Video & Animation

identity-federation

github.com

Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

js-reverse

github.com

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

mobile-reverse

github.com

Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

llm-security

github.com

Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

protocol-reverse

github.com

Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

go-rust-reverse

github.com

Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

threat-hunting

github.com

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

radio-sdr

github.com

Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

threat-intelligence

github.com

Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

abusing-dpapi-for-credential-access

github.com

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

ctf-sandbox

github.com

Thin PRIMARY for CTF / AWD / 靶场 multi-type orchestration. Hands off to the sidecar CTF-Sandbox-Orchestrator. Use when the user says CTF, AWD, 靶场, or 比赛题 and no more specific pwn/APK/IDA route already won.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

database-security

github.com

Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

binary-diff

github.com

|

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

case-review

github.com

Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

cloud-k8s

github.com

Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

browser-extension-reverse

github.com

Use for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

binary-ninja-reverse

github.com

Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

browser-automation

github.com

|

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

firmware-pentest

github.com

|

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

apk-reverse

github.com

在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

api-security

github.com

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

attack-chain

github.com

Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→

mpv-player/mpv

github.com

🎥 Command line media player

$ npx skills add mpv-player/mpv
Skill anzeigen→

ghidra-reverse

github.com

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

$ npx skills add zhaoxuya520/reverse-skill
Skill anzeigen→