reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
$ npx -y skills add zhaoxuya520/reverse-skill --skill api-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/api-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
name: api-security description: Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认当前任务是否命中本 skill 的适用范围 3. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 4. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 5. `ACT`: 进入"工作流"第一步并执行,不要停在确认状态
> 覆盖 REST / GraphQL / WebSocket / SOAP 全协议 > 10 阶段方法论,从发现到 CI/CD 集成
主动发现:
□ Vespasian: 无头浏览器爬取 → 自动生成 OpenAPI 3.0 / GraphQL SDL 规范
□ Entropy --discover: 从 robots.txt + JS 文件提取端点
□ Kiterunner / ffuf: 爆破未文档化的端点路径
□ 检查常见路径: /swagger.json, /openapi.json, /graphql, /api-docs
GraphQL 内省(三级尝试):
1. 标准内省查询
2. 精简查询(绕过 WAF 全量封禁)
3. 仅查 __schema { types { name } }(最小探测)JWT 分析(jwt_tool / Burp): □ alg:none 攻击: 修改头部为 "alg":"none",清空签名 □ 密钥混淆: RS256 公钥 → HS256 对称密钥 □ 弱 HMAC 密钥爆破: jwt_tool -C -d wordlist.txt □ 过期/声明篡改: 修改 exp/iat/sub/role 声明 □ kid 注入: ../../etc/passwd → HMAC 签名绕过 OAuth 2.0: □ redirect_uri 操控 → 授权码泄漏 □ CSRF via state 参数缺失 □ Token 在 Referer 头泄漏 □ PKCE 缺失检测 GraphQL 认证: □ mutation 通过 GET 请求绕过认证(CSRF) □ 批查询认证绕过
BOLA(对象级授权绕过):
□ 遍历数字 ID: /user/1 → /user/2 → /user/3
□ 遍历 UUID
□ 遍历用户名/邮箱
□ Burp Autorize: 双会话重放对比
BFLA(功能级授权绕过):
□ 普通用户执行管理员 API
□ HTTP 方法切换: GET → PUT → PATCH → DELETE
□ API 版本降级: /v2/admin → /v1/admin
□ 批量操作注入: {"users": [1,2,3]} → {"users": [1,2,3,admin_id]}
工具: Burp Autorize, AuthMatrix, Entropy (malicious_insider persona)内省泄漏 → 信息暴露检测 别名过载 → 100+ 别名 DoS 批查询 → 10+ 同时查询 DoS 字段重复 → __typename × 500 指令过载 → 递归 @skip/@include 循环查询 → 深度嵌套内省递归 字段建议 → 错误消息信息泄漏 GraphiQL/Playground 暴露 → IDE 公开风险 GET 突变 → CSRF 风险 追踪/调试模式 → 元数据泄漏 工具: FireTail, Escape DAST, api.sh (Phases 1-3)
□ HTTP 方法切换: GET→POST→PUT→DELETE→OPTIONS→PATCH
□ Content-Type 篡改: JSON→XML→multipart
□ NoSQL 注入: {"username": {"$gt": ""}}
□ SSRF via URL 参数: webhook URL/头像 URL/导入 URL
□ XXE in XML 端点
□ 参数污染: /api?role=user&role=admin
□ 批量赋值: 向请求体添加 is_admin: true□ Entropy compare: diff v1 vs v2 API → 状态码变化/字段删除/延迟回归 □ 多角色工作流测试: admin/user/readonly 权限矩阵 □ 优惠券/积分/价格操控 □ 竞态条件: 并发请求测试 TOCTOU
□ 端点发现 □ 消息注入(注入 payload、原型污染) □ 超大消息处理 □ 类型混淆 □ 跨站点 WebSocket 劫持(CSWH)
□ 限速绕过 via 头部: X-Forwarded-For, X-Real-IP □ 路径变体: /api/ → /api → /Api/ → /API/ □ Slowloris 低带宽耗尽 □ GraphQL 批查询深度嵌套 DoS □ IP 轮换测试(ProxyCat 代理池)
□ 响应过度暴露: 对比 API 返回 vs UI 展示 □ 分页枚举: ?page=1&limit=10000 □ 错误消息信息泄漏: 堆栈跟踪/内部路径/SQL 错误 □ GraphQL 嵌套遍历访问越权数据 □ OpenAPI 规范暴露敏感端点
□ Entropy --ci --watch: spec 变更时自动重跑 □ Escape DAST: 按严重度阈值自动阻断构建 □ 发现持久化为回归测试 □ StackHawk(开发者优先、ZAP 内核)
| 工具 | 用途 | 获取 | |------|------|------| | Vespasian | 流量 → OpenAPI/GraphQL 规范 | GitHub: praetorian-inc/vespasian | | Entropy | LLM 生成攻击场景,5 personas | GitHub: arjinexe/entropy-chaos | | Escape DAST | 业务逻辑安全测试 | escape.tech | | api.sh | 8 阶段全协议攻击管道 | GitHub: Sharon-Needles/api | | FireTail | GraphQL 12 专项测试 | firetail.ai | | jwt_tool | JWT 全面测试 | GitHub: ticarpi/jwt_tool | | Burp Autorize | 双会话授权对比 | Burp BApp Store |
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…
统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。…