeah, RESEAR. Use it as a repeatable review, validation or hardening pass.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [License List Data](https://mdrss.com/security/cryptography-privacy-and-compliance/901114/901114.md)

A curated reference on cryptography, privacy & compliance centered on License List Data. Use it to make implementation decisions and avoid common dead ends.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [TryHackMe Road Map](https://mdrss.com/security/cryptography-privacy-and-compliance/901106/901106.md)

Hey Guys, here is a list of 350+ Free TryHackMe rooms to start learning hacking. I have arranged and compiled it according to different topics so that you can start hacking right away. Use it to make implementation decisions and avoid common dead ends.

Classification: security/cryptography-privacy-and-compliance · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Digital Forensics: Tools, Methods and Workflows](https://mdrss.com/security/forensics-and-reverse-engineering/901094/901094.md)

Digital Forensics is the process of recovering and preserving material found on digital devices during the course of criminal investigations. Digital forensics tools include hardware and software tools used by law enforcement to collect and preserve digital evidence and support o. Use it to build a structured path from fundamentals to hands-on practice.

Classification: security/forensics-and-reverse-engineering · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1

### [Nmap Cheat Sheet](https://mdrss.com/security/application-security-and-threat-modeling/901072/901072.md)

Nmap ("Network Mapper") is a free and open source utility for network discovery and security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap. Use it as a repeatable review, validation or hardening pass.

Classification: security/application-security-and-threat-modeling · Feed: security · Updated: 2026-08-04T13:54:51.641Z · Version: 1
