Reverse Skill
by @zhaoxuya520 · plugin · 42 skills
Reverse Skill from zhaoxuya520/reverse-skill.
Install the whole plugin (CLI)
npx skillmds add zhaoxuya520/reverse-skill-router
npx skillmds add zhaoxuya520/ot-ics
npx skillmds add zhaoxuya520/radare2
npx skillmds add zhaoxuya520/cloud-k8s
npx skillmds add zhaoxuya520/pwn-chain
npx skillmds add zhaoxuya520/radio-sdr
npx skillmds add zhaoxuya520/code-audit
npx skillmds add zhaoxuya520/js-reverse
npx skillmds add zhaoxuya520/windows-ad
npx skillmds add zhaoxuya520/apk-reverse
npx skillmds add zhaoxuya520/binary-diff
npx skillmds add zhaoxuya520/ida-reverse
npx skillmds add zhaoxuya520/api-security
npx skillmds add zhaoxuya520/attack-chain
npx skillmds add zhaoxuya520/llm-security
npx skillmds add zhaoxuya520/thick-client
npx skillmds add zhaoxuya520/edr-bypass-re
npx skillmds add zhaoxuya520/macos-reverse
npx skillmds add zhaoxuya520/pentest-tools
npx skillmds add zhaoxuya520/wifi-wireless
npx skillmds add zhaoxuya520/docs-generator
npx skillmds add zhaoxuya520/dotnet-reverse
npx skillmds add zhaoxuya520/email-security
npx skillmds add zhaoxuya520/ghidra-reverse
npx skillmds add zhaoxuya520/mobile-reverse
npx skillmds add zhaoxuya520/threat-hunting
npx skillmds add zhaoxuya520/go-rust-reverse
npx skillmds add zhaoxuya520/firmware-pentest
npx skillmds add zhaoxuya520/malware-analysis
npx skillmds add zhaoxuya520/protocol-reverse
npx skillmds add zhaoxuya520/database-security
npx skillmds add zhaoxuya520/diagram-generator
npx skillmds add zhaoxuya520/digital-forensics
npx skillmds add zhaoxuya520/hardware-security
npx skillmds add zhaoxuya520/browser-automation
npx skillmds add zhaoxuya520/patch-diff-exploit
npx skillmds add zhaoxuya520/identity-federation
npx skillmds add zhaoxuya520/reverse-engineering
npx skillmds add zhaoxuya520/supply-chain-security
npx skillmds add zhaoxuya520/src-hunter
npx skillmds add zhaoxuya520/browser-extension-reverse
npx skillmds add zhaoxuya520/dsl-vm-reverseSkills in this plugin
- ▌ reverse-skill-router · zhaoxuya520 bundleRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
- ▌ ot-ics · zhaoxuya520 bundleAuthorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
- ▌ radare2 · zhaoxuya520 bundleProvides a command-line workflow for binary analysis with radare2, covering reconnaissance, disassembly, function analysis, string and import inspection, patching, binary diffing, and r2pipe scripting across PE, ELF, Mach-O, DEX, and WASM formats.
- ▌ cloud-k8s · zhaoxuya520 bundleAuthorized security assessment for cloud, container, and Kubernetes environments covering metadata SSRF, IAM misconfigurations, container escape paths, and cluster RBAC review.
- ▌ pwn-chain · zhaoxuya520 bundleEngineers reliable exploits from known vulnerabilities in binaries, covering stack overflows, heap exploitation, and kernel pwn with remote stabilization techniques.
- ▌ radio-sdr · zhaoxuya520 bundleGuides authorized RF/SDR security research for signal identification, demodulation analysis, and replay feasibility studies in shielded lab environments.
- ▌ code-audit · zhaoxuya520 bundlePerforms authorized source-code security reviews using SAST tools like Semgrep and CodeQL, with manual verification of findings and fix recommendations.
