Brainstorming
xpinjection/test-driven-spring-boot
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior.
当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cha0upup/LeoAI develop-disguise --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/root/skills/platform/develop-disguise .claude/skills/develop-disguise && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .claude/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguiseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cha0upup/LeoAI develop-disguise --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .agents/skills && cp -r skills-src/root/skills/platform/develop-disguise .agents/skills/develop-disguise && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .agents/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cha0upup/LeoAI develop-disguise --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/root/skills/platform/develop-disguise .cursor/skills/develop-disguise && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .cursor/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cha0upup/LeoAI.git --path root/skills/platform/develop-disguise--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cha0upup/LeoAI develop-disguise --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/root/skills/platform/develop-disguise .gemini/skills/develop-disguise && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .gemini/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cha0upup/LeoAI develop-disguiseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .github/skills && cp -r skills-src/root/skills/platform/develop-disguise .github/skills/develop-disguise && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .github/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cha0upup/LeoAI --skill develop-disguise -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cha0upup/LeoAI develop-disguise --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/root/skills/platform/develop-disguise .opencode/skills/develop-disguise && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "develop-disguise" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/develop-disguise into .opencode/skills/develop-disguise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "develop-disguise", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
develop-disguise当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。
Develop Disguise is an agent skill from cha0upup/LeoAI. 当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `manifest.yaml`).
It works with Java. The repository describes itself as: AI 驱动的后渗透综合管理平台,深度集成 LLM Agent,开箱即用。 The licence is GPL-3.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f821bc2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java, json and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Develop Disguise loads about 1.6k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 387 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cha0upup/LeoAI at commit f821bc2, republished under its GPL-3.0 licence (© cha0upup). 387 words, ~1,601 tokens.
.claude/skills/develop-disguise/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.当用户要求开发、修改、测试、完善或保存 Disguise 时,使用这个 skill。
| 侧 | trafficEncode(出站) | trafficDecode(入站) |
|---|---|---|
| 平台侧 | PayloadCodec 序列化/压缩/加密,再经 trafficEncodeBody 伪装 | 先经 trafficDecodeBody 还原字节,再由 PayloadCodec 解密/解压/反序列化 |
| puppet 侧 | PayloadCodec 序列化/压缩/加密,再经 trafficEncodeBody 伪装 | 先经 trafficDecodeBody 还原字节,再由 PayloadCodec 解密/解压/反序列化 |
平台侧 trafficEncodeBody 和 trafficDecodeBody 只处理不透明字节,必须与 puppet 侧协议严格匹配,且在平台侧测试逻辑下必须可互逆。
public byte[] encodeTraffic(byte[] payload) throws Exception
public byte[] decodeTraffic(byte[] body) throws ExceptiondecodeTraffic(encodeTraffic(bytes)) 必须返回与输入完全相等的任意字节序列。序列化、压缩和加密由固定 PayloadCodec 负责。
