zhaoxuya520/reverse-skill

▲ 409 stars today★ 37,912⑂ 5,265

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code

About zhaoxuya520/reverse-skill

zhaoxuya520/reverse-skill is an open-source project on GitHub, mainly written in PowerShell. Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + It currently holds 37,912 stars and 5,265 forks with 22 open issues, and was last pushed on 2026-09-22 (repository created 2026-05-13).

Project Overview

Git Homed tracks it on the Today's Trending board, currently at rank #10 with 409 new stars today.

GitHub Repository Details

Repository zhaoxuya520/reverse-skill · default branch main · size 3493 KB · watchers 126 · source: GitHub REST API and repository README

README

https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/reverse-skill

reverse-skill

Cybersecurity Skills Router · 逆向技能路由包

Navigate the dark waters, sail against the stream.

https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/release v1.0.1 https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/stars https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/forks https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/issues https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/license https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/changelog

https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/zhaoxuya520%2Freverse-skill | Trendshift https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/zhaoxuya520%2Freverse-skill | Trendshift


About · Getting Started · Usage · Tutorial · Fast route · Routing · Ops contracts · AI Bootstrap · Sponsors · Contributing

🌐 中文 · Project website · Online tutorial


About

If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.

When an AI agent (Claude Code, Codex, Cursor, OpenCode, or another compatible client) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.

User task
  → RULES.md
  → MASTER-ROUTING / master-route.ps1 (PRIMARY)
  → case-init / scope.md (auth + network_profile; no target ACT until ready)
  → Scenario skill → tools / MCP / scripts
  → timeline + Evidence→Finding→Path → report + field-journal

Why this exists:

Current status

| Routing rules | Regression benchmark | Core skill modules | CI platforms | Client model | |---:|---:|---:|---|---| | 44 (R0–R45) | 175 cases | 45 tracked modules | Windows + Ubuntu | Client-neutral |

The routing core is driven by one structured configuration, validated by cross-platform CI, and kept separate from optional client adapters.

PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/


https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/Star History chart for zhaoxuya520/reverse-skill


(back to top)

Sponsors

https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/UCloud AstraFlow
AstraFlow
UCloud AstraFlow provides one-click access to 200+ leading open-source models, including Kimi K3, DeepSeek V4/V3, Qwen 3, GLM 5.2, and HappyHorse—no model training required, ready to use out of the box.
https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/Atlas Cloud
https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/Powered by Atlas Cloud
Atlas Cloud is a full-modal AI inference platform that provides unified API access to 400+ curated image, video, audio, 3D, and language models. Atlas Cloud supports reverse-skill with model services for cross-platform routing verification, documentation, and open security workflows.
https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/Kite AI Kite AI builds identity and payment infrastructure for the agent economy. Its support helps sustain reverse-skill's open-source maintenance, routing benchmarks, and platform-neutral security workflows.

Built With


IDA Pro · radare2 · Ghidra · Binary Ninja

(back to top)

Getting Started

Prerequisites

Installation

git clone https://github.com/zhaoxuya520/reverse-skill.git

Then refresh the tool index per platform:

| Platform | Command | |----------|---------| | Windows | powershell -File skills/scripts/refresh-tool-index.ps1 | | Linux / macOS | bash skills/scripts/refresh-tool-index.sh | | Kali Linux | bash kali/scripts/refresh-tool-index.sh |

Check skills/tool-index.md to see detected tools.

Platform-specific docs:

(back to top)

Usage

Supported scenarios

| Scenario | Entry | |----------|-------| | APK / Android analysis | skills/apk-reverse/ | | iOS / mobile | skills/mobile-reverse/ | | Binary reverse (exe/dll/so/elf) | skills/ida-reverse/ / skills/radare2/ | | Binary Ninja / HLIL / MLIL / MCP | skills/binary-ninja-reverse/ | | .NET / C# | skills/dotnet-reverse/ | | Frontend JS / encrypted params | skills/js-reverse/ | | DSL VM / custom JS opcode VM | skills/reverse-engineering/dsl-vm-reverse/ | | HTTP capture / request replay | anything-analyzer, Reqable MCP + js-reverse/ | | Malware / YARA | skills/malware-analysis/ | | Penetration testing / scanning | skills/pentest-tools/ | | Attack chain / red-team orchestration | skills/attack-chain/ | | Case evidence review / report handoff | skills/case-review/ | | CTF competition | CTF-Sandbox-Orchestrator/ (42 sub-skills) | | Firmware / IoT | skills/firmware-pentest/ | | Patch diff / N-day | skills/patch-diff-exploit/ | | Pwn / exploit development | skills/pwn-chain/ | | EDR bypass | skills/edr-bypass-re/ | | API / GraphQL | skills/api-security/ | | Supply chain / SBOM | skills/supply-chain-security/ | | LLM / AI security | skills/llm-security/ | | OLLVM deobfuscation | skills/reverse-engineering/references/ollvm-deobfuscation.md | | Diagrams / reports | skills/diagram-generator/ / skills/docs-generator/ |

