Skip to content
Security
Skill

/macos-reverse

Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

BOOST
From plugin
reverse-skill
39k46 skills
Install
$ npx -y skills add zhaoxuya520/reverse-skill --skill macos-reverse --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/macos-reverse

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

SKILL.md

macos-reverse.SKILL.md
name: macos-reverse
description: Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

macOS / Mach-O Reverse Engineering

ACTION REQUIRED(读完后立刻执行)

1. `NOW`: 读取 `../field-journal/precedent-reverse.md` 2. `NOW`: 确认目标为 macOS/Mach-O/App bundle(iOS IPA → `mobile-reverse/`) 3. `NEXT`: tool-index;jtool2/lldb 等 4. `ACT`: 签名与装载信息 → 静态 → 动态(lldb/Frida)

适用场景

  • Mach-O 可执行文件 / dylib / framework
  • .app bundle、LaunchAgent/Daemon
  • Objective-C / Swift 符号与 runtime
  • 公证/签名、Hardened Runtime、TCC 相关行为分析
  • macOS 恶意软件静态/动态分析(联合 malware-analysis)

工作流

1. 包体与签名

file target
codesign -dv --verbose=4 target
spctl -a -vv target 2>&1
otool -L target

2. 静态

□ class-dump / swift-demangle / Hopper / Ghidra / IDA
□ 字符串与 XPC 服务名、TCC 敏感 API
□ LC_LOAD_dylib 依赖与 rpath

3. 动态

□ lldb / Frida
□ fs_usage / log stream 观察
□ 网络:联合 protocol-reverse 或代理

工具链

| 工具 | 用途 | |------|------| | otool / nm / codesign | 系统自带 | | Hopper / Ghidra / IDA | 反编译 | | class-dump / dsdump | ObjC | | Frida / lldb | 动态 | | jtool2 | Mach-O |

参考

  • `references/macho-triage.md`
  • `../mobile-reverse/`(iOS) `../ghidra-reverse/` `../malware-analysis/`

路由上下文

**上游**: MASTER R31 **下游**: iOS → mobile-reverse;通用样本 → malware-analysis

任务完成自检

  • [ ] 是否记录签名/Hardened Runtime 状态?
  • [ ] 是否有地址级/符号级结论?
  • [ ] Checklist?
Read more
Ships withreverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Get the whole plugin
Stats
39,460
Stars
5,492
Forks
Active
Maintenance
PowerShell
Language
MIT
License
11d ago
Last commit
4mo ago
Created
3h ago
Added

Repo: zhaoxuya520/reverse-skill

Other skills on reverse-skill.

binary-diff
Skill

binary-diff

跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…