reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
$ npx -y skills add zhaoxuya520/reverse-skill --skill protocol-reverse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/protocol-reverseContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
name: protocol-reverse description: Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` — 确认授权与常规操作边界 2. `NOW`: 确认任务是否为**协议/流量/序列化格式**逆向(非纯 Web 参数签名 → 转 `js-reverse/`) 3. `NOW`: 若有目标网络交互 → `../scripts/case-init.ps1` 完成 scope;`auth` 未 granted 禁止对目标 ACT 4. `NEXT`: 读取 `../tool-index.md`;缺工具 bootstrap(tshark/wireshark 等可能需手动) 5. `ACT`: 进入工作流 Phase 1,产出帧布局或消息字典草稿
| 情况 | 去哪 | |------|------| | 仅 HTTP 参数签名 / JS 加密 | `js-reverse/` | | 仅 TLS 证书问题 | `pentest-tools/` 或浏览器代理 | | 固件内协议栈深挖 + 仿真 | `firmware-pentest/` 后再回本 skill |
□ 拿到样本:PCAP / 代理导出 / 客户端日志 / 二进制 □ 标记方向:C→S / S→C;是否有握手、心跳、重连 □ 固定头?魔数?长度字段?TLV?定长? □ 是否压缩(zlib/gzip/lz4)或加密(AES/ChaCha 帧内) □ tshark -r cap.pcap -T fields -e frame.number -e ip.src -e tcp.payload
□ 对齐多个同类消息,找不变字节 / 自增序列号 □ 长度字段:大端/小端、含头/不含头 □ 校验:CRC16/32、checksum、HMAC 位置 □ 画出状态机:Connect → Auth → Ready → Request/Response → Close □ 工具:Wireshark 自定义 dissector 草稿 / ImHex / 010 Editor 模板 / Kaitai Struct
□ Protobuf:.proto 恢复(blackboxprotobuf / pbtk / protoc --decode_raw) □ gRPC:HTTP/2 headers + protobuf body □ 加密:找密钥派生(客户端 so/dll/JS)→ 联合 ida-reverse / js-reverse / apk-reverse □ 重放:仅在授权 scope 内;先无害字段再敏感操作
MUST 产出: - 消息类型表(name / opcode / fields) - 至少 1 条可复现的解码命令或脚本 - Evidence:原始 hex 摘录 + 解码结果(脱敏)
| 工具 | 必需 | 用途 | 自举 | |------|------|------|------| | tshark / Wireshark | 强烈建议 | PCAP 解析 | 手动 / winget | | Python3 | 是 | 解码脚本 | 系统 | | blackboxprotobuf | 可选 | 未知 protobuf | pip | | ImHex / 010 | 可选 | 结构模板 | 手动 | | IDA / r2 / Ghidra | 按需 | 客户端序列化函数 | 见对应 skill |
**上游**: `MASTER-ROUTING` R21 · `routing.md` **下游**: 需客户端算法 → `ida-reverse`/`js-reverse`;需利用重放 → `pentest-tools`/`api-security` **同级**: `malware-analysis`(C2 协议)、`digital-forensics`(流量取证)
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…