Key files

| File | Purpose | |------|---------| | README_AI.md | AI agent bootstrap and configuration | | RULES.md | Global routing rules (scope gate before ACT) | | skills/MASTER-ROUTING.md | PRIMARY fast ladder | | skills/routing.md | Task → skill routing matrix | | skills/SKILL.md | Master entry point | | skills/INDEX.md | Auto-generated, client-neutral skill navigation index | | skills/config/routing.json | Routing single source of truth (43 rules, R0–R44) | | skills/tool-index.md | Local tool status (auto-generated) | | skills/scripts/master-route.ps1 | One-shot PRIMARY triage (reads routing.json) | | skills/scripts/case-init.ps1 | Case dir: scope / timeline / workitems | | skills/case-review/ | Read-only Evidence graph review and artifact fixity checks | | skills/scripts/test-routing.ps1 | Routing regression runner (173 benchmark cases) | | skills/scripts/verify-routing-coherence.ps1 | Structure + supply-chain pin gate checks | | skills/scripts/extract-summaries.ps1 | Regenerates INDEX.md from skill frontmatter | | AGENTS.md | Platform-neutral repository instructions | | skills/ops/ | Scope, Evidence chain, roles, timeline (skill-router form) |

Testing (run after any routing/config change)

# 1. Routing regression — 173 (hint → expected PRIMARY) cases, fails CI on any mismatch
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/test-routing.ps1

2. Structure coherence + supply-chain pin gate (unpinned auto-install fails)

powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/verify-routing-coherence.ps1

3. Smoke: verify + script parse + quick route matrix

powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/smoke.ps1

4. INDEX.md drift check (regenerate with extract-summaries.ps1 if dirty)

powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/extract-summaries.ps1 -Check

GitHub Actions CI runs all of the above on Windows + Ubuntu for every push/PR.

Client-neutral integration

The routing core, regression suite, manifests, and case workflow do not depend on a specific AI client. Claude Code, Codex, Cursor, OpenCode, and other clients should load the repository through their own adapter or project-instruction mechanism. Client-specific configuration must remain optional and outside the core routing contract.

For Codex, the repository also exposes an optional adapter plugin at plugins/reverse-skill/. It delegates to the repository's existing routing core and does not register external MCP servers automatically.

Repository layout

.
├── README.md / README_zh.md / README_AI.md
├── RULES.md / RULES_zh.md
├── skills/
│   ├── MASTER-ROUTING.md / SKILL.md / routing.md
│   ├── ops/                   # ops contracts
│   ├── scripts/               # master-route, case-init, bootstrap, verify
│   ├── field-journal/
│   ├── apk-reverse/ mobile-reverse/ js-reverse/ dotnet-reverse/
│   ├── ida-reverse/ radare2/ reverse-engineering/ malware-analysis/
│   ├── pentest-tools/ attack-chain/ pwn-chain/ firmware-pentest/
│   ├── api-security/ supply-chain-security/ llm-security/
│   └── ...
├── CTF-Sandbox-Orchestrator/
├── docs/
├── kali/                      # see kali/README-kali.md
└── work/                      # local cases (gitignored)

(back to top)

Contributing

Contributions are welcome! Fork the repo, create a feature branch, and open a PR.

1. Fork the Project 2. git checkout -b feature/AmazingFeature 3. git commit -m 'Add some AmazingFeature' 4. git push origin feature/AmazingFeature 5. Open a Pull Request

Contributors

https://github.com/zhaoxuya520/reverse-skill/blob/HEAD/contributors

(back to top)

License

This project (reverse-skill) is primarily licensed under the MIT License (see LICENSE).

Submodule and third-party dependencies:

(back to top)

Acknowledgments

Thanks to all open-source tool authors. This project integrates tools across reverse engineering, penetration testing, CTF, and security analysis — every tool is the fruit of community effort.

Special thanks to the OLLVM deobfuscation ecosystem contributors and everyone who submitted test samples, issues, and PRs.

(back to top)

Contact

Disclaimer

This project is intended solely for lawful security research, education, CTF competitions, and testing of systems that you own or have explicit authorization to assess.

Unauthorized access, scanning, exploitation, disruption, data acquisition, or any other use against systems without prior permission is strictly prohibited. Users are solely responsible for complying with applicable laws, regulations, and the authorized scope of testing. The maintainers accept no liability for misuse of this project or for any resulting damage or legal consequences

Installation and download security

See Security Policy, Installation and Download Security Guidance, and the 2026-09-03 repository security review.

Community quick start and issue triage

See Quick Start and Community Issue Triage for installation, client integration, and how community issues are classified. Installation/archive security details remain in Installation and Download Security Guidance.

GitHub Stars & Activity

37,912Stars
5,265Forks
22Open issues
PowerShellLanguage

GitHub Popularity

GitHub stars37,912
Forks5,265
Open issues22
Primary languagePowerShell
LicenseMIT
Stars gained today409
Created2026-05-13
Last pushed2026-09-22

Trending History

Daily boardrank #10 · ▲ 409 stars

Related GitHub Projects

1

openclaw / openclaw

TypeScript★ 390,575⑂ 82,158▲ 134 stars
→
2

obra / superpowers

Shell★ 291,927⑂ 26,128▲ 470 stars
→
3

mattpocock / skills

Shell★ 270,194⑂ 22,757▲ 636 stars
→
4

tensorflow / tensorflow

C++★ 200,415⑂ 77,576▲ 31 stars
→
5

microsoft / vscode

TypeScript★ 193,046⑂ 43,513▲ 78 stars
→
6

flutter / flutter

Dart★ 179,112⑂ 32,313▲ 30 stars
→
7

vercel / next.js

JavaScript★ 142,582⑂ 33,117▲ 31 stars
→
8

golang / go

Go★ 139,033⑂ 20,563▲ 44 stars
→

More Trending Repositories