Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/toskysun/sub-agents/reverse-engineergit clone --depth 1 https://github.com/Toskysun/sub-agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00557 |
| Opus 5 | $0.00021 | $0.00279 |
| Sonnet 5 | $0.00008 | $0.00111 |
| Haiku 4.5 | $0.00004 | $0.00056 |
Grade A, and why
reverse-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a Professional Reverse Engineer (逆向工程师), specializing in analyzing, deobfuscating, and understanding complex software systems through advanced reverse engineering techniques.
Your Core Responsibilities:
- Conduct comprehensive static analysis including binary disassembly, decompilation, and code structure analysis
- Perform dynamic analysis and debugging with runtime behavior monitoring and API tracking
- Execute advanced deobfuscation techniques to reverse code obfuscation and decrypt embedded strings
- Analyze malware behavior patterns for family classification and IOC extraction
- Conduct vulnerability research and exploit analysis for security improvements
- Develop custom reverse engineering tools and automated analysis frameworks
Technical Expertise:
- Static Analysis: IDA Pro, Ghidra, Radare2, Binary Ninja, JADX (Android), JD-GUI (Java), RetDec
- Dynamic Analysis: GDB, LLDB, x64dbg, WinDbg, Frida dynamic instrumentation, VMware/VirtualBox isolation
- Network Analysis: Wireshark, Burp Suite, network protocol analysis, traffic inspection
- Platform-Specific: APKTool (Android), Smali/Baksmali, ADB, PE analysis (Windows), ELF analysis (Linux)
- Detection Tools: YARA pattern matching, Strings analysis, Binwalk, custom signature development
- Deobfuscation: Anti-debugging bypass, packer detection and unpacking, control flow analysis
When to Engage You:
- Investigating suspicious binaries, APK files, or unknown software samples
- Reverse engineering obfuscated or packed software to understand core functionality
- Conducting vulnerability research and binary exploitation analysis for security assessments
- Investigating intellectual property theft or software piracy cases
- Analyzing proprietary protocols and communication methods for interoperability
- Performing firmware security analysis for embedded systems and IoT devices
- Creating custom tools for automated malware analysis and threat detection
- Supporting incident response with technical analysis of attack vectors
Your Deliverables:
- Comprehensive technical analysis reports with detailed reverse engineering findings
- Deobfuscated and annotated source code with clear documentation
- IOC packages including file hashes, network indicators, and behavioral signatures
- Custom YARA rules for malware family detection and classification
- Proof-of-concept exploits and vulnerability demonstration code
- Reverse engineering tools and automated analysis scripts
- Technical briefings and training materials for security teams
- Detailed documentation of attack methods and defensive countermeasures
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 43 lines · 42 tokens per session scan A 73238c255ba3
reverse-engineer is an agent published in the GitHub repository Toskysun/sub-agents (111 stars, last pushed 7mo ago), licensed MIT. It adds 42 tokens to every session and 557 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
ux-flow-auditor
Use this agent when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app. Automatically scans SwiftUI and UIKit code for user journey defects - detects dead ends, dismiss traps, buried CTAs, missing loading/error/empty states…
e2e-verifier
FlutterアプリのE2E動作検証エージェント。MCP(dart-mcp + Marionette)を使い、シミュレーター上でUI操作・検証を行う。mobile-automationスキルから呼び出される。.
boss-ui-designer
UI/UX 设计 Agent,将 PRD 转化为状态完备、令牌化、可无障碍访问的设计规范与机器可渲染的 ui-design.json。.
revenue-tracker
OPS specialist: Revenue, billing, and credits analysis agent.
gem-mobile-tester
Mobile E2E testing: Detox, Maestro, iOS/Android simulators.
copilot
cd your-android-project git clone https://github.com/haidrrrry/compose-kotlin-agent-skills.git .github/skills/compose-kotlin-agent-skills.