reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
$ npx -y skills add zhaoxuya520/reverse-skill --skill go-rust-reverse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/go-rust-reverseContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
name: go-rust-reverse description: Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` 2. `NOW`: 确认样本为 Go/Rust 编译产物(`file`/字符串/运行时特征) 3. `NEXT`: GoReSym / 相关插件是否可用 4. `ACT`: 运行时识别 → 符号/元数据恢复 → 业务逻辑
□ 识别 go.buildid、runtime 符号残留、pclntab □ GoReSym / redress / IDA Go 插件恢复函数名 □ 注意 interface、slice、string 结构在反编译中的形态 □ 网络/加密库路径:crypto/* net/http
□ panic 字符串、rust_begin_unwind、crate 路径暗示 □ 范型实例化导致的代码膨胀;先定位字符串 xref □ 异步/tokio 状态机需结合交叉引用
□ 仍可用 Frida;注意 Go 栈与调度 □ 优先日志与配置字符串驱动断点
| 工具 | 用途 | |------|------| | GoReSym | Go 元数据 | | IDA/Ghidra + Go/Rust 插件 | 反编译 | | radare2 | 快速字符串 | | strings / rabin2 | 分诊 |
**上游**: MASTER R33 **下游**: 恶意样本流程 `malware-analysis`;通用 RE `reverse-engineering`
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…