Tool

reverse-skill

reverse-skill is an open-source AI skill router for authorized reverse engineering, security research, CTF, and penetration-testing workflows.

Quick verdict: reverse-skill is an open-source AI skill router for authorized reverse engineering, security research, CTF, and penetration-testing workflows. It gives compatible coding agents a structured way to choose a playbook, check local tools, record scope, and preserve evidence instead of improvising commands. The idea is unusually practical for experienced security teams, but this is not a scanner, model, desktop app, or safe one-click installer. You still need a capable AI client, a controlled lab, the right specialist tools, and explicit permission for every target.

What is reverse-skill?

reverse-skill is a client-neutral routing and methodology pack for AI coding agents such as Claude Code, Codex, Cursor, and OpenCode. When a task involves an APK, binary, encrypted frontend JavaScript, packet capture, malware sample, CTF challenge, or an authorized security target, the project routes the agent toward a scenario-specific skill and the relevant local tools.

The official workflow is more disciplined than “ask an agent to hack something.” A request passes through the global rules and PRIMARY router, then a case scope gate records authorization and network boundaries before active work. The chosen scenario skill can call scripts, MCP services, or external tools, while the case keeps a timeline and an Evidence → Finding → Path trail for reporting. The current README lists 41 routing rules, 163 regression cases, and 42 tracked core modules.

reverse-skill authorized task routing workflow from request and scope gate to evidence report
OSSNav contextual diagram based on the official reverse-skill README, showing the documented task-to-route, scope, scenario, evidence, and report flow.

Main features

  • Structured task routing: a central JSON configuration maps task hints to PRIMARY skills instead of scattering routing logic across prompts and scripts.
  • Broad security coverage: modules cover Android and iOS analysis, native binaries, .NET, JavaScript, malware, firmware, APIs, cloud, supply chain, LLM security, digital forensics, CTF work, and more.
  • Regression-tested decisions: the repository documents 163 bilingual routing cases so changes can be checked against expected skill choices.
  • Hard scope gate: the case contract records authorization, in-scope assets, excluded activity, a network profile, and signoff before target interaction.
  • Local tool inventory: PowerShell and Bash refresh commands detect available utilities and write a machine-specific tool index.
  • Evidence-oriented case files: timeline, work items, findings, paths, reports, and a field journal make handoff more repeatable.
  • Client-neutral core: the routing files and tests are not tied to one vendor, although every host agent needs its own instruction or adapter setup.
  • Cross-platform guidance: Windows is the primary path, Kali has a specialized layer, and Ubuntu/Debian plus macOS have generic Bash documentation.

Product characteristics

The most important characteristic is that reverse-skill organizes work; it does not replace the tools that perform it. Java and a JDK may be needed for jadx or apktool, Node.js 22.12+ supports JavaScript tooling and MCP servers, and Python is used by Frida and helper scripts. IDA Pro, Burp Suite, Nmap, Ghidra, radare2, and other utilities keep their own installation, licensing, and operational requirements.

The architecture has three useful layers. A compatible agent client loads the project instructions. The routing core classifies the task and selects a methodology. Local scripts, MCP bridges, and security utilities then provide execution capabilities. That separation makes the knowledge portable, but it also means results depend on the host model, installed tools, environment permissions, and the operator’s judgment.

reverse-skill client routing core and local security tool execution layers
OSSNav contextual diagram based on the official reverse-skill README and platform guide, showing the client, routing-core, and local-execution layers.

Version choice deserves a quick check. The latest tagged release is v1.0.1 from August 8, 2026, while the main branch already contains additional commits. The tag is easier to pin and review; main has newer fixes and routing changes but is an unreleased snapshot. The repository also includes bootstrap logic, so read scripts and manifests before allowing downloads or machine-level changes. A disposable lab is the sensible first home.

How to install and get started

Start with a harmless local sample or a public CTF challenge, not a live third-party system. Read the main README, RULES.md, your platform guide, and the package security audit. Then clone either the reviewed release tag or the current branch into an isolated workspace:

git clone --branch v1.0.1 https://github.com/zhaoxuya520/reverse-skill.git
cd reverse-skill

Next, refresh the local tool index. On Windows the documented command is powershell -File skills/scripts/refresh-tool-index.ps1. Linux and macOS use bash skills/scripts/refresh-tool-index.sh, while Kali uses its dedicated script under kali/scripts/. Inspect the generated skills/tool-index.md and JSON file before deciding which missing utilities are actually necessary.

Route the sample task with the PRIMARY router, create a case with case-init, and review scope.md. Active work must remain blocked unless authorization is granted, assets and allowed activities are listed, the network profile is chosen, exclusions are reviewed, and ready_for_act is true. Only then should the agent open the selected scenario skill. Keep credentials out of the repository and verify every command before execution.

Best use cases

reverse-skill fits security practitioners who already understand authorization and want a shared operating method for AI-assisted work. Useful examples include triaging a mobile app in a lab, selecting a binary-analysis path, reviewing a packet capture, organizing a malware-analysis case, preparing an authorized API assessment, navigating a CTF, or standardizing how a team records evidence and hands work between specialists.

It is also a strong reference for people designing their own agent skills because the repository exposes routing rules, regression cases, capability manifests, scope contracts, and cross-platform adapters in public. It is a weak fit for nontechnical users, general-purpose coding help, anyone expecting a polished GUI, or teams that need vendor-backed guarantees. It is completely inappropriate for scanning or exploiting systems without explicit permission.

Pricing and license

The main reverse-skill project is free and open source under the MIT License. That license does not make every bundled or connected component MIT. The included CTF-Sandbox-Orchestrator directory is GPL-3.0, Pentest Swarm AI is an external AGPL-3.0 project, and tools such as Frida, jadx, Nmap, Burp Suite, and IDA Pro retain their respective licenses.

There is no reverse-skill subscription, but the working stack may not be free. Your AI coding client or model provider can require a paid plan or API usage, commercial analysis tools have separate licenses, and safe labs need compute, storage, network isolation, and maintenance time. Review the exact components you plan to use before treating “MIT” as a budget or compliance answer for the whole workflow.

Practical evaluation

The project solves a real problem: an AI agent can sound confident while choosing the wrong security tool, skipping authorization checks, or producing evidence that cannot be audited later. A single routing source, regression suite, case contract, and evidence chain are sensible controls. The client-neutral design is another plus because the workflow is not locked to one agent vendor.

The trade-off is complexity and trust. This is a large, fast-moving skill pack with scripts that can inspect tools, bootstrap dependencies, and connect external services. It still relies on human review, and some modules cover advanced offensive techniques that demand strict legal and operational boundaries. For an experienced security team willing to review the code and work inside an isolated, authorized environment, reverse-skill is a thoughtful foundation. For casual experimentation, begin with the documentation and routing tests rather than the full toolchain.