xAmirHamza77/ReverseOps-Skill

ReverseOps-Skill is an AI-powered security orchestration framework that routes AI agents to the right tools and workflows for reverse engineering, APK analysis, malware, pentesting, CTFs, firmware, exploit development, and JavaScript deobfuscation, delivering repeatable investigations with structured evidence and reports.

This repository also configures its own agents. See what ReverseOps-Skill tells them →

4Stars on the repository
88Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for OAuth, OIDC, redirect flows, state or nonce handling, PKCE, token exchange, refresh logic, claim mapping, and accepted login paths. Use when the user asks to trace redirects, callback parameters, scopes, state, nonce, PKCE, refresh…

not rated 4 1mo ago A 119 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for packet capture analysis, session reconstruction, application-protocol decoding, stream reassembly, beacon timing, and packet-to-process correlation. Use when the user asks to analyze a PCAP, rebuild TCP or UDP sessions, decode HTTP…

not rated 4 1mo ago A 117 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for prompt-injection, retrieval poisoning, memory contamination, planner drift, MCP or tool-boundary abuse, and agent exfiltration challenges. Use when the user asks to analyze prompt injection, retrieval poisoning, memory contamination…

not rated 4 1mo ago A 105 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for queues, async workers, cron jobs, delayed tasks, retry behavior, worker-only config drift, and payload-to-side-effect chains. Use when the user asks to trace a queue payload, inspect async job execution, explain worker-only behavior…

not rated 4 1mo ago A 121 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for race windows, ordering bugs, idempotency failures, lock gaps, concurrent worker drift, and state inconsistencies that produce decisive effects. Use when the user asks to reproduce timing-sensitive bugs, concurrent state corruption…

not rated 4 1mo ago A 105 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for forced-auth coercion, relay chains, target selection, NTLM or related acceptance paths, and coercion-to-privilege transitions. Use when the user asks to trace a coercion primitive, follow a relay path, analyze forced authentication…

not rated 4 1mo ago A 119 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for parser differentials, HTTP normalization gaps, ambiguous headers, path decoding drift, transfer-framing mismatches, and request smuggling routes. Use when the user asks to trace proxy and backend parse differences, conflicting path…

not rated 4 1mo ago A 109 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for reverse engineering, malware, DFIR, firmware, pwnable, and native exploit challenges. Use when the user asks to reverse a binary, unpack a sample, inspect a memory dump or PCAP, recover malware behavior, debug a crash, or build or verify…

not rated 4 1mo ago A 105 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for reverse proxies, Host headers, forwarded headers, vhost routing, websocket upgrades, path-prefix rewriting, base-URL derivation, and multi-node route resolution. Use when the user asks which host or container serves a route, why a…

not rated 4 1mo ago A 120 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for SSRF reachability, internal route probing, metadata-service access, credential pivoting, and token-to-accepted-privilege chains. Use when the user asks to trace SSRF sources, internal hosts, metadata endpoints, link-local tokens…

not rated 4 1mo ago A 113 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for image, audio, video, document, and container steganography. Use when the user asks to inspect metadata, alpha or palette channels, LSBs, thumbnails, appended trailers, QR fragments, transcoding artifacts, or recover a hidden payload from…

not rated 4 1mo ago A 100 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for CI/CD, registry, dependency drift, artifact provenance, image build, release pipeline, and runtime consumer challenges. Use when the user asks to trace dependency drift, registry pulls, malicious packages, build or release tampering, CI…

not rated 4 1mo ago A 103 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for SSR, template rendering, route loaders, hydration payloads, server-client render boundaries, and template-to-handler enforcement gaps. Use when the user asks to inspect SSR or template routes, trace render context or hydration data…

not rated 4 1mo ago A 111 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for CTF web, API, SSR, frontend, queue-backed app, and routing challenges. Use when the user asks to inspect a site or API, follow real browser requests, debug auth or session flow, trace uploads or workers, find hidden routes, or explain why…

not rated 4 1mo ago A 108 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for WebSocket and SSE handshakes, auth material, subscription state, realtime message schemas, reconnect behavior, and frame-driven runtime effects. Use when the user asks to inspect a WebSocket or SSE handshake, decode frames, trace…

not rated 4 1mo ago A 114 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Kerberos, WinRM, SMB, RDP, Windows credential material, replayable tickets, delegation edges, and host-to-host pivot chains. Use when the user asks to replay Kerberos material, trace a WinRM, SMB, or RDP pivot, understand host-to-host…

not rated 4 1mo ago A 115 tokens copy · 100% MIT

xAmirHamza77/ReverseOps-Skill

Skill Codex

Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when the user presents challenge infrastructure, binaries, prompts, hosts, or…

not rated 4 1mo ago A 108 tokens copy · 100% MIT

ReverseOps-router

42

xAmirHamza77/ReverseOps-Skill

Skill Codex

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct ReverseOps entrypoint is unclear.

not rated 4 1mo ago A 49 tokens original MIT

screenshots

43

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex

Advanced UI analysis and interaction through pixel-level reasoning to solve complex interaction problems, locate hard-to-find elements, verify visual states, and debug layout/rendering issues. Use as needed after UI Mapper inspection when advanced reasoning or non-standard views are required.

not rated 4 1mo ago A 52 tokens original MIT

api-security

44

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex needs its repo

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

not rated 4 1mo ago A 36 tokens original MIT

apk-reverse

45

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex needs its repo

Use when performing Android APK reverse engineering in a CLI environment. Applies to APK unpacking, Java decompilation, smali modification, repackaging, and Frida dynamic hooking, with on-demand switching to so/native analysis. Prefer locally installed jadx, apktool, frida, adb, ida-reverse, radare2.

not rated 4 1mo ago A 71 tokens original MIT

attack-chain

46

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex ⚠ unsafe

Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

not rated 4 1mo ago F ⚑ AI: unsafe 43 tokens original MIT

binary-diff

47

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex

Cross-version symbol migration and binary diffing. Use this when you have symbols/reverse engineering results from an old version and need to quickly migrate them to a new version. Applicable scenarios: kernel missing PDB with derivation from old-version symbols, batch-migrating function names after a program update…

not rated 4 1mo ago A 129 tokens original MIT

browser-automation

48

xAmirHamza77/ReverseOps-Skill

Skill Claude CodeCodex

Unified automation entry point. Covers browser automation (Playwright) and Windows desktop application automation (OpenReverse). Browser scenarios: open web pages, click, fill forms, scrape, take screenshots, automated logins, pentest page interactions. Desktop scenarios: operate GUI tools such as IDA/x64dbg, Windows…

not rated 4 1mo ago A 126 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: