Agent skill

Reverse Engineer

by boshu2 in boshu2/agentops

Tear down a competitor's repo or product into a feature inventory and adoption choices.

Apache-2.0Auto-check passedAI & LLM Engineering

Install Reverse Engineer

skills CLI
$ npx skills add boshu2/agentops --skill reverse-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boshu2/agentops reverse-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boshu2/agentops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/reverse-engineer .claude/skills/reverse-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reverse-engineer
GitHub stars
447
Used in
1 other repo
Token cost
~2.1k tokens
SKILL.md length
1,004 words
Files
44 (incl. scripts, references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Tear down a competitor's repo or product into a feature inventory and adoption choices.

  • Works in 2 steps: teardown → steal-map
  • : comparing us to another tool
  • SKILL.md covers ⚠️ Constraints — Hard…, Evidence rules, Phase 1 — teardown and Phase 2 — steal-map, plus 5 more sections
  • Calls python3 and bash; reaches github.com

What it does

Reverse Engineer is an agent skill from boshu2/agentops. Tear down a competitor's repo or product into a feature inventory and adoption choices. Use when: comparing us to another tool or asking what to steal.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 49 other files, including scripts and reference files (for example `agents/openai.yaml`, `fixtures/cc-sdd-v2.1.0/clone-metadata.json` and `fixtures/cc-sdd-v2.1.0/feature-registry.yaml`).

It sits in AI & LLM Engineering. The repository describes itself as: DevOps discipline for AI coding agents: shape the work, track it as a graph, and get each change judged by a context that didn't write it. The licence is Apache-2.0.

When your agent uses it

  • : comparing us to another tool
  • Asking what to steal

Example prompts

  • “/reverse-engineer”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. teardown
  2. steal-map

What it can do on your machine

Read from SKILL.md and the folder at commit 3bdbfed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reverse Engineer loads about 2.1k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 1,004 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from boshu2/agentops at commit 3bdbfed, republished under its Apache-2.0 licence (© boshu2). 1,004 words, ~2,138 tokens.

Download SKILL.mdSave it as .claude/skills/reverse-engineer/SKILL.md (or your agent's skills folder). This skill also uses 43 other files; get the full folder from GitHub.
name
reverse-engineer
description
Tear down a competitor's repo or product into a feature inventory and adoption choices. Use when: comparing us to another tool or asking what to steal.
practices
legacy-code-seams, ddd-bounded-context, adr
hexagonal_role
supporting
produces
.agents/scratch/reverse-engineer/*/
skill_api_version
1
user-invocable
true
context.window
fork
metadata.capabilities
reverse_engineer
metadata.effects
clone_upstream_repo, authorized_binary_execution, write_teardown_artifacts
metadata.canonical_status
canonical
metadata.disposition
keep_specialist

Reverse Engineer

Reverse-engineer an external system into two things: a teardown (the evidence: feature inventory, machine-checkable registry and specs, optionally a security audit) and a steal-map (the decision: what to adopt into our surfaces and what to leave behind). A decision row that must cite evidence can be re-checked by anyone; a decision made from impressions cannot be re-checked by its own author. Deciding from a competitor's README is the failure this skill exists to prevent.

⚠️ Constraints — Hard Guardrails (MANDATORY)

  • Only operate on code/binaries you own or have explicit written authorization to analyze — this matters because unauthorized teardown is the legal/IP line.
  • Do not provide steps to bypass protections/ToS or to extract proprietary source/system prompts.
  • Do not output reconstructed proprietary source or embedded prompts (index only; redact in reports) — to prevent reproducing protected IP.
  • Redact secrets/tokens/keys if encountered; run the secret-scan gate over outputs to prevent credential leakage.
  • Always separate docs say vs code proves vs hosted/control-plane.

Evidence rules

  • Tag every capability by its source. code: their source, binary or teardown registry shows it; cite the file:line or registry entry and record what the code actually does, which is often narrower than the claim. docs: a README, doc page or announcement says it; unverified. hosted: a service or control plane you cannot inspect.
  • No code access, no steal. With only docs, a README or a landing page, every row about their implementation is docs and unverified. It can be gap, park or reject, never steal.
  • Prove our side on the live tree. A have row cites our file. Every "missing" row carries the search that proved it (command and scope). Check what our current stack already offers before calling anything missing.
  • Independently checked, not self-report. Facts on how they implement a capability come from code, cross-checked by a fresh reader, never from one context's summary. Model family is optional metadata, not a trust requirement.
  • The steal is the pattern, not the platform. Their robustness is usually one idea (unification, a gate, a reconcile loop). Re-express it in our primitives; never vendor their runtime or storage engine.