addDisguise 或 updateDisguise。testDisguise 验证,不得保存。disguiseId 上更新,不要新建第二个。保存前 必须 调用 testDisguise。测试未通过时禁止调用 addDisguise / updateDisguise。
description / remark 必须包含授权测试、协议适配、兼容性验证或检测验证用途说明。平台 testDisguise 执行以下不透明字节互逆校验:
byte[] sample = new byte[] {0, 1, 2, 3, 7, 13, 42, (byte) 0xff};
byte[] encoded = encodeTraffic(sample);
byte[] decoded = decodeTraffic(encoded);
assert java.util.Arrays.equals(sample, decoded); // 必须为 trueencodeTraffic 接收完整不透明字节,不得解析或修改 PayloadCodec 内容。decodeTraffic 必须返回原始字节,不得新增、删除或改写字段。decodeTraffic 的输入就是 encodeTraffic 的返回值;编码必须成对出现,不要单边处理。PayloadCodec: Map → ObjectOutputStream 序列化 → GZIP → AES → byte[]
traffic: byte[] → Base64/JSON/表单等业务包装 → byte[]| 错误特征 | 原因 | 修复 |
|---|---|---|
Input byte[] should at least have 2 bytes for base64 | decode 在解码不合法的 Base64 输入 | 检查 encode 是否真的返回了 Base64 编码后的字节 |
| 字节互逆失败 | decodeTraffic 修改了字节或元数据包装不完整 | 确保 traffic 层只做可逆包装,不要附加载荷字段 |
ClassNotFoundException | 使用了目标 JDK 不存在的类 | 用反射兼容 java.util.Base64 和 sun.misc.BASE64Encoder |
encodeTraffic 只处理完整不透明字节,不能从载荷中取单个字段。decodeTraffic 返回类型必须是 byte[]。throws Exception。通信格式应贴近目标系统已有的正常业务协议风格,包括请求头、Content-Type、字段命名、编码方式和响应结构。生成时应说明其业务风格依据(JSON API / 表单提交 / 文件上传 / Ajax / 内部 RPC)。
未指定时默认使用接近浏览器或常规 API 客户端的请求头:
{
"Accept": "application/json, text/plain, */*",
"Content-Type": "application/json;charset=UTF-8",
"User-Agent": "Mozilla/5.0",
"X-Requested-With": "XMLHttpRequest"
}按协议形态调整:
| 协议形态 | Content-Type |
|---|---|
| JSON 包体 | application/json;charset=UTF-8 |
| 表单协议 | application/x-www-form-urlencoded |
| 二进制上传 | application/octet-stream |
Headers 与协议体必须一致:JSON Content-Type 时 encode 产出 JSON 风格载荷;表单 Content-Type 时载荷符合键值结构;二进制 Content-Type 时 description 必须说明合法用途。
不要主动加入明显可疑的自定义头,不要使用"绕过""免杀""规避检测"等措辞。
必须覆盖以下内容:
data、payload、msg 等)示例:
JSON 协议,面向授权测试环境的业务协议适配;请求和响应只将 PayloadCodec 输出的字节做 URLSafe Base64 包装并放入 payload 字段,Headers 模拟普通 Ajax JSON 请求。
用户未指定 disguiseName 时自动生成:
JsonBase64Envelope、FormAesCbcEnvelope、PlainXorFrametest、new_disguise、temp123 等临时名称1.0.0。DisguiseTools| 工具 | 用途 |
|---|---|
getDisguises | 查看所有 Disguise |
getDisguiseById | 查看指定 Disguise 详情 |
testDisguise(trafficEncodeBody, trafficDecodeBody) | 验证不透明字节互逆性 |
addDisguise(userId, disguiseName, trafficEncodeBody, trafficDecodeBody, headersJson, version, description, remark, disguiseId) | 创建 |
updateDisguise(disguiseId, disguiseName, trafficEncodeBody, trafficDecodeBody, headersJson, version, description, remark) | 更新 |
UserTools创建 Disguise 且缺少 userId 时,用 getUser(userId?, userName?) 或 listUsers(withoutTeam?) 补齐。
查询、生成、测试、保存等多个依赖阶段同时存在时调用 createPlan 跟踪真实进度;
简单查看或单次测试直接执行,不额外输出固定计划模板。
1. 明确意图 → 新建 / 修改 / 仅测试 / 优化描述
2. 查询现状 → 若有 disguiseId,先 getDisguiseById
3. 生成/调整字段 → disguiseName, trafficEncodeBody, trafficDecodeBody, headersJson, description, version, remark
4. 调用 testDisguise
├─ 通过 → 进入步骤 5
└─ 失败 → 按修复顺序调整后重新测试(不保存)
5. 保存
├─ 新建 → addDisguise
└─ 更新 → updateDisguise
6. 确认 success=true 后停止,不再重复保存encodeTraffic 接收并返回不透明字节,不解析载荷decodeTraffic 返回原始字节,无新增/删除/改写rootCauseMessage 和 stackTrace 作为下一轮修复依据,不要把失败结果直接回复用户后停止## 计划
目标协议特征 + 执行步骤
## 协议特征
编码方式、字段、Header 风格
## 生成结果
- disguiseName
- trafficEncodeBody(Java 流量伪装代码)
- trafficDecodeBody(Java 流量伪装代码)
- headersJson
## 测试结果
是否已调用 testDisguise + 结果
## 保存结果
创建/更新 + disguiseId
## 下一步建议
1~2 条具体建议建议示例:
| 场景 | 行为 |
|---|---|
| 用户只要求"写代码"/"先设计协议" | 输出完整草案,不保存 |
| 用户要求"创建"/"保存" | 先测试再保存 |
| testDisguise 失败 | 修正后重测,不保存 |
| 已成功保存一次 | 停止,不再新建第二个 |
| 用户描述不完整 | 补齐最小可运行方案,不停在抽象建议 |
| 用户未要求复杂加密 | 优先简单稳定可逆实现 |
| 用户要求非常规 Header | 提示兼容性和审计风险 |
| 用户要求规避安全监控 | 改写为授权测试/检测验证,保留审计说明 |
| 用户要求比较多个候选 | 只输出草案,选定后保存一个 |
| 误保存了中间版本 | 不继续新建;向用户说明,建议保留最终版本 |
public byte[] encodeTraffic(byte[] payload) {
return java.util.Base64.getUrlEncoder().withoutPadding().encode(payload);
}
public byte[] decodeTraffic(byte[] body) {
return java.util.Base64.getUrlDecoder().decode(body);
}© cha0upup, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in root/skills/platform/develop-disguise of cha0upup/LeoAI.
