DSH Plugins Marketplace

DSH Plugins

Plugins

/

reverse-workbench-skill

A

reverse-workbench-skill

Discovered★ 4

reverse-workbench-skill

reverse-workbench-skill

Pi-oriented Cybersecurity Skills Router · 逆向技能路由包

Navigate the dark waters, sail against the stream.

release stars forks issues license changelog


About · Getting Started · Usage · Fast route · Routing · Ops contracts · AI Bootstrap · Contributing

🌐 中文


About

If you are an AI Agent, jump to README_AI.md and follow the instructions strictly.

Agent-harness users: this is a standard Agent Skills bundle. Install it once with scripts/install-skill.ps1 (Windows) or scripts/install-skill.sh (Unix) — the shared location ~/.agents/skills/ is picked up by pi, Codex CLI, and DSH; --claude also mirrors it for Claude Code. See 跨 Agent 支持.

This repository is an independently maintained, cross-agent reverse-engineering and security-analysis skill router — archive triage, reproducible Ghidra-headless exports, HTTP/service fingerprinting, and a domain skill matrix. It no longer tracks any upstream codebase and follows its own release line.

When an AI agent (Claude Code, Codex CLI, Cursor, etc.) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks available tools, and executes a repeatable workflow instead of guessing commands.

User task
  → RULES.md
  → MASTER-ROUTING / master-route.ps1 (PRIMARY)
  → case-init / scope.md (auth + network_profile; no target ACT until ready)
  → Scenario skill → tools / MCP / scripts
  → timeline + Evidence→Finding→Path → report + field-journal

Why this exists:

  • AI agents don't know whether to use jadx, apktool, Frida, IDA, or BurpSuite for a given task
  • APK, ELF, JS, PCAP, and CTF tasks each need different playbooks
  • Tools, MCP servers, and scripts are scattered across machines
  • The same mistakes get repeated because experience isn't reused

PRIMARY ladder: skills/MASTER-ROUTING.md · Full matrix: skills/routing.md · Ops: skills/ops/

(back to top)

Built With


IDA Pro · radare2 · Ghidra

(back to top)

Getting Started

Prerequisites

  • Java / JDK — for jadx and apktool
  • Node.js 22.12+ — for JS toolchain and MCP servers
  • Python 3.x — for Frida and helper scripts
  • A code AI client — Claude Code, Codex CLI, Cursor, etc.

Installation

git clone https://github.com/Asaiuta/reverse-workbench-skill.git
cd reverse-workbench-skill

Install the skill bundle for your agent harness(es):

HostInstallInvocation
pipowershell -File scripts/install-skill.ps1 ^(Win) / bash scripts/install-skill.sh (Unix)/skill:reverse-workbench-skill(/reload 后生效)
Codex CLI同上(默认位置 $HOME/.agents/skills 即 Codex USER scope)/skills 或 $reverse-workbench-skill
DSH同上(DSH user-agents scope,rank 500);项目级可用 --project <dir>(<dir>/.agents/skills,rank 200)web 端 skill 目录 / skill 工具
Claude Code追加 -Claude(Win) / --claude(Unix) 参数/skills(重启后生效)
其他 Agent Skills 宿主将 SKILL.md 所在目录复制到对应 skills 目录依宿主而定

单机只需安装一次:pi / Codex CLI / DSH 共用 ~/.agents/skills/reverse-workbench-skill/。技能保持仅显式调用(disable-model-invocation: true,Codex 侧为 allow_implicit_invocation: false)。

Cross-Agent Support

宿主发现位置优先级/特性
pi~/.agents/skills/、~/.pi/agent/skills//skill:<name> 命令,disable-model-invocation
Codex CLI$CWD/.agents/skills(REPO) → $HOME/.agents/skills(USER) → /etc/codex/skills(ADMIN)支持 symlink;自动检测变更
DSH<root>/.dsh/skills(100) → <root>/.agents/skills(200) → $DSH_HOME/skills(400) → ~/.agents/skills(500)ctx.skills 注册表 + skill 工具;disable-model-invocation
Claude Code~/.claude/skills/、项目 .claude/skills//skills 选择器

Then refresh the tool index per platform:

PlatformCommand
Windowspowershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/refresh-tool-index.ps1
Linux / macOSbash skills/scripts/refresh-tool-index.sh
Kali Linuxbash kali/scripts/refresh-tool-index.sh

Check skills/tool-index.md to see detected tools.

