zhaoxuya520/reverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients.

About the project

Reverse Skill is a routing package for AI coding agents that selects appropriate reverse-engineering, penetration-testing, and security-research methods and tools for a given target. It is used for tasks involving APKs, binaries, frontend JavaScript, packet captures, CTF challenges, and authorized penetration testing. Its catalogue add-ons provide the skills and instructions that guide these workflows.

This repository also configures its own agents. See what reverse-skill tells them →

35kStars on the repository
91Mods indexed here, across every type
8d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

patch-diff-exploit

73

zhaoxuya520/reverse-skill

Skill Claude CodeCodex needs its repo

A method for comparing a vulnerable software version with its patched version to work out what security bug was fixed. It is aimed at turning that understanding into a proof of concept, meaning a small demonstration that triggers the bug.

not rated 35k +822 8d ago A Socket: warnSnyk: failSkillSpector: pass 192 tokens original MIT

pentest-tools

74

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

A toolkit workflow for authorised penetration testing, which means checking systems for weaknesses by simulating attacks. It covers discovery, port and vulnerability scanning, web testing, and password testing through common security tools.

not rated 35k +822 8d ago A Socket: failSnyk: passSkillSpector: warn 133 tokens original MIT

src-hunter

75

zhaoxuya520/reverse-skill

Skill Claude Code

A guided workflow for authorised bug-bounty and Security Response Center testing, covering reconnaissance, testing, and reporting. It explains common web attack types and provides example payloads and previously disclosed vulnerability cases.

not rated 35k +822 changed 7d ago A Snyk: passSkillSpector: pass 243 tokens original MIT

protocol-reverse

76

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: pass 30 tokens original MIT

pwn-chain

77

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

A workflow for turning a known memory-safety bug in a binary into a working exploit. It focuses on making the exploit reliable across different libraries, protections, and remote environments.

not rated 35k +822 8d ago A Socket: failSnyk: failSkillSpector: pass 271 tokens original MIT

radare2

78

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together…

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: pass 112 tokens original MIT

radio-sdr

79

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: pass 34 tokens original MIT

reverse-engineering

80

zhaoxuya520/reverse-skill

Skill Claude Code needs its repo

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it…

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: warn 117 tokens original MIT

dsl-vm-reverse

81

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. Use when analyzing IIFE or switch-based opcode dispatchers, extracting instruction tables, recovering bytecode semantics, capturing VM state at runtime, or reconstructing execution flow.

not rated 35k +822 8d ago A Snyk: passSkillSpector: pass 63 tokens original MIT

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

not rated 35k +822 8d ago A Socket: passSnyk: warnSkillSpector: warn 37 tokens original MIT

thick-client

83

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: warn 30 tokens original MIT

threat-hunting

84

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

not rated 35k +822 8d ago A Socket: passSnyk: passSkillSpector: pass 29 tokens original MIT

threat-intelligence

85

zhaoxuya520/reverse-skill

Skill Claude CodeCodex needs its repo

Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.

not rated 35k +822 8d ago A Snyk: warnSkillSpector: pass 56 tokens original MIT

wifi-wireless

86

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.

not rated 35k +822 8d ago A Socket: warnSnyk: passSkillSpector: pass 31 tokens original MIT

windows-ad

87

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.

not rated 35k +822 8d ago A Socket: warnSnyk: failSkillSpector: warn 34 tokens original MIT

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Use the reverse-skill repository from Codex for authorized reverse engineering, security analysis, CTF, and defensive testing tasks. Requires the reverse-skill repository to be available as the current workspace or an explicitly supplied local path.

not rated 35k +822 8d ago A Socket: failSnyk: passSkillSpector: pass 50 tokens original MIT

zhaoxuya520/reverse-skill

Skill Codex

Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.

not rated 35k +822 8d ago A Snyk: failSkillSpector: pass 55 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: