Agent skill

Protocol Reverse Engineering

by diegosouzapw in diegosouzapw/awesome-omni-skills

Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

MITAuto-check passedSecurity

Install Protocol Reverse Engineering

skills CLI
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .claude/skills/protocol-reverse-engineering && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
protocol-reverse-engineering
GitHub stars
159
Token cost
~3.8k tokens
SKILL.md length
1,767 words
Files
19 (incl. scripts, references, assets)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

  • Works in 9 steps: Confirm authorization and define scope → Preserve raw evidence before analysis → Validate capture quality → …
  • The user needs comprehensive techniques for capturing
  • SKILL.md covers Overview, When to Use, Operating Table and Workflow, plus 5 more sections
  • Documenting network protocols for authorized security research

What it does

Protocol Reverse Engineering is an agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering workflow skill. Use this skill when the user needs comprehensive techniques for capturing, analyzing, and documenting network protocols for authorized security research, interoperability work, and debugging, with emphasis on evidence preservation, safe capture practice, and source-backed analysis.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts, reference files and assets (for example `ATTRIBUTION.md`, `OMNI_ENHANCED.json` and `ORIGIN.md`).

It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Public repository of AI coding skills, curated improved best-practice skills, and runtime surfaces for CLI, API, MCP, and A2A. The licence is MIT.

When your agent uses it

  • The user needs comprehensive techniques for capturing
  • Documenting network protocols for authorized security research
  • Interoperability work
  • With emphasis on evidence preservation

Example prompts

  • “/protocol-reverse-engineering”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Confirm authorization and define scope
  2. Preserve raw evidence before analysis
  3. Validate capture quality
  4. Classify the transport and security layer
  5. Isolate conversations and reconstruct streams
  6. Infer framing and field structure
  7. Handle encrypted protocols correctly
  8. Validate hypotheses across sessions
  9. Produce reusable documentation

What it can do on your machine

Read from SKILL.md and the folder at commit c3af004. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Protocol Reverse Engineering loads about 3.8k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,767 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from diegosouzapw/awesome-omni-skills at commit c3af004, republished under its MIT licence (© diegosouzapw). 1,767 words, ~3,839 tokens.

Download SKILL.mdSave it as .claude/skills/protocol-reverse-engineering/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
protocol-reverse-engineering
description
Protocol Reverse Engineering workflow skill. Use this skill when the user needs comprehensive techniques for capturing, analyzing, and documenting network protocols for authorized security research, interoperability work, and debugging, with emphasis on evidence preservation, safe capture practice, and source-backed analysis.
version
0.0.1
category
testing-security
tags
protocol-reverse-engineering, network-analysis, packet-capture, wireshark, tcpdump, protocol-documentation, omni-enhanced
complexity
advanced
risk
safe
tools
codex-cli, claude-code, cursor, gemini-cli, opencode
source
omni-team
author
Omni Skills Team
date_added
2026-04-15
date_updated
2026-04-19

Protocol Reverse Engineering

Overview

This skill supports authorized, evidence-first protocol reverse engineering for defensive security research, interoperability debugging, and protocol documentation.

Use it to move from raw packet captures to a defensible protocol understanding:

  • what transport is in use
  • whether traffic is cleartext, compressed, or encrypted
  • how conversations are segmented
  • what fields and message types appear stable across sessions
  • what remains unknown and needs validation

This skill focuses on passive analysis and documentation. It does not advise unauthorized interception, encryption bypass, intrusive man-in-the-middle setups, or active tampering unless the user’s scope explicitly authorizes security testing beyond passive observation.

Preserve provenance and raw evidence before trimming, converting, or annotating captures.

When to Use

Use this skill when you need to:

  • capture and analyze an unknown or partially documented network protocol
  • document message framing, fields, and state transitions from packet evidence
  • troubleshoot interoperability issues between a client and server
  • determine whether application data is recoverable or blocked by modern encryption
  • compare multiple sessions to separate constants, counters, timestamps, lengths, and payload data
  • turn packet observations into reusable documentation, field tables, or machine-readable schema notes

Do not use this skill as the primary workflow when the task is actually:

  • unauthorized interception or surveillance
  • exploit development or offensive protocol manipulation
  • active fuzzing of a protocol implementation
  • malware traffic analysis that needs a dedicated malware or incident-response workflow
  • pure packet forensics where reconstruction and attribution matter more than protocol grammar extraction

Stop and ask for clarification if any of the following are missing:

