ReverseOps-Skill is an AI-powered security orchestration framework that routes AI agents to the right tools and workflows for reverse engineering, APK analysis, malware, pentesting, CTFs, firmware, exploit development, and JavaScript deobfuscation, delivering repeatable investigations with structured evidence and reports.
N-day patch diffing to exploitation. Reverse-engineer the vulnerability from vendor-released patches, write a PoC, and turn it into a usable attack module. Use cases: a known CVE with a patch but no PoC, SRC/red team targeting assets that have not been updated in time, N-day weaponization, Patch Tuesday follow-up.…
Active penetration testing toolchain. Covers reconnaissance, port scanning, vulnerability scanning, web exploitation, SQL injection, directory brute-forcing, password cracking, and more. Exposes 20+ security tools to the AI agent via MCP servers (pentestMCP / mcp-security-hub). Trigger keywords: penetration testing…
A structured vulnerability-hunting workflow for security-response programs, penetration tests, and bug bounty work. It moves through intake, reconnaissance, enumeration, testing, and reporting.
A workflow for turning a known memory-corruption bug in a program into a working exploit. Memory corruption means a program handles memory incorrectly, for example through a buffer overflow or use-after-free.
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together…
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
Purpose: turn raw engagement output (reports/.md, evidence chains, case dirs) into machine-readable findings and an interactive dashboard — the ReverseOps panel (panel/).
Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it…
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
★not rated 4 1mo agoA34 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: