# zhaoxuya520/reverse-skill

Source: [GitHub](https://github.com/zhaoxuya520/reverse-skill)  
Feed7 permalink: https://feed7.dev/p/reverse-skill-1e4jlfw  
Published: Unknown  
Trust: Needs Review (needs_review)

## Why Included

A security skill router gives coding agents scoped, repeatable playbooks for reverse engineering and pentesting instead of ad hoc tool selection. Its case workflow also preserves evidence and findings.

## Source Summary

Reverse-skill routes agents across APK, binary, JavaScript, PCAP, CTF, and pentesting work. Its **MASTER-ROUTING** flow checks scope and authorization before action, inventories local tools, then selects a scenario playbook.

## Practical Implication

Use it as a reference for security-agent harnesses: make authorization a hard gate, detect capabilities before planning, and record a timeline linking **Evidence→Finding→Path**. The repository includes platform setup and workflows for tools such as jadx, Frida, IDA, and Burp Suite.

## Agent-Ready Context

Reverse-skill routes agents across APK, binary, JavaScript, PCAP, CTF, and pentesting work. Its **MASTER-ROUTING** flow checks scope and authorization before action, inventories local tools, then selects a scenario playbook.

Use it as a reference for security-agent harnesses: make authorization a hard gate, detect capabilities before planning, and record a timeline linking **Evidence→Finding→Path**. The repository includes platform setup and workflows for tools such as jadx, Frida, IDA, and Burp Suite.

This is a broad router pack, not evidence that its workflows produce correct findings. Tool availability, target authorization, sandboxing, and the licenses of included or invoked components still need independent review.

## Connected Context

Feed7 judgment across 318 accumulated Signals:

This turns broad security workflows into a routed skill pack with authorization, capability discovery, and evidence traceability, reinforcing prior calls to govern skills and verify outcomes. It does not establish that the playbooks are accurate or safe, so selection, sandboxing, licensing review, and finding validation remain harness responsibilities rather than properties of the pack.

- [We Vetted 2000 AI Skills Before They Reached Developers — Lucas Palma, Nubank](https://feed7.dev/p/we-vetted-2000-ai-skills-before-they-reached-developers-lucas-palma-nuba-0k4ehkz) — The router’s third-party skills and invoked tools are the kind of supply-chain surface this candidate says should be scanned and gated before distribution or use.
- [In Code They Act, In Proof We Trust — Erik Meijer, Leibniz Labs](https://feed7.dev/p/in-code-they-act-in-proof-we-trust-erik-meijer-leibniz-labs-1lyno2y) — Its authorization gate and Evidence→Finding→Path record provide inspectable controls, while the proposed proof harness goes further by requiring machine-checkable safety before side effects.
- [Skills are new features: Building Skill-Centric Harness — Yogendra Miraje, FactSet](https://feed7.dev/p/skills-are-new-features-building-skill-centric-harness-yogendra-miraje-f-0lp4c7o) — The pack supplies routing descriptions and executable workflows, making the candidate’s requirements for evaluation, access control, ownership, and sandboxing direct implementation concerns.
- [How we set up our cloud agent environment](https://feed7.dev/p/cloud-agent-environment-1c839pq) — Inventorying local tools before selecting a playbook reinforces the candidate’s point that skill instructions depend on a discoverable, reliable execution environment.

## Context Map

- Layer: agent
- Domains: security, coding
- Topics: skills, harness-engineering, tool-use

## Uncertainty

- This is a broad router pack, not evidence that its workflows produce correct findings. Tool availability, target authorization, sandboxing, and the licenses of included or invoked components still need independent review.

## Agent Instruction

Use this item as source-backed context. Do not invent claims beyond the linked source. If this item conflicts with another source, call out the conflict.
