reverse-skill / README.md — Human-facing project overview and quick start for reverse-skill, a cybersecurity skills router

Snapshot 2026-08-05 14:11:52 UTC · version 1

published
N
NikNov14 cards · 9.8/10 MDRSS

Human-facing project overview and quick start for reverse-skill, a cybersecurity skills router. Covers About, Built With, Getting Started (prerequisites, installation), Usage with supported scenarios, key files, repository layout and license. The entry point for human contributors.

MARKDOWN SNAPSHOT

Loading…

Direct .mdRaw + metadata0 commentsMDRSS 9.8/10
INDEXABLE MARKDOWN SNAPSHOT

Research document

Open canonical .md

MDRSS snapshot · README.md from zhaoxuya520/reverse-skill · audience: humans · License: MIT (repo root).

Human-facing project overview and quick start for reverse-skill, a cybersecurity skills router.


reverse-skill

Cybersecurity Skills Router · 逆向技能路由包

Navigate the dark waters, sail against the stream.


About · Getting Started · Usage · Fast route · Routing · Ops contracts · AI Bootstrap · Sponsors · Contributing

🌐 中文


About

If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.

When an AI agent (Claude Code, Codex CLI, Cursor, etc.) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.

User task
  → RULES.md
  → MASTER-ROUTING / master-route.ps1 (PRIMARY)
  → case-init / scope.md (auth + network_profile; no target ACT until ready)
  → Scenario skill → tools / MCP / scripts
  → timeline + Evidence→Finding→Path → report + field-journal

Why this exists:

  • AI agents don't know whether to use jadx, apktool, Frida, IDA, or BurpSuite for a given task
  • APK, ELF, JS, PCAP, and CTF tasks each need different playbooks
  • Tools, MCP servers, and scripts are scattered across machines
  • The same mistakes get repeated because experience isn't reused

PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/



(back to top)

Built With


IDA Pro · radare2 · Ghidra

(back to top)

Getting Started

Prerequisites

  • Java / JDK — for jadx and apktool
  • Node.js 22.12+ — for JS toolchain and MCP servers
  • Python 3.x — for Frida and helper scripts
  • A code AI client — Claude Code, Codex CLI, Cursor, etc.

Installation

git clone https://github.com/zhaoxuya520/reverse-skill.git

Then refresh the tool index per platform:

Platform Command
Windows powershell -File skills/scripts/refresh-tool-index.ps1
Linux / macOS bash skills/scripts/refresh-tool-index.sh
Kali Linux bash kali/scripts/refresh-tool-index.sh

Check skills/tool-index.md to see detected tools.

Platform-specific docs:

(back to top)

Usage

Supported scenarios

Scenario Entry
APK / Android analysis skills/apk-reverse/
iOS / mobile skills/mobile-reverse/
Binary reverse (exe/dll/so/elf) skills/ida-reverse/ / skills/radare2/
.NET / C# skills/dotnet-reverse/
Frontend JS / encrypted params skills/js-reverse/
DSL VM / custom JS opcode VM skills/reverse-engineering/dsl-vm-reverse/
HTTP capture / request replay anything-analyzer, Reqable MCP + js-reverse/
Malware / YARA skills/malware-analysis/
Penetration testing / scanning skills/pentest-tools/
Attack chain / red-team orchestration skills/attack-chain/
CTF competition CTF-Sandbox-Orchestrator/ (40+ sub-skills)
Firmware / IoT skills/firmware-pentest/
Patch diff / N-day skills/patch-diff-exploit/
Pwn / exploit development skills/pwn-chain/
EDR bypass skills/edr-bypass-re/
API / GraphQL skills/api-security/
Supply chain / SBOM skills/supply-chain-security/
LLM / AI security skills/llm-security/
OLLVM deobfuscation skills/reverse-engineering/references/ollvm-deobfuscation.md
Diagrams / reports skills/diagram-generator/ / skills/docs-generator/

Key files

File Purpose
README_AI.md AI agent bootstrap and configuration
RULES.md Global routing rules (scope gate before ACT)
skills/MASTER-ROUTING.md PRIMARY fast ladder
skills/routing.md Task → skill routing matrix
skills/SKILL.md Master entry point
skills/tool-index.md Local tool status (auto-generated)
skills/scripts/master-route.ps1 One-shot PRIMARY triage
skills/scripts/case-init.ps1 Case dir: scope / timeline / workitems
skills/ops/ Scope, Evidence chain, roles, timeline (skill-router form)

Repository layout

.
├── README.md / README_zh.md / README_AI.md
├── RULES.md / RULES_zh.md
├── skills/
│   ├── MASTER-ROUTING.md / SKILL.md / routing.md
│   ├── ops/                   # ops contracts
│   ├── scripts/               # master-route, case-init, bootstrap, verify
│   ├── field-journal/
│   ├── apk-reverse/ mobile-reverse/ js-reverse/ dotnet-reverse/
│   ├── ida-reverse/ radare2/ reverse-engineering/ malware-analysis/
│   ├── pentest-tools/ attack-chain/ pwn-chain/ firmware-pentest/
│   ├── api-security/ supply-chain-security/ llm-security/
│   └── ...
├── CTF-Sandbox-Orchestrator/
├── docs/
├── kali/                      # see kali/README-kali.md
└── work/                      # local cases (gitignored)

(back to top)

Sponsors

For sponsorship or business inquiries:

(back to top)

Contributing

Contributions are welcome! Fork the repo, create a feature branch, and open a PR.

  1. Fork the Project
  2. git checkout -b feature/AmazingFeature
  3. git commit -m 'Add some AmazingFeature'
  4. git push origin feature/AmazingFeature
  5. Open a Pull Request

Contributors

(back to top)

License

This project (reverse-skill) is primarily licensed under the MIT License (see LICENSE).

Submodule and third-party dependencies:

  • CTF-Sandbox-Orchestrator/: GNU GPLv3
  • Pentest Swarm AI: Original project is AGPL-3.0. This repo only invokes it via CLI or MCP and does not include its source code
  • Other tools (jadx, frida, nmap, burpsuite-mcp, etc.) are subject to their respective official licenses

(back to top)

Acknowledgments

Thanks to all open-source tool authors. This project integrates tools across reverse engineering, penetration testing, CTF, and security analysis — every tool is the fruit of community effort.

Special thanks to the OLLVM deobfuscation ecosystem contributors and everyone who submitted test samples, issues, and PRs.

(back to top)

Contact


Snapshot metrics: 10,468 B · 253 lines · ~2,577 tokens · 15 headings · 3 code blocks · git mode 100644.

MARKDOWN METRICS
929words
15headings
21links
3code blocks
MDRSS ASSESSMENT
Scam / risk5/100low
Evidence100/100high confidence
Why MDRSS assigned this score
  • 24 evidence URL(s) found in Markdown
  • evidence comes from multiple domains
  • some evidence URLs look like primary-source hosts
Evidence (5)
concept:forensics-and-reverse-engineeringorg:collider-club

Discussion 0

Sign in to join the discussion.