reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
$ npx -y skills add zhaoxuya520/reverse-skill --skill cloud-k8s --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cloud-k8sContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
name: cloud-k8s description: Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` — **云/K8s 测试必须书面授权** 2. `NOW`: case-init + scope;明确账号边界、禁止破坏性操作 3. `NOW`: 确认是云元数据/容器/K8s/IAM,而非普通 Web 扫(后者 `pentest-tools/`) 4. `NEXT`: tool-index;kubectl/aws/gcloud 等多为手动安装 5. `ACT`: 从「身份与暴露面」开始,禁止默认全网扫描
□ 当前身份:云 AK/SK、K8s SA、节点 SSH? □ 范围:单账号 / 单 cluster / 单 namespace □ 网络档:authorized_target_only
# 示例(按厂商替换;MUST 在授权账号内) aws sts get-caller-identity aws s3 ls # Azure / GCP 对应 identity 命令
□ 公开桶 / 错误 ACL □ 元数据:IMDSv1 vs v2;SSRF 链 □ 角色可扮演(PassRole)与横向
□ 是否 privileged / hostPath / hostNetwork □ capabilities(SYS_ADMIN 等) □ 可写宿主机路径 → 逃逸候选 □ 镜像历史与已知 CVE → Trivy
kubectl auth can-i --list kubectl get pods,secrets,svc -A kubectl get clusterrolebindings
□ SA token 挂载与权限 □ 危险 admission webhook 缺失 □ etcd / dashboard 暴露 □ 网络策略是否默认放行
| 工具 | 用途 | 自举 | |------|------|------| | kubectl | 集群交互 | 手动 | | trivy | 镜像/IaC | bootstrap `trivy` 若可用 | | kube-bench / kubeaudit | CIS/配置 | 手动 | | pacu / scoutsuite | 云审计(授权) | 手动 | | nuclei | 已知云漏洞模板 | bootstrap nmap/nuclei 生态 |
**上游**: MASTER R23 **下游**: 拿到节点 shell → `attack-chain` / `windows-ad`;镜像漏洞 → supply-chain **MUST NOT**: 未授权扫公有云其他租户
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…