  • authorization to capture or inspect the traffic
  • target environment and scope boundaries
  • whether passive-only analysis is required
  • success criteria for the reverse-engineering output
  • available evidence such as pcaps, endpoint logs, or session secrets

Operating Table

SituationStart hereWhy it matters
You are about to collect trafficDefine scope, interface, timeframe, and BPF capture filter firstBad capture choices create false conclusions later
You already have a pcapPreserve the original file unchanged and record provenanceReverse engineering is much harder to defend if raw evidence was altered
Traffic appears encryptedClassify TLS/QUIC/other protections before attempting payload inferencePrevents wasted effort and incorrect decryption assumptions
Sessions are interleaved or noisyIsolate one conversation before inferring fieldsMessage boundaries and state become clearer when scoped
Payload structure is still unclearCompare multiple sessions and test field hypothesesSeparates constants from lengths, IDs, counters, and timestamps
You need references during analysisOpen references/source-map.mdProvides task-indexed official references without bloating this file
You need a concrete exampleOpen examples/synthesis-example.mdShows how to turn observations into source-backed protocol notes

Workflow

1. Confirm authorization and define scope

Record the operating boundary before analysis:

  • who authorized the work
  • what hosts, interfaces, or captures are in scope
  • whether analysis is passive-only
  • whether the environment includes NAT, proxies, TLS termination, or load balancers
  • whether endpoint access, logs, or session secrets are available

Output:

  • a short scope statement
  • explicit non-goals
  • stop conditions for out-of-scope traffic or unexpected sensitive content
2. Preserve raw evidence before analysis

Do this before trimming or filtering:

  • keep the original pcap/pcapng untouched
  • record capture time window, timezone/clock context, interface, host role, and capture point
  • record any BPF capture filter used
  • note snaplen and whether packet truncation or drops were reported

Minimum provenance note:

  • capture source
  • interface or mirror/span point
  • filter used at capture time
  • file hash if available
  • analyst and timestamp
3. Validate capture quality

Before inferring protocol behavior, check whether the capture is trustworthy.

Look for:

  • dropped packets
  • too-small snaplen causing truncation
  • checksum or segmentation offload artifacts
  • asymmetric routing or partial visibility
  • time skew between capture sources
  • incomplete handshakes or missing connection setup

If capture quality is poor, fix collection first when possible. Many “unknown protocol” problems are actually evidence-quality problems.

4. Classify the transport and security layer

Establish the outer structure before studying the payload.

Questions to answer:

  • TCP or UDP?
  • Single request/response or multiplexed streams?
  • Cleartext, compressed, or encrypted?
  • TLS present? If so, which version indicators are visible?
  • QUIC present over UDP?
  • Are SNI, ALPN, certificate metadata, or handshake properties visible even if payload is not?
  • Which side acts as client and which as server?

Useful clues:

  • destination ports are hints, not proof
  • ALPN can indicate higher-level protocols
  • repeated length-prefixed records suggest framing
  • stable first-byte patterns may indicate message type/version fields

Output:

  • protocol classification note
  • client/server role assignment
  • encryption decision branch
5. Isolate conversations and reconstruct streams

Do not reason from mixed traffic if you can avoid it.

For each candidate conversation:

  • isolate by 5-tuple and time window
  • follow the TCP stream or equivalent reconstructed flow
  • enable or verify reassembly behavior where appropriate
  • distinguish application records from transport segmentation
  • note retries, resets, retransmissions, and out-of-order delivery

Capture these artifacts:

  • conversation ID or stream index
  • start/end timestamps
  • request/response sequence or bidirectional event list
  • any correlation to DNS, process role, or application log entries
6. Infer framing and field structure

Work from repeated observations across multiple messages.

For each message candidate, test whether bytes likely represent:

  • magic/version bytes
  • message type or opcode
  • length fields
  • request IDs, correlation IDs, or stream IDs
  • flags or capability bits
  • counters, sequence numbers, or timestamps
  • checksums, MACs, or cryptographic material
  • variable-length payloads or nested records

Good practice:

  • compare several examples of the same operation
  • compare a success case and a failure case
  • compare short vs long payloads to validate length assumptions
  • record confidence levels rather than forcing certainty too early

Preferred evidence table columns:

OffsetWidthObserved valuesHypothesisConfidenceEvidence
0x0010x01, 0x02message typemediumchanges with operation
7. Handle encrypted protocols correctly

If traffic is protected, document what is visible and what is not.

