client-reverse

A workflow for understanding and replaying requests made by Android apps, browser JavaScript, or desktop clients. It uses captured network traffic first and examines client code only when signing, encryption, tokens, or anti-automation rules prevent replay.

In plain words
What is it for?
Use it in authorized app or client security tests to capture traffic, trace how requests are built, recover signing or encryption logic when needed, and confirm that requests can be replayed reliably.
Why use it?
It helps explain why a request copied into Burp, a tool for intercepting web traffic, does not work by itself. The workflow identifies required headers, tokens, device values, timestamps, and request order.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fb0sh/pentester/client-reverse
Any agent
npx skills add fb0sh/pentester --skill client-reverse
Clone the repo
git clone --depth 1 https://github.com/fb0sh/pentester

Made for: Claude Code, Codex.

Per session 56 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 945 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00056 $0.00945
Opus 5 $0.00028 $0.00473
Sonnet 5 $0.00011 $0.00189
Haiku 4.5 $0.00006 $0.00094

Measured 2d ago against content hash 3e8c5ba841db, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

client-reverse scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to client-reverse — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/skills/third-party/client-reverse/SKILL.md · 81 lines

What it actually says

客户端逆向与 Burp 重放 Skill

当请求由客户端(安卓App、浏览器JS、桌面客户端)构造,且存在签名、加密、token状态、设备绑定或反自动化逻辑导致 Burp 无法直接重放时,使用本 Skill。

核心原则

Packet-First:先捕获并分析真实的 HTTP/HTTPS 请求或 WebSocket 流量,确认可用性,再按需逆向阻塞点。逆向是阻塞解决步骤,不是默认入口。

场景路由

已授权安卓 App 渗透测试

不要先用 jadx、ida_pro_mcp 分析 APK,按以下顺序操作:

  1. 确认目标 App 已安装在连接设备上
  2. 准备好 Burp 或 Charles 抓包
  3. 用 scrcpy_vision 打开 App,驱动真实业务流程
  4. 每个关键动作后检查 Burp/Charles 是否出现 HTTP/HTTPS 或 WebSocket 数据包
  5. 如果包可见且可重放 → 立即进入 web-security-advanced 做 Web/API 安全测试
  6. 重复"界面动作 → 抓包 → Web 安全分析"循环
  7. 只有抓不到包/包被加密/无法重放时 → 升级到 jadx → frida_mcp → ida_pro_mcp

MCP 工具链:scrcpy_vision → burp/charles → adb_mcp → jadx → frida_mcp → ida_pro_mcp

浏览器 JS 签名、反爬、WebSocket 握手

  1. chrome_devtools 查看页面状态和请求链
  2. js_reverse 定位 token/sign 生成逻辑
  3. burp 验证重放并确定可变字段

阶段模型:locate → recover → runtime → validation → replay

MCP 工具链:chrome_devtools → js_reverse → burp

桌面客户端 / 本地 signer

  1. everything_search 定位相关文件
  2. ida_pro_mcp 静态分析签名函数
  3. frida_mcp 获取运行时参数
  4. burp 验证稳定重放

MCP 工具链:everything_search → ida_pro_mcp → frida_mcp → burp

重放就绪检查清单

在进入 Payload 测试前,必须能回答:

  • 请求体如何构造?
  • 签名/加密输入来自哪里?
  • 哪些 cookie、header、token、设备值、时间戳、nonce 是必须的?
  • 请求是否依赖顺序或会话状态?
  • 哪些字段改动后不会破坏重放?

证据保留

  • builder/signer/crypto 代码位置
  • 关键 hook 点和运行时观察值
  • 可用的 replay 请求样本
  • 前置条件、失败模式和反自动化行为说明

参考文档

  • references/02-client-api-reverse-and-burp.md — 客户端逆向到 Burp 重放总工作流
  • references/android-authorized-app-pentest-sop.md — 安卓 App 渗透 SOP
  • references/browser-js-signing-workflow.md — 浏览器 JS 签名工作流
  • references/android-signing-and-crypto-workflow.md — 安卓签名与加密工作流
  • references/android-ui-driven-observation-and-packet-loop.md — 安卓 UI 驱动观察循环
  • references/android-external-url-runtime-first-workflow.md — 安卓外部 URL 测试
  • references/android-network-layer-testing-quick-reference.md — 安卓网络层测试速查
  • references/MCP.md — MCP 能力总文档
  • references/tool-selection-map.md — 工具选型地图
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 81 lines · 56 tokens per session scan A 3e8c5ba841db

Subscribe to this mod's changes

client-reverse is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 56 tokens to every session and 945 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to client-reverse, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

client-side

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

transilienceai/communitytools · 38 tokens

transilience-report-style

Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.

transilienceai/communitytools · 31 tokens

firewall-review

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…

transilienceai/communitytools · 100 tokens

pentest-engagement

Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…

transilienceai/communitytools · 140 tokens

coordination

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

transilienceai/communitytools · 24 tokens

hackerone

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.

transilienceai/communitytools · 36 tokens