Agent skill

Shell Obfuscation

by cha0upup in cha0upup/LeoAI

理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。

GPL-3.0Auto-check passed

Install Shell Obfuscation

skills CLI
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .claude/skills/shell-obfuscation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shell-obfuscation
GitHub stars
312
Token cost
~776 tokens
SKILL.md length
232 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
GPL-3.0

At a glance

理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。

  • Works in 5 steps: 运行时与承载方式:Java WebShell、Java 内存马或 PHP… → 用户本次选择的通信参数:传输协议、请求伪装器、响应伪装器。 → 兼容与结构参数:JSP/JSPX、Java/Servlet… → …
  • SKILL.md covers 生成模型, 参数确认原则, Java WebShell 工作流 and Java 内存马工作流, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Shell Obfuscation is an agent skill from cha0upup/LeoAI. 理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `manifest.yaml`).

It works with Java and PHP. The repository describes itself as: AI 驱动的后渗透综合管理平台,深度集成 LLM Agent,开箱即用。 The licence is GPL-3.0.

Example prompts

  • “/shell-obfuscation”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 运行时与承载方式:Java WebShell、Java 内存马或 PHP WebShell。
  2. 用户本次选择的通信参数:传输协议、请求伪装器、响应伪装器。
  3. 兼容与结构参数:JSP/JSPX、Java/Servlet 版本、容器、注入器、Packer、输出模式和混淆策略。
  4. Java WebShell 的 Core 字节码只保存在服务端 CoreArtifactStore,AI 仅设计不含 Payload 的 Wrapper 模板。
  5. 结果交付:生成器把完整结果写入 ShellResultStore,工具返回 resultId、元数据和取回按钮。

What it can do on your machine

Read from SKILL.md and the folder at commit f821bc2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shell Obfuscation loads about 776 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 232 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~776

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cha0upup/LeoAI at commit f821bc2, republished under its GPL-3.0 licence (© cha0upup). 232 words, ~776 tokens.

Download SKILL.mdSave it as .claude/skills/shell-obfuscation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
shell-obfuscation
description
理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。

Shell 生成与结构变体

Shell 是独立生成的制品,不从平台已有 Puppet 自动继承配置。只有用户明确要求“匹配/复制某个 Puppet”时,才可以查询该指定节点;不得因为平台上只有一个节点、最近操作过某个节点或当前页面选中了节点就读取它。

生成模型

一次生成由五部分组成:

  1. 运行时与承载方式:Java WebShell、Java 内存马或 PHP WebShell。
  2. 用户本次选择的通信参数:传输协议、请求伪装器、响应伪装器。
  3. 兼容与结构参数:JSP/JSPX、Java/Servlet 版本、容器、注入器、Packer、输出模式和混淆策略。
  4. Java WebShell 的 Core 字节码只保存在服务端 CoreArtifactStore,AI 仅设计不含 Payload 的 Wrapper 模板。
  5. 结果交付:生成器把完整结果写入 ShellResultStore,工具返回 resultId、元数据和取回按钮。

不要手写或转述完整生成代码,不要虚构工具未返回的结果。

参数确认原则

  1. 生成前调用 getShellGeneratorMeta() 获取协议、Java/Servlet、注入器、Packer 和混淆步骤等合法值。
  2. 调用 getDisguises() 获取当前可选请求/响应伪装器;不得用 Puppet 查询代替该步骤。
  3. 用户未给出的重要生成偏好必须通过 request_user_input 询问。Java WebShell 至少确认:
    • 传输协议:http 或 httpchunk;
    • 请求伪装器与响应伪装器;
    • 文件类型:JSP 或 JSPX;
    • 是否启用混淆。
  4. Java WebShell 必须显式传 obfuscate=true/false;启用默认混淆时不传步骤,只有用户指定步骤时才从元数据中选择并保持顺序。
  5. Java 版本和 Servlet 命名空间未指定时可使用 auto;已知 Jakarta 环境时显式使用 jakarta。
  6. 类名未指定时留空,让生成器随机生成。不要为了填满参数而猜测用户意图。

