AI automatic routing · On-demand bootstrapping tool chain · Automatic evolution experience library
Real-time sampling from GitHub stargazers interface · Real stargazer history
Four typical problems when AI programming assistants face reverse engineering and penetration tasks
Facing APK, ELF, JS, and PCAP, Agent does not know how to choose tools and can only blindly guess commands.
jadx ? Frida ? IDA ? BurpSuite ?APK, binary, front-end JS, CTF, each type of task requires a completely different methodology and operation manual.
Playbooks scattered everywhere.Tools, MCP services and scripts are scattered on different machines, and the environment migration will be invalid and cannot be reproduced.
Works on my machine. Only mine.The same pitfalls are trampled over and over again, each mission starts from scratch, and experience is lost as the session ends.
Same mistakes, again and again.41 priority routing rules (R0–R40) form the client-independent routing ladder. When the Agent receives a task, it is first routed to the correct methodology and special skills, and then executed - routing first, then execution.
Tool paths, MCP services, and script entries are concentrated in the tool-index index. When missing, the ability to declare in the manifest will automatically guide the installation, and environment migration will no longer cause disconnection.
field-journal will continue to accumulate practical experience after desensitization, and the evidence chain can be traced. No more pitfalls for similar problems. The more you use it, the stronger it becomes.
Route first, act later·Authorize first·Leave evidence traces
Natural language description target: an APK, an encrypted JS, a CTF, and an authorized penetration
Global routing rules go first, authorization threshold master switch before any ACT action
master-route.ps1 One-click routing, output PRIMARY path + one sentence basis, misses will fall into R0
Authorization confirmation + network_profile network configuration, not ready to prohibit any operation on the target (exit 2)
Enter apk-reverse / js-reverse / pwn-chain and other special modules, and read the corresponding SKILL.md manual
jadx · Frida · IDA · BurpSuite MCP · nmap, the tool path only recognizes tool-index.md
timeline + Evidence → Finding → Path, output the report and write it to the field-journal experience library
Priority ≠ Numbering order: semantics take precedence over tool name, if not hit, R0 will be used.
| priority | Trigger characteristics | PRIMARY path |
|---|---|---|
| R1 | APK / smali / jadx / apktool | apk-reverse/ |
| R3 | JS signature / front-end encryption / jshook / CDP | js-reverse/ |
| R5 | .NET / dnSpy / de4dot / ConfuserEx | dotnet-reverse/ |
| R6 | IDA / Decompile Deep Digging | ida-reverse/ |
| R9 | Malicious Samples/YARA/Sandbox ※ Prioritize R6 to avoid misrouting | malware-analysis/ |
| R10 | Attack Chains / Red Team / Lateral Movement | attack-chain/ |
| R11 | Nmap / Nuclei / SQLMap / Penetration Tools | pentest-tools/ |
| R14 | LLM/Prompt Injection/Agent Security | llm-security/ |
| R17 | pwn/ROP/stack exploit | pwn-chain/ |
| R23-R40 | Cloud and K8s / Windows AD / Forensics / Industrial Control / Wi-Fi / Hardware / Case Review… | Corresponding project directory |
| R0 Keep it safe | Universal Reverse / Anti-Debugging / OLLVM / Didn’t hit any strong keywords | reverse-engineering/ |
Some anti-virus software, EDR or browsers may identify security research scripts, tool names, Hook/debugging logic, scanning and decompilation commands, CTF/vulnerability verification fragments or on-demand installation scripts in the warehouse as "Trojan horses, backdoors, hacking tools". Such heuristic hits are not uncommon in security tool projects, butAn alarm cannot automatically equate to a false alarm。
Security products will detect based on high-risk keywords, process injection, dynamic hooks, network detection, script downloads, unpacking or vulnerability characteristics. Even if the file is used for authorization research, it may share local behavioral characteristics with malicious samples.
Please submit the security software name, detection label, relative file path, SHA-256, project version and download source. Don't upload files that contain company code, real samples, credentials, or other sensitive information.
Thanks to every partner who submitted code - the list is synchronized in real time from GitHub
UCloud AstraFlow provides one-click access to 200+ leading open-source models, including Kimi K3, DeepSeek V4/V3, Qwen 3, GLM 5.2, and HappyHorse—no model training required, ready to use out of the box.
Visit website ↗Atlas Cloud is an all-modal AI inference platform that provides 400+ selected image, video, audio, 3D and language models through a unified API, and provides model service support for reverse-skill's cross-platform route verification, document construction and public security workflow.
Visit website ↗Payment and permissions infrastructure for the smart economy. Kite Passport provides AI Agents with verifiable trust, budget scope, and full auditability.
Visit website ↗For inquiries, please send an email