Source

zhaoxuya520/reverse-skill

88 skills · 31.7K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
9511
reverse-engineering Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, o…
zhaoxuya520/reverse-skill
1.1K
2
apk-reverse 在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解?
zhaoxuya520/reverse-skill
955
3
ida-reverse IDA Pro 逆向分析? Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they…
zhaoxuya520/reverse-skill
873
4
pentest-tools 主动渗透测试工? 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安? 触发?
zhaoxuya520/reverse-skill
845
5
radare2 Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse e…
zhaoxuya520/reverse-skill
824
6
binary-diff 跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:? 核心方法:用 LLM 做…
zhaoxuya520/reverse-skill
783
7
diagram-generator generate, refine, validate, and render diagrams from natural language, notes, code snippets, schemas, tables, or exis…
zhaoxuya520/reverse-skill
770
8
firmware-pentest 固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工?…
zhaoxuya520/reverse-skill
767
9
edr-bypass-re 逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现? 再写针对性的 unhook / 间…
zhaoxuya520/reverse-skill
758
10
patch-diff-exploit N-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知 CVE 编号但只有补丁没…
zhaoxuya520/reverse-skill
755
11
pwn-chain 从逆向走到可用利用 (Working Exploit) 的? 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit…
zhaoxuya520/reverse-skill
752
12
reverse-skill-router Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documen…
zhaoxuya520/reverse-skill
739
13
dotnet-reverse .NET / C# 二进制逆向。当目标是 .NET assembly(PE 头含 CLR、.exe/.dll 托管程序)、C# 编译产物(含 NativeAOT)、红队 Sh…
zhaoxuya520/reverse-skill
712
14
js-reverse 在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证…
zhaoxuya520/reverse-skill
704
15
ghidra-reverse Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Gh…
zhaoxuya520/reverse-skill
673
16
mobile-reverse Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis…
zhaoxuya520/reverse-skill
658
17
browser-automation 统一自动化? 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI…
zhaoxuya520/reverse-skill
646
18
protocol-reverse Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven p…
zhaoxuya520/reverse-skill
645
19
malware-analysis Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YA…
zhaoxuya520/reverse-skill
644
20
macos-reverse Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint secu…
zhaoxuya520/reverse-skill
638
21
docs-generator Creates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, archit…
zhaoxuya520/reverse-skill
637
22
go-rust-reverse Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery…
zhaoxuya520/reverse-skill
636
23
api-security Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication…
zhaoxuya520/reverse-skill
634
24
browser-extension-reverse Use for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background…
zhaoxuya520/reverse-skill
634
25
code-audit Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API h…
zhaoxuya520/reverse-skill
632
26
attack-chain Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial acces…
zhaoxuya520/reverse-skill
626
27
llm-security Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG…
zhaoxuya520/reverse-skill
621
28
digital-forensics Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and…
zhaoxuya520/reverse-skill
620
29
database-security Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/comm…
zhaoxuya520/reverse-skill
619
30
hardware-security Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage,…
zhaoxuya520/reverse-skill
619
31
thick-client Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, …
zhaoxuya520/reverse-skill
616
32
threat-hunting Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection va…
zhaoxuya520/reverse-skill
616
33
supply-chain-security Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integr…
zhaoxuya520/reverse-skill
614
34
wifi-wireless Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection r…
zhaoxuya520/reverse-skill
614
35
windows-ad Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM re…
zhaoxuya520/reverse-skill
614
36
identity-federation Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration,…
zhaoxuya520/reverse-skill
612
37
radio-sdr Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded lab…
zhaoxuya520/reverse-skill
612
38
email-security Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC pat…
zhaoxuya520/reverse-skill
608
39
ot-ics Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol d…
zhaoxuya520/reverse-skill
608
40
cloud-k8s Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, conta…
zhaoxuya520/reverse-skill
607
41
case-review Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverag…
zhaoxuya520/reverse-skill
412
42
ctf-sandbox Thin PRIMARY for CTF / AWD / 靶场 multi-type orchestration. Hands off to the sidecar CTF-Sandbox-Orchestrator. Use wh…
zhaoxuya520/reverse-skill
268
43
threat-intelligence Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat…
zhaoxuya520/reverse-skill
228
44
src-hunter 实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个…
zhaoxuya520/reverse-skill
77
45
competition-web-runtime Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for CTF web, API, SSR, frontend, queue-b…
zhaoxuya520/reverse-skill
72
46
ctf-sandbox-orchestrator Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable,…
zhaoxuya520/reverse-skill
72
47
competition-android-hooking Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, …
zhaoxuya520/reverse-skill
71
48
competition-bundle-sourcemap-recovery Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for source maps, build manifests, chunk …
zhaoxuya520/reverse-skill
71
49
competition-container-runtime Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for live container runtime analysis, mou…
zhaoxuya520/reverse-skill
71
50
competition-crypto-mobile Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for crypto, encoding, steganography, APK…
zhaoxuya520/reverse-skill
71
Page 1 · 88 total Next