Java WebShell 工作流

  1. 调用 getShellGeneratorMeta() 和 getDisguises()。
  2. 对尚未明确的传输协议、请求/响应伪装、JSP/JSPX 和混淆开关调用 request_user_input;调用后停止本轮,等待用户回答。
  3. 调用 createJavaCoreArtifact(...),只接收 coreArtifactId、哈希和契约元数据;不得请求 Core 字节码或 Base64。
  4. 可调用 getWebShellWrapperContract(...) 查看五个阶段占位符和无 Payload 基线模板。
  5. 调用 designWebShellWrapper(coreArtifactId, shellType, requirements)。工具内部让 AI 设计外层并验证,成功后只返回 wrapperTemplateId。
  6. 调用 assembleWebShellWrapper(...),明确传入 obfuscate=true/false;平台再次验证模板后才注入真实 Core 并组装结果。
  7. 检查返回元数据中的 Core 哈希、协议、类型、版本、命名空间和混淆信息。
  8. 原样嵌入工具返回的 [[shell-result:...]] 取回按钮。

Java WebShell 的五个阶段占位符必须各出现一次、独占一行并保持顺序。真实加载、读取、调用和响应代码由平台注入,以保证 LeoCore 单次调用和同一 buffer 数据流;AI 不得展开或改写这些阶段。

Java 内存马工作流

  1. 调用 getShellGeneratorMeta() 和 getDisguises()。
  2. 询问尚未明确的协议、请求/响应伪装、目标容器、注入器、Packer 和是否混淆;不要从 Puppet 推断。
  3. 根据元数据检查 packerCompatibility、packerAvailability 和可用混淆步骤。
  4. 只有用户明确要求结构变体且 Packer 为 ClassLoaderJSP 或 DefineClassJSP 时,才调用 mutateJspTemplate(...);其他 Packer 不接受 AI 自定义模板。
  5. 调用 generateMemoryShell(...),检查兼容性警告并交付取回按钮。

PHP WebShell 工作流

  1. 调用 getShellGeneratorMeta() 和 getDisguises(),确认 PHP generator 的真实能力。
  2. 询问请求/响应伪装和输出模式;PHP 当前仅支持 http,应向用户说明而不是查询 Puppet。
  3. 要求用户提供 PHP PayloadCodec AES 密钥;不得使用默认值或环境变量。
  4. headerName 与 headerValue 必须同时设置或同时留空;不要在回复中显示 Header 密钥。
  5. 调用 generatePhpWebShell(...),检查最低版本、运行要求、输出模式和警告后交付结果。

明确匹配 Puppet 的例外

只有用户明确给出或选择了目标 Puppet,并明确要求生成结果匹配该节点时,才允许读取该节点配置。读取结果只能服务于这次显式匹配;不能把它变成后续独立生成的默认值。排查“某个已生成 Shell 为什么连不上”时,也只有在用户把该 Shell 与具体 Puppet 建立关联后才比较两者配置。

失败处理

  • 伪装器为空或不存在:停止生成,重新展示可用伪装器并询问用户。
  • 参数不在元数据中:重新读取元数据并让用户从合法候选中选择,不重复提交同一无效值。
  • PHP 请求 httpchunk:说明当前只支持 http,等待用户确认后再生成。
  • 模板连续变异失败:报告失败,不得自行拼接 JSP 冒充生成成功。
  • CoreArtifact 或 Wrapper 模板过期:重新执行对应生成阶段,不得要求工具返回缓存中的 Core Payload。
  • 工具返回兼容性警告:区分“生成成功”和“已验证可运行”。
  • 没有真实 resultId:不得输出取回按钮或声称生成完成。

回复要求

简洁报告生成类型、用户选择的协议与伪装、关键兼容/混淆参数、警告,以及工具返回的取回按钮。除非用户明确要求匹配 Puppet,否则回复中不应出现目标 Puppet。

© cha0upup, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in root/skills/platform/shell-obfuscation of cha0upup/LeoAI.