Allowed, defensible paths include:

  • analyzing cleartext protocols directly
  • using authorized endpoint-generated session secrets such as key log files where supported
  • using server-side material only when it is actually applicable and authorized
  • documenting handshake metadata and residual unknowns when decryption is not possible

Important boundary:

  • do not assume a private key is enough to decrypt modern TLS traffic
  • for TLS 1.3 and many modern deployments, private-key-only decryption is insufficient
  • QUIC combines transport and crypto behavior in ways that change normal TCP-era assumptions
  • this skill does not cover bypassing encryption controls

If decryption is unavailable, still document:

  • handshake metadata
  • SNI/ALPN visibility
  • certificate or endpoint identity clues
  • packet sizes, timing, burst patterns, and session boundaries
Show full SKILL.md (728 more words)Show less
8. Validate hypotheses across sessions

A field hypothesis is stronger when it survives comparison.

Validate by checking:

  • multiple captures of the same operation
  • different payload sizes
  • different users or sessions when authorized
  • success vs error responses
  • version or capability negotiation differences
  • whether inferred lengths match actual payload sizes
  • whether sequence or correlation identifiers line up with message ordering

Mark each conclusion as one of:

  • confirmed by repeated observation
  • plausible but unconfirmed
  • contradicted by later evidence
  • still unknown
9. Produce reusable documentation

Your output should be reproducible, not just descriptive.

Recommended deliverables:

  • protocol overview and scope statement
  • capture provenance and environment notes
  • transport/security classification
  • conversation map
  • message catalog
  • field table with offsets and confidence levels
  • state transition notes
  • edge cases and failure behavior
  • known unknowns
  • schema stub or machine-readable format description when useful

For binary or structured payloads, prefer a schema-oriented handoff when possible instead of prose alone.

Troubleshooting

I captured traffic, but the protocol looks malformed

Likely causes:

  • snaplen too small, causing truncation
  • dropped packets
  • TCP reassembly not considered
  • checksum/offload artifacts
  • only one direction of the flow was captured

Checks:

  • verify snaplen and capture statistics
  • inspect for [truncated] or shortened payloads
  • compare packet counts from both directions
  • check whether retransmissions or missing segments break message boundaries
  • confirm whether the capture point sees pre- or post-NAT traffic

Corrective action:

  • recollect with appropriate snaplen and a narrower BPF if possible
  • analyze a clean, isolated conversation
  • re-test hypotheses only after evidence quality is acceptable
I see packets, but I cannot decode the application layer

Likely causes:

  • TLS 1.3 or another encrypted transport without authorized session secrets
  • QUIC over UDP
  • wrong assumption that a server private key can decrypt everything
  • certificate/private-key mismatch or unsupported decryption path

Checks:

  • identify whether TLS or QUIC is present
  • check for visible SNI, ALPN, handshake version, and certificate metadata
  • verify whether authorized key logs or equivalent session secrets exist
  • confirm the capture includes the handshake needed for context

Corrective action:

  • use authorized session secrets when available
  • document what remains opaque if decryption is not possible
  • continue with metadata, flow, timing, and message-size analysis rather than inventing payload structure
My conclusions change depending on which packets I select

Likely causes:

  • mixing several conversations together
  • request/response interleaving
  • load balancer, proxy, or NAT rewriting endpoints
  • multiple protocol versions or modes in the same capture

Checks:

  • isolate by conversation or stream index
  • group by endpoint role rather than IP alone when proxies are involved
  • compare repeated operations from the same client state
  • look for ALPN, version, or capability negotiation differences

Corrective action:

  • analyze one scoped conversation at a time
  • annotate infrastructure layers that can alter apparent endpoint identity
  • produce separate notes for each protocol variant or transport mode
No packets are showing up, or I captured the wrong traffic

Likely causes:

  • wrong interface
  • capture filter mistake
  • confusion between capture filters and display filters
  • capture point does not actually see the target traffic

Checks:

  • confirm interface selection
  • validate the BPF syntax separately from any Wireshark display filter
  • test with a minimal capture filter first
  • verify whether traffic is inside a tunnel, namespace, or mirrored segment you are not observing

Corrective action:

  • simplify the BPF
  • correct the interface or vantage point
  • capture broadly enough to validate visibility, then narrow safely

Examples

Use examples/synthesis-example.md for a compact, source-backed mini-case that shows:

  • a bounded analysis goal
  • capture metadata and BPF choice
  • conversation isolation and reassembly thinking
  • encryption decision handling
  • field inference with confidence levels
  • final protocol notes including known unknowns

