reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering".
$ npx -y skills add zhaoxuya520/reverse-skill --skill ida-reverse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ida-reverseContext preview
The summary Claude sees to decide when to auto-load this skill.
IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering".
name: ida-reverse description: | IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering". This includes requests like "看看这个exe", "分析这个dll", "帮我破解", "找一下密码", "这个软件怎么注册", etc. Use the bundled scripts (scripts/start.ps1, scripts/open.ps1) for deterministic server management and file opening — do NOT write ad-hoc PowerShell commands for these operations.
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认当前任务是否命中本 skill 的适用范围 3. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 4. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 5. `ACT`: 进入"工作流"第一步并执行,不要停在确认状态
1. **`idb_open`(旧名 `idalib_open`)不要直接靠部分 AI 客户端 MCP 调用**
2. **`C:\Windows\System32\` 文件无权限打开**
3. **启动服务器命令阻塞对话**
4. **MCP 服务器名不能用横线**
5. **Remote HTTP vs Local Stdio**
6. **PR #389 修复了部分 schema 问题**
7. **idalib 超时留下孤儿 worker 进程锁文件**
8. **带自动分析打开看起来像卡死**
9. **HTTP MCP 会在登录后静默退出**
10. **Streamable HTTP GET `/mcp` 会卡住单线程 supervisor**
| 步骤 | 做什么 | 用什么 | |------|--------|--------| | 1 | 确保 HTTP 服务器在运行 | `scripts/start.ps1`(无参数) | | 2 | 打开目标二进制文件 | `scripts/open.ps1 -Path "xxx.exe"` | | 3 | 使用 MCP 分析工具 | 直接调用 `idapro_*` / HTTP tools(约 65 个,视版本而定) | | 4 | 分析完毕 | 工具自动可用 |
路径:`scripts/start.ps1`
**调用方式**:
powershell -File "<skill-root>\ida-reverse\scripts\start.ps1"
路径:`scripts/open.ps1`
**调用方式**:
powershell -File "<skill-root>\ida-reverse\scripts\open.ps1" -Path "C:\path\to\file.exe"
**可选参数**:
# 指定 SessionId powershell -File "scripts\open.ps1" -Path "file.exe" -SessionId "my_session" # 跳过自动分析(大文件推荐) powershell -File "scripts\open.ps1" -Path "large.exe" -NoAutoAnalysis # 设置超时,避免带自动分析时长时间无返回 powershell -File "scripts\open.ps1" -Path "file.exe" -TimeoutSeconds 600
**输出约定**:
# 分析进行中(每 10 秒输出一次) INFO:opening:11/600s # 成功打开 OK:sample.exe:abcd1234 # 成功打开,但因锁文件降级到 Temp 副本 OK:1234abcd-sample.exe:abc
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…