reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
$ npx -y skills add zhaoxuya520/reverse-skill --skill thick-client --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/thick-clientContext preview
The summary Claude sees to decide when to auto-load this skill.
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
name: thick-client description: Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
1. `NOW`: 读取 `../field-journal/precedent-pentest.md` 2. `NOW`: 确认目标是 **桌面厚客户端**(Win/macOS/Linux GUI 或服务伴生),非纯 Web 3. `NOW`: case-init;安装包来源与测试账号写入 scope 4. `NEXT`: 工具(Burp 上游代理、进程监控、逆向工具) 5. `ACT`: 信任边界图 → 本地面 → 网络面 → 更新/供应链
□ 进程树、子进程、驱动/服务 □ 监听端口与出站域名 □ 本地敏感路径:%APPDATA%、Keychain、注册表
□ 明文配置、硬编码密钥、调试开关 □ DLL 劫持/搜索顺序(Windows) □ 数据库文件(SQLite)权限与加密 □ IPC:谁可连接?是否鉴权?
□ 系统代理 / 应用自定义 TLS □ 证书钉扎 → 联合 mobile/js 方法学或 Frida □ API 越权:客户端隐藏的管理接口
□ .NET → dotnet-reverse;原生 → ida/ghidra;Electron → asar + js-reverse
| 工具 | 用途 | |------|------| | Process Monitor / API Monitor | 行为 | | Burp / mitmproxy | 流量 | | dnSpy / IDA / Ghidra | 逆向 | | Sysinternals | Windows 面 | | asar / nexe 检测 | Electron |
**上游**: MASTER R32 **下游**: 纯协议 `protocol-reverse`;供应链更新 `supply-chain-security`
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…