Additional Resources

  • references/source-map.md - task-indexed official references for capture, filtering, reassembly, TLS/QUIC constraints, Zeek correlation, and schema documentation
  • Wireshark User’s Guide
  • Wireshark TLS guidance
  • tcpdump and pcap-filter manuals
  • RFC 8446 for TLS 1.3
  • RFC 9000 for QUIC
  • Zeek documentation
  • Kaitai Struct documentation

Route to a different skill when the task shifts to:

  • packet forensics and incident reconstruction
  • malware traffic analysis
  • TLS deployment troubleshooting
  • binary file-format reverse engineering outside network captures
  • active protocol fuzzing or exploit-oriented security testing

Safe Operating Notes

  • Analyze only traffic you are authorized to capture or receive.
  • Prefer passive collection and documentation unless the scope explicitly permits active testing.
  • Preserve original evidence before transformation.
  • Keep capture filters narrow and intentional to reduce unnecessary data collection.
  • Distinguish capture filters from display filters.
  • Document uncertainty instead of overstating conclusions.
  • If the user asks for encryption bypass or unauthorized interception, refuse and redirect to lawful alternatives such as metadata-only analysis or authorized endpoint instrumentation.

© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references, assets) in skills_omni/protocol-reverse-engineering of diegosouzapw/awesome-omni-skills.

  • SKILL.md
  • ATTRIBUTION.md
  • OMNI_ENHANCED.json
  • ORIGIN.md
  • agents/omni-import-router.md
  • assets/omni-import-source-manifest.json
  • examples/omni-import-operator-packet.md
  • examples/omni-import-prompt-template.md
  • examples/synthesis-example.md
  • metadata.json
  • references/omni-import-checklist.md
  • references/omni-import-playbook.md
  • references/omni-import-rubric.md
  • references/omni-import-source-summary.md
  • references/source-map.md
  • resources/implementation-playbook.md
  • … and 3 more

Open the folder on GitHubat commit c3af004

Compare with similar skills

Protocol Reverse Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Protocol Reverse Engineering compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Protocol Reverse Engineering this skilldiegosouzapw/awesome-omni-skills159—~3.8kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from diegosouzapw/awesome-omni-skills

All 39 skills in this repo
  • Content Creator

    diegosouzapw/awesome-omni-skills

    Content Creator workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4k tokensUpdated 3 mo ago
    Auto-check passed
  • Helm Chart Scaffolding

    diegosouzapw/awesome-omni-skills

    Helm Chart Scaffolding workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Engineering

    diegosouzapw/awesome-omni-skills

    Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Engineering Patterns

    diegosouzapw/awesome-omni-skills

    Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Library

    diegosouzapw/awesome-omni-skills

    📝 Prompt Library workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Puzzle Activity Planner

    diegosouzapw/awesome-omni-skills

    Puzzle Activity Planner workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.9k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Protocol Reverse Engineering

What does Protocol Reverse Engineering do?

Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering is an agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering workflow skill.

When should I use Protocol Reverse Engineering?

Protocol Reverse Engineering fits situations like: the user needs comprehensive techniques for capturing; documenting network protocols for authorized security research; interoperability work; with emphasis on evidence preservation.

How do I install Protocol Reverse Engineering in Claude Code?

Run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a claude-code`. Or copy the skill folder (skills_omni/protocol-reverse-engineering in diegosouzapw/awesome-omni-skills) into .claude/skills/protocol-reverse-engineering in your project. Claude Code loads it when a task matches its description.

How do I install Protocol Reverse Engineering in Codex?

Run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a codex`. Or copy the skill folder (skills_omni/protocol-reverse-engineering in diegosouzapw/awesome-omni-skills) into .agents/skills/protocol-reverse-engineering in your project. Codex loads it when a task matches its description.

Can I use Protocol Reverse Engineering in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protocol-reverse-engineering, .gemini/skills/protocol-reverse-engineering, .github/skills/protocol-reverse-engineering and .opencode/skills/protocol-reverse-engineering in your project.

What does Protocol Reverse Engineering need to run?

SKILL.md names no scripts, command-line tools or credentials: Protocol Reverse Engineering is instructions for the agent only.

Does Protocol Reverse Engineering access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Protocol Reverse Engineering safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Protocol Reverse Engineering use?

Protocol Reverse Engineering is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Protocol Reverse Engineering use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Protocol Reverse Engineering?

Skills that share tags, products or a category with Protocol Reverse Engineering: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Protocol Reverse Engineering?

diegosouzapw (a GitHub user) maintains it in diegosouzapw/awesome-omni-skills, which has 159 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on July 8, 2026.

Source: diegosouzapw/awesome-omni-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.