reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
$ npx -y skills add zhaoxuya520/reverse-skill --skill ot-ics --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ot-icsContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
name: ot-ics description: Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` — **工控环境误操作可致物理危害** 2. `NOW`: 书面授权必须写清:站点、网段、是否允许主动扫描/写寄存器 3. `NOW`: case-init;默认 **passive-first**;`ready_for_act` 前禁止对 PLC 写操作 4. `NEXT`: tool-index;多数工控工具需手动与隔离实验网 5. `ACT`: 资产与分区识别 → 暴露面 → 只读验证
MUST NOT 在未明确允许时: - 对 PLC 写线圈/寄存器 - 全网高速率扫描生产 OT - 中断安全仪表系统(SIS)相关路径 优先:只读识别、流量镜像、离线固件/配置分析
□ Purdue L0–L5 草图:现场设备 → 控制 → 监督 → 站点 DMZ → 企业 □ 资产清单:PLC/RTU/HMI/工程师站/历史库/Jump host □ 协议与端口基线(仅授权网段)
□ SPAN/镜像 PCAP → protocol-reverse / Wireshark 工控解析器 □ 配置与工程文件离线审计(TIA/RSLogix 导出等) □ 默认口令与明文协议(Modbus 无认证)记录为 Finding,不写盘改值
□ 低速识别,维护窗口 □ 只读功能码优先 □ 每步 Evidence;异常立即停止并通报
□ 控制器固件版本 → CVE 映射(不盲刷固件) □ 联合 firmware-pentest 做离线镜像分析
| 工具 | 用途 | 注意 | |------|------|------| | Wireshark 工控 dissectors | 被动解析 | 镜像流量 | | Nmap NSE(受限) | 识别 | 速率与时间窗 | | Claroty/Nozomi 等 | 资产发现 | 商业/现场 | | PLC 厂商工程软件 | 配置审计 | 离线优先 | | binwalk / Ghidra | 固件 | 离线 |
**上游**: MASTER R28 **下游**: 固件深挖 `firmware-pentest`;协议 `protocol-reverse`;IT 横向 `windows-ad`/`attack-chain` **同级**: 不要用普通 Web 扫默认参数打 OT
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…