- ▌ js-reverse · zhaoxuya520 bundleGuides front-end JavaScript reverse engineering through a structured observe-capture-rebuild workflow using js-reverse MCP tools and optional jshookmcp for browser automation, CDP debugging, and runtime hooking.
- ▌ windows-ad · zhaoxuya520 bundleGuides authorized Active Directory security research covering Kerberos attacks, AD CS vulnerabilities, BloodHound path analysis, NTLM relay, and domain privilege escalation techniques.
- ▌ apk-reverse · zhaoxuya520 bundleProvides a structured CLI workflow for Android APK reverse engineering, covering decompilation with jadx and apktool, smali modification, repackaging, signing, and Frida dynamic hooking, with optional native .so analysis via IDA or radare2.
- ▌ binary-diff · zhaoxuya520 bundleMigrates symbols and reverse-engineering results from an older binary version to a newer one using LLM-based structured diffing of disassembly and pseudocode, enabling rapid offset and function-name mapping when PDBs are missing.
- ▌ ida-reverse · zhaoxuya520 bundleProvides a complete workflow for IDA Pro reverse engineering of binaries (PE, ELF, APK, DLL, SO, firmware) using bundled PowerShell scripts to manage the MCP server and open files, then leverages 72 MCP tools for survey, decompilation, cross-references, data-flow tracing, patching, and reporting.
- ▌ api-security · zhaoxuya520 bundleAuthorized security assessment of REST, GraphQL, WebSocket, and SOAP APIs covering discovery, authentication, authorization, rate-limiting, and CI/CD integration.
- ▌ attack-chain · zhaoxuya520 bundleOrchestrates multi-stage attack-path planning and execution across reconnaissance, initial access, privilege escalation, lateral movement, and impact assessment for authorized penetration testing.
- ▌ llm-security · zhaoxuya520 bundleConduct authorized security assessments of LLM applications and AI agents, covering prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.
- ▌ thick-client · zhaoxuya520 bundleAuthorized security testing framework for desktop thick clients covering local storage, IPC, update channels, traffic interception, and client-side trust boundaries.
- ▌ edr-bypass-re · zhaoxuya520 bundleReverse-engineers EDR, Defender, and AV hook tables, ETW providers, and AMSI implementations to build targeted bypasses including unhooking, indirect syscalls, ETW patching, and call stack spoofing for authorized red team operations.
- ▌ macos-reverse · zhaoxuya520 bundleGuides authorized macOS and Mach-O reverse engineering covering codesign analysis, Objective-C/Swift symbol recovery, endpoint security surfaces, and Apple platform malware analysis.
- ▌ pentest-tools · zhaoxuya520 bundleProvides a comprehensive penetration testing toolchain with 20+ security tools (Nmap, Nuclei, SQLMap, FFUF, Hashcat, etc.) exposed via MCP servers for authorized vulnerability scanning, exploitation, and reporting.
- ▌ wifi-wireless · zhaoxuya520 bundleGuides authorized Wi-Fi security assessments including handshake capture, PMKID collection, rogue AP detection, and offline password policy evaluation using aircrack-ng, hashcat, and Wireshark.
- ▌ docs-generator · zhaoxuya520 bundleGenerates task-oriented technical documentation with progressive disclosure for READMEs, API docs, architecture docs, and security reports after reverse engineering, penetration testing, or CTF tasks.
- ▌ dotnet-reverse · zhaoxuya520 bundleProvides a structured workflow for reverse engineering .NET and C# binaries, including deobfuscation with de4dot, static analysis via dnSpyEx IL view, dynamic debugging, and reliable IL patching for red-team tools and malware.
- ▌ email-security · zhaoxuya520 bundleAnalyzes email security including phishing dissection, SPF/DKIM/DMARC authentication checks, BEC fraud patterns, and OAuth token abuse research for authorized reviews.
