reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
$ npx -y skills add zhaoxuya520/reverse-skill --skill macos-reverse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/macos-reverseContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
name: macos-reverse description: Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` 2. `NOW`: 确认目标为 macOS/Mach-O/App bundle(iOS IPA → `mobile-reverse/`) 3. `NEXT`: tool-index;jtool2/lldb 等 4. `ACT`: 签名与装载信息 → 静态 → 动态(lldb/Frida)
file target codesign -dv --verbose=4 target spctl -a -vv target 2>&1 otool -L target
□ class-dump / swift-demangle / Hopper / Ghidra / IDA □ 字符串与 XPC 服务名、TCC 敏感 API □ LC_LOAD_dylib 依赖与 rpath
□ lldb / Frida □ fs_usage / log stream 观察 □ 网络:联合 protocol-reverse 或代理
| 工具 | 用途 | |------|------| | otool / nm / codesign | 系统自带 | | Hopper / Ghidra / IDA | 反编译 | | class-dump / dsdump | ObjC | | Frida / lldb | 动态 | | jtool2 | Mach-O |
**上游**: MASTER R31 **下游**: iOS → mobile-reverse;通用样本 → malware-analysis
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…