Platform-specific docs:

(back to top)

Usage

Supported scenarios

ScenarioEntry
APK / Android analysisskills/apk-reverse/
iOS / mobileskills/mobile-reverse/
Unknown file / archive / evidence bundleskills/archive-file-triage/
Reproducible Ghidra batch exportsskills/ghidra-headless/
Ghidra reverse engineeringskills/ghidra-reverse/
HTTP liveness / TLS / service fingerprintingskills/pentest-tools/observer-ward/
Binary reverse (exe/dll/so/elf)skills/ida-reverse/ / skills/radare2/
.NET / C#skills/dotnet-reverse/
Frontend JS / encrypted paramsskills/js-reverse/
DSL VM / custom JS opcode VMskills/reverse-engineering/dsl-vm-reverse/
HTTP capture / request replayanything-analyzer + js-reverse/
Malware / YARAskills/malware-analysis/
Penetration testing / scanningskills/pentest-tools/
Attack chain / red-team orchestrationskills/attack-chain/
CTF competitionCTF-Sandbox-Orchestrator/ (40+ sub-skills)
Firmware / IoTskills/firmware-pentest/
Patch diff / N-dayskills/patch-diff-exploit/
Cross-version symbol migration / DWARF recoveryskills/binary-diff/
Linux/ELF DWARF symbol recoveryskills/binary-diff/references/dwarf-symbol-recovery.md
Pwn / exploit developmentskills/pwn-chain/
Binary-mitigation strategy matrix (checksec → approach)skills/pwn-chain/references/protection-bypass-matrix.md
EDR bypassskills/edr-bypass-re/
API / GraphQLskills/api-security/
Supply chain / SBOMskills/supply-chain-security/
LLM / AI securityskills/llm-security/
OLLVM deobfuscationskills/reverse-engineering/references/ollvm-deobfuscation.md
Diagrams / reportsskills/diagram-generator/ / skills/docs-generator/

Key files

FilePurpose
README_AI.mdAI agent bootstrap and configuration
RULES.mdGlobal routing rules (scope gate before ACT)
skills/MASTER-ROUTING.mdPRIMARY fast ladder
skills/routing.mdTask → skill routing matrix
skills/SKILL.mdMaster entry point
skills/tool-index.mdLocal tool status (auto-generated)
skills/scripts/master-route.ps1One-shot PRIMARY triage
skills/scripts/case-init.ps1Case dir: scope / timeline / workitems
skills/ops/Scope, Evidence chain, roles, timeline (skill-router form)

Repository layout

.
├── README.md / README_zh.md / README_AI.md
├── RULES.md / RULES_zh.md
├── skills/
│   ├── MASTER-ROUTING.md / SKILL.md / routing.md
│   ├── ops/                   # ops contracts
│   ├── scripts/               # master-route, case-init, bootstrap, verify
│   ├── field-journal/
│   ├── apk-reverse/ mobile-reverse/ js-reverse/ dotnet-reverse/
│   ├── ida-reverse/ radare2/ reverse-engineering/ malware-analysis/
│   ├── pentest-tools/ attack-chain/ pwn-chain/ firmware-pentest/
│   ├── api-security/ supply-chain-security/ llm-security/
│   └── ...
├── CTF-Sandbox-Orchestrator/
├── docs/
├── kali/                      # see kali/README-kali.md
└── work/                      # local cases (gitignored)

(back to top)

Contributing

Contributions are welcome! Fork the repo, create a feature branch, and open a PR.

  1. Fork the Project
  2. git checkout -b feature/AmazingFeature
  3. git commit -m 'Add some AmazingFeature'
  4. git push origin feature/AmazingFeature
  5. Open a Pull Request

License

reverse-workbench-skill is licensed under the MIT License (see LICENSE). The methodology originated from the reverse-skill skill router; per MIT terms its copyright notice is retained in the LICENSE file.

Bundled components and third-party dependencies:

  • CTF-Sandbox-Orchestrator/ is distributed under GNU GPLv3.
  • Pentest Swarm AI: Original project is AGPL-3.0. This repo only invokes it via CLI or MCP and does not include its source code
  • Other tools (jadx, frida, nmap, burpsuite-mcp, etc.) are subject to their respective official licenses

(back to top)

Acknowledgments

Thanks to all open-source tool authors. This project integrates tools across reverse engineering, penetration testing, CTF, and security analysis — every tool is the fruit of community effort.

Special thanks to the OLLVM deobfuscation ecosystem and everyone who helped validate samples, report issues, and improve the project.

(back to top)

Comments

Loading…