Your AI Agent Doesn't Know Whether to Reach for jadx or Frida—This Router Fixes That
You've handed your AI agent an APK and asked it to figure out what's going on. It confidently starts running commands, but half of them are wrong for the task. Maybe it should've used jadx. Maybe apktool. Maybe Frida. The agent doesn't know, and you end up babysitting it through every step. That's the problem reverse-skill is trying to solve.
What It Does
reverse-skill is a cybersecurity skills router for AI agents. When your agent (Claude Code, Codex, Cursor, OpenCode, or another compatible client) encounters an APK, a binary, frontend JS encryption, a CTF challenge, or a pentesting target, this package routes it to the right methodology, checks what tools are available, and walks it through a repeatable workflow instead of letting it guess.
The flow looks like this: your task hits RULES.md, then gets passed through MASTER-ROUTING or master-route.ps1, which initializes a case with scope and network profile. From there, it picks the right scenario skill and invokes the appropriate tools, MCP servers, or scripts. The output is a timeline, evidence-to-finding-to-path chain, and a report with a field journal. The whole thing is client-neutral, runs on Windows and Ubuntu, and is validated by cross-platform CI.
Under the hood, there are 44 routing rules (R0–R45), 175 regression benchmark cases, and 45 tracked skill modules. The routing core is driven by a single structured configuration and kept separate from optional components.
Why It's Cool
-
It solves a real coordination problem. AI agents are good at executing commands but bad at knowing which commands to execute for a given reverse-engineering task. This router gives them a decision tree instead of a blank slate.
-
The routing is structured, not vibes-based. With 44 explicit rules and 175 regression cases, the routing logic is testable and reproducible. That matters when you're dealing with security work where "close enough" isn't good enough.
-
It's client-neutral. You're not locked into Claude Code or Cursor or anything else. If your agent can read instructions, it can use this router.
-
The workflow is auditable. The evidence-to-finding-to-path chain and field journal mean you can trace how the agent arrived at a conclusion. That's useful for CTFs, pentesting reports, and just understanding what your agent actually did.
-
It separates routing from execution. The core routing config is kept apart from optional tools and scripts, which means you can update one without breaking the other.
-
There's an AI-specific bootstrap. The README explicitly tells AI agents to jump to
README_AI.mdand follow instructions strictly. That's a small but telling detail—the project is designed with agent consumption in mind, not just human reading.
How to Try It
Getting started depends on your setup, but the README points to a few key entry points:
-
Clone the repo:
git clone https://github.com/zhaoxuya520/reverse-skill -
If you're an AI agent, the README says to jump straight to
README_AI.mdand follow the instructions strictly. That file is your bootstrap. -
If you're a human setting this up for your agent, start with
RULES.mdand then look atskills/MASTER-ROUTING.mdfor the fast route, orskills/routing.mdfor the full routing logic. Theskills/ops/directory contains ops contracts. -
Check the tutorial at the project website if you want a guided walkthrough: https://reverse.apivix.com/docs/
-
Review the current status table in the README to understand what's covered: 44 routing rules, 175 regression cases, 45 skill modules, Windows and Ubuntu CI.
The repo is at https://github.com/zhaoxuya520/reverse-skill.
Final Thoughts
reverse-skill is a niche tool for a specific audience: people using AI agents for reverse engineering, CTFs, or pentesting who are tired of the agent fumbling through tool selection. It's not going to teach you how to reverse engineer anything—it assumes you (or your agent) already have the tools and just need help picking the right one at the right time. If that's your workflow, the structured routing and regression benchmarks are a solid foundation. If you're not already using an AI agent for this kind of work, this won't be the thing that converts you. But for those who are, it's a practical piece of infrastructure that addresses a problem most people just work around manually.
Follow @githubprojects for more developer tools and open source projects.