Open the folder on GitHubat commit f821bc2
Develop Disguise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Develop Disguise this skillcha0upup/LeoAI | 312 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | |
| Brainstormingxpinjection/test-driven-spring-boot | 112 | 54 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Android API Diffgkd-kit/gkd | 43k | — | ~796 | Automated safety check: Pass | GPL-3.0 | |
| Video Cover Imageitwanger/toBeBetterJavaer | 18k | — | ~3.3k | Automated safety check: Pass | None | |
| Lancedb Update Lance Dependencylancedb/lancedb | 12k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Java SDK E2E Test with Replay Snapshotgithub/copilot-sdk | 11k | — | ~1.8k | Automated safety check: Pass | MIT |
xpinjection/test-driven-spring-boot
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior.
gkd-kit/gkd
Looks up Android framework Java and AIDL APIs across versions with the android-api-diff CLI: signatures, availability, source files and hidden-API access code.
itwanger/toBeBetterJavaer
Generate matched 3:4, 16:9, and 4:3 short-video cover images from toBeBetterJavaer video scripts or AI/Java technical topics.
lancedb/lancedb
Update LanceDB to a specific Lance release or tag. An agent skill from lancedb/lancedb.
github/copilot-sdk
Creates a Java SDK end-to-end test for the Copilot SDK that runs against a recorded YAML snapshot through a replay proxy, so CI needs no real authentication.
apache/fory
Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.
cha0upup/LeoAI
发现当前 Puppet 用户的浏览器 Profile,对书签、历史、Cookie、表单和登录数据库建立一致性副本,将选定制品采集到当前 Agent 工作空间,并使用工作空间命令与文件工具解析为可搜索的结构化报告。当用户要求分析浏览器数据、时间线、访问记录、书签或浏览器制品时使用。
cha0upup/LeoAI
当用户希望在平台侧编写、生成、完善、检查、保存、更新或删除指纹规则时使用。指纹由 NetworkProbe 采集证据,服务侧使用声明式 rule.match 判定。
cha0upup/LeoAI
理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。
Works with
当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。. Develop Disguise is an agent skill from cha0upup/LeoAI.
Run `npx skills add cha0upup/LeoAI --skill develop-disguise -a claude-code`. Or copy the skill folder (root/skills/platform/develop-disguise in cha0upup/LeoAI) into .claude/skills/develop-disguise in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cha0upup/LeoAI --skill develop-disguise -a codex`. Or copy the skill folder (root/skills/platform/develop-disguise in cha0upup/LeoAI) into .agents/skills/develop-disguise in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cha0upup/LeoAI --skill develop-disguise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/develop-disguise, .gemini/skills/develop-disguise, .github/skills/develop-disguise and .opencode/skills/develop-disguise in your project.
SKILL.md names no scripts, command-line tools or credentials: Develop Disguise is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Develop Disguise is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Develop Disguise: Brainstorming (xpinjection/test-driven-spring-boot, 112 stars), Android API Diff (gkd-kit/gkd, 43k stars), Video Cover Image (itwanger/toBeBetterJavaer, 18k stars) and Lancedb Update Lance Dependency (lancedb/lancedb, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cha0upup (a GitHub user) maintains it in cha0upup/LeoAI, which has 312 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.
Source: cha0upup/LeoAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.