Phase 1 — teardown

With an authorized clone or binary, the script clones (pinned), scans the CLI/config/artifact surface, writes the inventory, registry and specs, and validates the teardown:

bash
python3 skills/reverse-engineer/scripts/reverse_engineer.py <product> --mode=repo \
  --upstream-repo="https://github.com/org/repo.git" --upstream-ref=v1.0.0 \
  --output-dir=".agents/scratch/reverse-engineer/<product>/"

Binary mode requires --authorized; use the bundled demo fixture if you lack authorization for a real binary. Flags, output inventory, earlier output paths, fixtures and the self-test are in the invocation reference.

Without code access (only a README, docs site or landing page), skip the script: build the inventory and steal-map by hand with each row tagged docs or hosted, and say that no teardown validator ran. When the code is readable but the script cannot run on it, read the code directly and cite file:line for each code row; the validator gap still gets reported.

Phase 2 — steal-map

Map each capability onto our surfaces in .agents/scratch/reverse-engineer/<product>/steal-map.md. The script stops after validating Phase 1; it cannot truthfully decide whether our live tree has, lacks, or should adopt a capability. The caller authors the map from the registry plus a fresh read of our repository. A missing or malformed map is an incomplete skill result, not a script success relabelled as a decision.

Their capabilityOur surface todayVerdict
<feature> (code: <registry entry>, or docs, or hosted)<our file / skill / CLI>, or "none" plus the search that proved ithave / gap / steal / park / reject

Each row gets exactly one verdict:

  • have — our live tree already does it; cite the file and confirm it still holds.
  • steal — we lack it, code evidence shows how they do it, and it advances our core. Take the pattern, re-expressed in our primitives.
  • gap — we lack it and would want it if it holds up, but steal is not earned: their mechanism is docs or hosted only, or its value to our core is unshown. Name the evidence that would decide it.
  • park — real, but deliberately not ours to build now: substrate we delegate (for AgentOps, ADR-0009 keeps scheduling, supervision and queues external) or downstream of a bet we have not made. Name it, don't build it.
  • reject — conflicts with our doctrine (e.g. a completion edge with no check behind it, where we require checks and CI, plus one fresh judgment for a costly mistake).

When two seem to fit, reject beats park, and park beats steal or gap; between steal and gap, the evidence rules decide.

Show full SKILL.md (270 more words)Show less

Route one-way-door adoptions into planning

If adopting a steal is a one-way door (an architecture fork, a new bounded context, a storage or data migration), do not decide it here. Hand the steal-map to Plan. Dueling Idea Genies or Premortem may challenge the choice as advisory evidence. Plan alone shapes the selected option in the existing intent source; neither strategy grants readiness or continuation authority.

Validation

After authoring steal-map.md, validate the complete output with $output_dir, $security_audit, $sbom, and $upstream_ref_set (each numeric flag 0|1):

bash
bash skills/reverse-engineer/scripts/validate-output.sh \
  --output-dir "$output_dir" --phase complete \
  --security-audit "$security_audit" --sbom "$sbom" \
  --upstream-ref-set "$upstream_ref_set"

Give the validated steal-map.md to Plan for one-way-door candidates; ordinary have, park, and reject rows remain evidence-backed terminal decisions.

Quality Rubric

  • With an upstream ref, feature-registry.yaml and clone-metadata.json record the resolved commit.
  • Every row tags code/docs/hosted and cites teardown evidence and our matching surface, or "none" with the search that proved it.
  • Verdicts use the full set — have/gap/steal/park/reject — and no docs or hosted row is steal.
  • One-way-door adoptions are supplied to Plan, not decided here.
  • Secret-scan gate passed over all outputs; no proprietary source/prompts reproduced.
  • The complete-output validator exits 0 before handoff, or the report says it did not run (docs-only mode).
ProblemCauseSolution
Steal-map is all "steal"Skipped the park/reject rulesSubstrate we delegate is park; doctrine conflicts are reject — not everything novel is worth adopting.

See Also

  • plan — shape selected steals in the existing intent source
  • idea-genie — optional advisory challenge (duel mode)
  • premortem — optional advisory challenge of the exact plan
  • research — general exploration; this is its external-system specialization

Reference Documents

© boshu2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 43 other files (scripts, references) in skills/reverse-engineer of boshu2/agentops.

  • SKILL.md
  • .gitignore
  • agents/openai.yaml
  • fixtures/cc-sdd-v2.1.0/cli-surface-contracts.txt
  • fixtures/cc-sdd-v2.1.0/clone-metadata.json
  • fixtures/cc-sdd-v2.1.0/docs-features.txt
  • fixtures/cc-sdd-v2.1.0/feature-registry.yaml
  • references/invocation.md
  • references/reverse-engineer.feature
  • references/templates/postmortem.md.tmpl
  • references/templates/security/attack-surface.md.tmpl
  • references/templates/security/authn-authz.md.tmpl
  • references/templates/security/crypto-review.md.tmpl
  • references/templates/security/dataflow.md.tmpl
  • references/templates/security/findings.md.tmpl
  • … and 29 more