- ▌ ghidra-reverse · zhaoxuya520 bundlePerforms free, open-source reverse engineering with Ghidra using headless or GUI modes, including decompilation, cross-references, and optional MCP workflows when IDA is unavailable.
- ▌ mobile-reverse · zhaoxuya520 bundleProvides a structured methodology for authorized Android and iOS reverse engineering, covering static analysis, dynamic instrumentation with Frida and Objection, SSL pinning bypass, root/jailbreak detection evasion, and cryptographic key extraction.
- ▌ threat-hunting · zhaoxuya520 bundleGuides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
- ▌ go-rust-reverse · zhaoxuya520 bundleReverse engineers stripped Go and Rust binaries by recovering runtime metadata, symbols, panic strings, and idiomatic decompilation patterns.
- ▌ firmware-pentest · zhaoxuya520 bundleEnd-to-end firmware and IoT penetration testing pipeline following OWASP FSTM methodology. Extracts, emulates, and exploits router, camera, and smart-home firmware using binwalk, EMBA, Firmadyne, and AFL++.
- ▌ malware-analysis · zhaoxuya520 bundleAnalyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
- ▌ protocol-reverse · zhaoxuya520 bundleAuthorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery with structured workflow and tooling.
- ▌ database-security · zhaoxuya520 bundlePerforms authorized database security assessments across PostgreSQL, MySQL, MSSQL, MongoDB, and Redis, checking exposure, authentication, authorization, dangerous configurations, and exploit paths.
- ▌ diagram-generator · zhaoxuya520 bundleGenerates editable diagram source code (Mermaid, Graphviz DOT, PlantUML, SVG) from natural language, code, schemas, or notes for flowcharts, sequence diagrams, ER diagrams, architecture diagrams, and more. Renders to PNG/SVG/PDF on request via a local Python script.
- ▌ digital-forensics · zhaoxuya520 bundleGuides authorized digital forensics and incident response workflows including memory dump analysis, disk timeline creation, PCAP investigation, and artifact triage with evidence preservation.
- ▌ hardware-security · zhaoxuya520 bundleGuides authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot assessment, and offline firmware extraction support.
- ▌ browser-automation · zhaoxuya520 bundleUnified automation entry point covering browser automation with Playwright and Windows desktop app automation with OpenReverse for GUI interaction, network capture, and reverse engineering workflows.
- ▌ patch-diff-exploit · zhaoxuya520 bundleAnalyzes vendor security patches via binary diffing to reverse-engineer vulnerabilities, write proof-of-concept exploits, and weaponize N-day exploits against unpatched systems.
- ▌ identity-federation · zhaoxuya520 bundleAuthorized assessment of federated identity systems covering SAML, OIDC, and OAuth2 flows, SSO misconfigurations, and token confusion issues.
- ▌ reverse-engineering · zhaoxuya520 bundleProvides structured reverse engineering techniques for analyzing compiled, obfuscated, packed, or virtualized targets including binaries, APKs, WASM, firmware, and custom VMs using static and dynamic analysis workflows.
- ▌ supply-chain-security · zhaoxuya520 bundleAssess software supply chain security by generating SBOMs, scanning dependencies, auditing CI/CD pipelines, analyzing container images, and verifying vulnerability reachability.
- ▌ src-hunter · zhaoxuya520 bundleProvides a structured 5-phase workflow for bug bounty and SRC vulnerability hunting, including 19 attack-type playbooks, 305 structured payloads, 263 WAF bypass variants, and 2,887 real HackerOne case studies.
- ▌ browser-extension-reverse · zhaoxuya520 bundleGuides authorized reverse engineering of Chrome and Firefox browser extensions, covering manifest analysis, background workers, and credential or traffic logic recovery.
- ▌ dsl-vm-reverse · zhaoxuya520Reverse-engineers custom JavaScript-based WASM virtual machines and risk-control engines by identifying DSL VM patterns, extracting opcodes, analyzing constant tables, and tracing exported functions through static analysis and runtime injection.