Video & Animation
identity-federation
Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
$ npx skills add zhaoxuya520/reverse-skilljs-reverse
在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。
$ npx skills add zhaoxuya520/reverse-skillmobile-reverse
Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
$ npx skills add zhaoxuya520/reverse-skillllm-security
Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.
$ npx skills add zhaoxuya520/reverse-skillprotocol-reverse
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
$ npx skills add zhaoxuya520/reverse-skillgo-rust-reverse
Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
$ npx skills add zhaoxuya520/reverse-skillthreat-hunting
Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
$ npx skills add zhaoxuya520/reverse-skillradio-sdr
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
$ npx skills add zhaoxuya520/reverse-skillthreat-intelligence
Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.
$ npx skills add zhaoxuya520/reverse-skillabusing-dpapi-for-credential-access
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsctf-sandbox
Thin PRIMARY for CTF / AWD / 靶场 multi-type orchestration. Hands off to the sidecar CTF-Sandbox-Orchestrator. Use when the user says CTF, AWD, 靶场, or 比赛题 and no more specific pwn/APK/IDA route already won.
$ npx skills add zhaoxuya520/reverse-skilldatabase-security
Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
$ npx skills add zhaoxuya520/reverse-skillbinary-diff
|
$ npx skills add zhaoxuya520/reverse-skillcase-review
Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
$ npx skills add zhaoxuya520/reverse-skillcloud-k8s
Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
$ npx skills add zhaoxuya520/reverse-skillbrowser-extension-reverse
Use for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
$ npx skills add zhaoxuya520/reverse-skillbinary-ninja-reverse
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
$ npx skills add zhaoxuya520/reverse-skillbrowser-automation
|
$ npx skills add zhaoxuya520/reverse-skillfirmware-pentest
|
$ npx skills add zhaoxuya520/reverse-skillapk-reverse
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
$ npx skills add zhaoxuya520/reverse-skillapi-security
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
$ npx skills add zhaoxuya520/reverse-skillattack-chain
Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
$ npx skills add zhaoxuya520/reverse-skillmpv-player/mpv
🎥 Command line media player
$ npx skills add mpv-player/mpvghidra-reverse
Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
$ npx skills add zhaoxuya520/reverse-skill