  • SKILL.md
  • manifest.yaml

Open the folder on GitHubat commit f821bc2

Compare with similar skills

Shell Obfuscation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shell Obfuscation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shell Obfuscation this skillcha0upup/LeoAI312—~776Automated safety check: PassGPL-3.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Audit SkillsRuoJi6/audit-skills1k—~447Automated safety check: PassNone
Skylosduriantaco/skylos843—~581Automated safety check: PassApache-2.0
Insecure Deserialization PlaybookPentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.0
Skylos Securityduriantaco/skylos843—~545Automated safety check: PassApache-2.0

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Audit Skills

    RuoJi6/audit-skills

    当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

    1k GitHub stars~447 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    843 GitHub stars~581 tokensUpdated yesterday
    SecurityAuto-check passed
  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Skylos Security

    duriantaco/skylos

    Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

    843 GitHub stars~545 tokensUpdated yesterday
    SecurityAuto-check passed
  • Claude API Development

    warpdotdev/warp

    Guides building, debugging and tuning apps on the Claude API and Anthropic SDK, including prompt caching, and migrating code between Claude model versions.

    65k GitHub starsUsed in 3 repos~8.2k tokens
    AI & LLM EngineeringAuto-check passed

More from cha0upup/LeoAI

  • Develop Disguise

    cha0upup/LeoAI

    当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。

    312 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • 发现当前 Puppet 用户的浏览器 Profile,对书签、历史、Cookie、表单和登录数据库建立一致性副本,将选定制品采集到当前 Agent 工作空间,并使用工作空间命令与文件工具解析为可搜索的结构化报告。当用户要求分析浏览器数据、时间线、访问记录、书签或浏览器制品时使用。

    312 GitHub stars~1k tokensUpdated 7 days ago
    Auto-check: warnings
  • Develop Fingerprint

    cha0upup/LeoAI

    当用户希望在平台侧编写、生成、完善、检查、保存、更新或删除指纹规则时使用。指纹由 NetworkProbe 采集证据,服务侧使用声明式 rule.match 判定。

    312 GitHub stars~382 tokensUpdated 7 days ago
    Auto-check passed

Works with

Questions about Shell Obfuscation

What does Shell Obfuscation do?

理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。. Shell Obfuscation is an agent skill from cha0upup/LeoAI.

How do I install Shell Obfuscation in Claude Code?

Run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a claude-code`. Or copy the skill folder (root/skills/platform/shell-obfuscation in cha0upup/LeoAI) into .claude/skills/shell-obfuscation in your project. Claude Code loads it when a task matches its description.

How do I install Shell Obfuscation in Codex?

Run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a codex`. Or copy the skill folder (root/skills/platform/shell-obfuscation in cha0upup/LeoAI) into .agents/skills/shell-obfuscation in your project. Codex loads it when a task matches its description.

Can I use Shell Obfuscation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shell-obfuscation, .gemini/skills/shell-obfuscation, .github/skills/shell-obfuscation and .opencode/skills/shell-obfuscation in your project.

What does Shell Obfuscation need to run?

SKILL.md names no scripts, command-line tools or credentials: Shell Obfuscation is instructions for the agent only.

Does Shell Obfuscation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Shell Obfuscation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shell Obfuscation use?

Shell Obfuscation is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shell Obfuscation use?

About 776 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shell Obfuscation?

Skills that share tags, products or a category with Shell Obfuscation: Code Audit (3stoneBrother/code-audit, 893 stars), Audit Skills (RuoJi6/audit-skills, 1k stars), Skylos (duriantaco/skylos, 843 stars) and Insecure Deserialization Playbook (PentesterFlow/agent, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shell Obfuscation?

cha0upup (a GitHub user) maintains it in cha0upup/LeoAI, which has 312 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.

Source: cha0upup/LeoAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.