Open the folder on GitHubat commit 3bdbfed

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in boshu2/agentops, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Reverse Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reverse Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reverse Engineer this skillboshu2/agentops4471 repos~2.1kAutomated safety check: PassApache-2.0
Agent BuildershareAI-lab/learn-claude-code78k6 repos~1.2kAutomated safety check: PassMIT
Add Uint Supportpytorch/pytorch104k2 repos~2.3kAutomated safety check: PassCustom licence
Peft Fine TuningOrchestra-Research/AI-Research-SKILLs13k9 repos~3.1kAutomated safety check: PassMIT
Segment Anything Model GuideOrchestra-Research/AI-Research-SKILLs13k9 repos~3.3kAutomated safety check: PassMIT
1passwordtrpc-group/trpc-agent-go1.8k15 repos~656Automated safety check: PassApache-2.0

Similar skills

  • Agent Builder

    shareAI-lab/learn-claude-code

    Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.

    78k GitHub starsUsed in 6 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Add Uint Support

    pytorch/pytorch

    Add unsigned integer (uint) type support to PyTorch operators by updating ATDISPATCH macros.

    104k GitHub starsUsed in 2 repos~2.3k tokens
    AI & LLM EngineeringAuto-check passed
  • Peft Fine Tuning

    Orchestra-Research/AI-Research-SKILLs

    Parameter-efficient fine-tuning for LLMs using LoRA, QLoRA, and 25+ methods.

    13k GitHub starsUsed in 9 repos~3.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Segment Anything Model Guide

    Orchestra-Research/AI-Research-SKILLs

    Guide to using Meta's Segment Anything Model for zero-shot image segmentation with point, box or mask prompts, or automatic mask generation.

    13k GitHub starsUsed in 9 repos~3.3k tokens
    AI & LLM EngineeringAuto-check passed
  • 1password

    trpc-group/trpc-agent-go

    Set up and use 1Password CLI (op). An agent skill from trpc-group/trpc-agent-go.

    1.8k GitHub starsUsed in 15 repos~656 tokens
    AI & LLM EngineeringAuto-check passed
  • Chroma Vector Database

    Orchestra-Research/AI-Research-SKILLs

    Shows how to store documents and embeddings in Chroma, query them by similarity with metadata filters, and persist them to disk for RAG and semantic search projects.

    13k GitHub starsUsed in 8 repos~2.3k tokens
    AI & LLM EngineeringAuto-check passed

More from boshu2/agentops

All 31 skills in this repo
  • Agent Native

    boshu2/agentops

    Dispatch independent tasks to parallel workers or subagents without write collisions.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Council

    boshu2/agentops

    Compare independent opinions from several models or contexts without inflating agreement.

    447 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Craft Goal

    boshu2/agentops

    Draft or lint a bounded long-running goal prompt with a finish line and hard limits.

    447 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Doc

    boshu2/agentops

    Write or update READMEs, docs, repo instructions and handoff notes, checked against source.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Idea Genie

    boshu2/agentops

    Brainstorm evidence-backed options for what to build, or stress-test an idea.

    447 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Implement

    boshu2/agentops

    Change or repair code, config or services without weakening tests; report what ran and what did not.

    447 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Reverse Engineer

What does Reverse Engineer do?

Tear down a competitor's repo or product into a feature inventory and adoption choices. Reverse Engineer is an agent skill from boshu2/agentops. Tear down a competitor's repo or product into a feature inventory and adoption choices.

When should I use Reverse Engineer?

Reverse Engineer fits situations like: : comparing us to another tool; asking what to steal.

How do I install Reverse Engineer in Claude Code?

Run `npx skills add boshu2/agentops --skill reverse-engineer -a claude-code`. Or copy the skill folder (skills/reverse-engineer in boshu2/agentops) into .claude/skills/reverse-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Reverse Engineer in Codex?

Run `npx skills add boshu2/agentops --skill reverse-engineer -a codex`. Or copy the skill folder (skills/reverse-engineer in boshu2/agentops) into .agents/skills/reverse-engineer in your project. Codex loads it when a task matches its description.

Can I use Reverse Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boshu2/agentops --skill reverse-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reverse-engineer, .gemini/skills/reverse-engineer, .github/skills/reverse-engineer and .opencode/skills/reverse-engineer in your project.

What does Reverse Engineer need to run?

Going by SKILL.md and its folder, Reverse Engineer needs the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3.

Does Reverse Engineer access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Reverse Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Reverse Engineer use?

Reverse Engineer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reverse Engineer use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Reverse Engineer?

Skills that share tags, products or a category with Reverse Engineer: Agent Builder (shareAI-lab/learn-claude-code, 78k stars), Add Uint Support (pytorch/pytorch, 104k stars), Peft Fine Tuning (Orchestra-Research/AI-Research-SKILLs, 13k stars) and Segment Anything Model Guide (Orchestra-Research/AI-Research-SKILLs, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reverse Engineer?

boshu2 (a GitHub user) maintains it in boshu2/agentops, which has 447 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: boshu2/agentops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.