Skill Claude CodeCodex
Use for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
ReverseOps-Skill is an AI-powered security orchestration framework that routes AI agents to the right tools and workflows for reverse engineering, APK analysis, malware, pentesting, CTFs, firmware, exploit development, and JavaScript deobfuscation, delivering repeatable investigations with structured evidence and reports.
This repository also configures its own agents. See what ReverseOps-Skill tells them →
Skill Claude CodeCodex
Use for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
Skill Claude CodeCodex
Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
Skill Claude CodeCodex
Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
Skill Claude CodeCodex
Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
Skill Codex
Create clear, editable diagrams from messy or structured inputs. Prefer text-based diagram source first so the result can be reviewed, versioned, and refined. Render to files only when the user asks for an image/PDF or when a downloadable artifact would materially help.
Skill Claude CodeCodex
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
Skill Claude CodeCodex
Creates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any completed reverse engineering, penetration testing, CTF, or security analysis task to generate a formal report in the user's…
Skill Claude Code
.NET / C# binary reverse engineering. Use when the target is a .NET assembly (CLR in the PE header, managed .exe/.dll programs), C# build artifacts (including NativeAOT), red team Sharp tools (Rubeus / SharpHound, etc.), .NET obfuscated programs (ConfuserEx / SmartAssembly / Babel / Eazfuscator), or .NET loaders /…
Skill Claude CodeCodex
Reverse engineering defender implementations → Red Team targeted bypass. Reverse engineer EDR / Defender / AV hook tables, ETW providers, and AMSI implementations first, then write targeted unhooking / indirect syscalls / ETW patches / call stack spoofing. Aligned with MITRE ATT&CK T1562 Impair Defenses. Trigger…
Skill Claude CodeCodex
Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
Skill Claude CodeCodex
Finding-validation discipline: promote scanner/hunch output from "candidate" to "confirmed", or demote it to false positive. Hypothesis matrix, minimal repro, negative control, rate guardrails, evidence closure, post-fix retest. Trigger keywords: validate finding, false positive, PoC, reproduction, exploit validation…
Skill Claude CodeCodex needs its repo
Firmware / IoT pentest chain. Start from a .bin / .img blob and close the full loop: reverse → extract → emulate → exploit. Methodology follows the OWASP FSTM nine stages; the toolchain centers on binwalk v3, unblob, EMBA, Firmadyne, and AFL++. Use cases: router/camera/smart-home firmware audits, firmware update…
Skill Claude CodeCodex
Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
Skill Claude CodeCodex
Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
Skill Claude CodeCodex
Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.
Skill Claude CodeCodex
IDA Pro reverse engineering assistance skill. Be sure to use this skill whenever the user mentions reverse engineering, decompilation, analyzing binary/PE/ELF/APK/DLL/SO files, cracking, finding passwords, vulnerability analysis, malware analysis, or firmware analysis, or needs to analyze exe/dll/so/elf/macho/sys…
Skill Claude CodeCodex
Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
Skill Claude CodeCodex
Use when doing front-end JavaScript reverse engineering with js-reverse-mcp; suited for signature-chain location, page observation and forensics, runtime sampling, local environment-patching reproduction, and evidence-based output. Prefers the js-reverse tools available in the current environment; when a stronger…
Skill Claude CodeCodex needs its repo
Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.
Skill Claude CodeCodex
Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
Skill Claude CodeCodex
Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.
Skill Claude CodeCodex
Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
Skill Claude CodeCodex
Passive reconnaissance and attack-surface mapping. Subdomain enumeration, certificate transparency, historical snapshots, fingerprinting and third-party asset discovery — passive/semi-passive methods first, zero target contact until the gate allows it. Trigger keywords: OSINT, passive recon, attack surface, subdomain…
Skill Claude CodeCodex
Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: