vphone600 Kernel Symbol Analysis
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .claude/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .claude/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineeringType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .agents/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .agents/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .cursor/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .cursor/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/diegosouzapw/awesome-omni-skills.git --path skills_omni/protocol-reverse-engineering--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .gemini/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .gemini/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineeringInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .github/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .github/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install diegosouzapw/awesome-omni-skills protocol-reverse-engineering --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills_omni/protocol-reverse-engineering .opencode/skills/protocol-reverse-engineering && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "protocol-reverse-engineering" agent skill from https://github.com/diegosouzapw/awesome-omni-skills/tree/main/skills_omni/protocol-reverse-engineering into .opencode/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
protocol-reverse-engineeringProtocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
Protocol Reverse Engineering is an agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering workflow skill. Use this skill when the user needs comprehensive techniques for capturing, analyzing, and documenting network protocols for authorized security research, interoperability work, and debugging, with emphasis on evidence preservation, safe capture practice, and source-backed analysis.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts, reference files and assets (for example `ATTRIBUTION.md`, `OMNI_ENHANCED.json` and `ORIGIN.md`).
It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Public repository of AI coding skills, curated improved best-practice skills, and runtime surfaces for CLI, API, MCP, and A2A. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c3af004. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Protocol Reverse Engineering loads about 3.8k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,767 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from diegosouzapw/awesome-omni-skills at commit c3af004, republished under its MIT licence (© diegosouzapw). 1,767 words, ~3,839 tokens.
.claude/skills/protocol-reverse-engineering/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.This skill supports authorized, evidence-first protocol reverse engineering for defensive security research, interoperability debugging, and protocol documentation.
Use it to move from raw packet captures to a defensible protocol understanding:
This skill focuses on passive analysis and documentation. It does not advise unauthorized interception, encryption bypass, intrusive man-in-the-middle setups, or active tampering unless the user’s scope explicitly authorizes security testing beyond passive observation.
Preserve provenance and raw evidence before trimming, converting, or annotating captures.
Use this skill when you need to:
Do not use this skill as the primary workflow when the task is actually:
Stop and ask for clarification if any of the following are missing:
| Situation | Start here | Why it matters |
|---|---|---|
| You are about to collect traffic | Define scope, interface, timeframe, and BPF capture filter first | Bad capture choices create false conclusions later |
| You already have a pcap | Preserve the original file unchanged and record provenance | Reverse engineering is much harder to defend if raw evidence was altered |
| Traffic appears encrypted | Classify TLS/QUIC/other protections before attempting payload inference | Prevents wasted effort and incorrect decryption assumptions |
| Sessions are interleaved or noisy | Isolate one conversation before inferring fields | Message boundaries and state become clearer when scoped |
| Payload structure is still unclear | Compare multiple sessions and test field hypotheses | Separates constants from lengths, IDs, counters, and timestamps |
| You need references during analysis | Open references/source-map.md | Provides task-indexed official references without bloating this file |
| You need a concrete example | Open examples/synthesis-example.md | Shows how to turn observations into source-backed protocol notes |
Record the operating boundary before analysis:
Output:
Do this before trimming or filtering:
Minimum provenance note:
Before inferring protocol behavior, check whether the capture is trustworthy.
Look for:
If capture quality is poor, fix collection first when possible. Many “unknown protocol” problems are actually evidence-quality problems.
Establish the outer structure before studying the payload.
Questions to answer:
Useful clues:
Output:
Do not reason from mixed traffic if you can avoid it.
For each candidate conversation:
Capture these artifacts:
Work from repeated observations across multiple messages.
For each message candidate, test whether bytes likely represent:
Good practice:
Preferred evidence table columns:
| Offset | Width | Observed values | Hypothesis | Confidence | Evidence |
|---|---|---|---|---|---|
| 0x00 | 1 | 0x01, 0x02 | message type | medium | changes with operation |
If traffic is protected, document what is visible and what is not.
Allowed, defensible paths include:
Important boundary:
If decryption is unavailable, still document:
A field hypothesis is stronger when it survives comparison.
Validate by checking:
Mark each conclusion as one of:
Your output should be reproducible, not just descriptive.
Recommended deliverables:
For binary or structured payloads, prefer a schema-oriented handoff when possible instead of prose alone.
Likely causes:
Checks:
[truncated] or shortened payloadsCorrective action:
Likely causes:
Checks:
Corrective action:
Likely causes:
Checks:
Corrective action:
Likely causes:
Checks:
Corrective action:
Use examples/synthesis-example.md for a compact, source-backed mini-case that shows:
references/source-map.md - task-indexed official references for capture, filtering, reassembly, TLS/QUIC constraints, Zeek correlation, and schema documentationRoute to a different skill when the task shifts to:
© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 18 other files (scripts, references, assets) in skills_omni/protocol-reverse-engineering of diegosouzapw/awesome-omni-skills.
Open the folder on GitHubat commit c3af004
Protocol Reverse Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Protocol Reverse Engineering this skilldiegosouzapw/awesome-omni-skills | 159 | — | ~3.8k | Automated safety check: Pass | MIT | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 936 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Website Rebuildboyang-hu/website-rebuild-skill | 1.4k | — | ~6.1k | Automated safety check: Pass | MIT | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT |
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
boyang-hu/website-rebuild-skill
1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
diegosouzapw/awesome-omni-skills
Content Creator workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
diegosouzapw/awesome-omni-skills
Helm Chart Scaffolding workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
diegosouzapw/awesome-omni-skills
Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
diegosouzapw/awesome-omni-skills
Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
diegosouzapw/awesome-omni-skills
📝 Prompt Library workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
diegosouzapw/awesome-omni-skills
Puzzle Activity Planner workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
Categories
Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering is an agent skill from diegosouzapw/awesome-omni-skills. Protocol Reverse Engineering workflow skill.
Protocol Reverse Engineering fits situations like: the user needs comprehensive techniques for capturing; documenting network protocols for authorized security research; interoperability work; with emphasis on evidence preservation.
Run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a claude-code`. Or copy the skill folder (skills_omni/protocol-reverse-engineering in diegosouzapw/awesome-omni-skills) into .claude/skills/protocol-reverse-engineering in your project. Claude Code loads it when a task matches its description.
Run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a codex`. Or copy the skill folder (skills_omni/protocol-reverse-engineering in diegosouzapw/awesome-omni-skills) into .agents/skills/protocol-reverse-engineering in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/awesome-omni-skills --skill protocol-reverse-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protocol-reverse-engineering, .gemini/skills/protocol-reverse-engineering, .github/skills/protocol-reverse-engineering and .opencode/skills/protocol-reverse-engineering in your project.
SKILL.md names no scripts, command-line tools or credentials: Protocol Reverse Engineering is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Protocol Reverse Engineering is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Protocol Reverse Engineering: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
diegosouzapw (a GitHub user) maintains it in diegosouzapw/awesome-omni-skills, which has 159 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on July 8, 2026.
Source: diegosouzapw/awesome-omni-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.