Ctf Crypto
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件
$ npx skills add dslsdzc/rev-skills --skill re-java -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-java --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-java .claude/skills/re-java && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .claude/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-javaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-java -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-java --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-java .agents/skills/re-java && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .agents/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-java -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-java --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-java .cursor/skills/re-java && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .cursor/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-java--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-java -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-java --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-java .gemini/skills/re-java && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .gemini/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-javaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-java -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-java .github/skills/re-java && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .github/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-java -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-java --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-java .opencode/skills/re-java && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-java" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-java into .opencode/skills/re-java/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-java", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-javaJava 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件
Re Java is an agent skill from dslsdzc/rev-skills. Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. It works with Java, Homebrew and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
javabrewaptdnfcurlchocoFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
benf.orgrepo1.maven.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Java loads about 1.4k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 423 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 423 words, ~1,409 tokens.
.claude/skills/re-java/SKILL.md (or your agent's skills folder).参考 [[re-analyze/platform-tips]]——反编译/解包为静态步骤,免沙箱;动态验证按最高原则进沙箱。
apt install openjdk-17-jdkdnf install java-17-openjdk;Arch: pacman -S jdk17-openjdkbrew install openjdk(或 brew install --cask temurin)choco install temurin 或官方安装器java -version && javap -versionapt install unzip / dnf install unzip / pacman -S unzip;macOS: brew install unzipunzip -vcurl -L -o cfr.jar https://www.benf.org/other/cfr/cfr-0.152.jarjava -jar cfr.jar --helpjava-decompiler/jd-gui release zip → 解压,Linux/macOS: java -jar jd-gui-1.6.6.jar(zip 内含各平台可执行)File > Open 打开 jarcurl -L -o procyon-decompiler.jar https://repo1.maven.org/maven2/org/bitbucket/mstrobel/procyon-decompiler/0.6.0/procyon-decompiler-0.6.0.jarjava -jar procyon-decompiler.jar --help按顺序执行,每步记录证据(路径 + sha256,见 [[re-triage]])。
jar/war 解包:
jar tf app.jar # 先看清单(JDK 自带 jar 工具)
unzip -o app.jar -d unpacked/
unzip -p app.jar META-INF/MANIFEST.MF # Main-Class / 加固标记WEB-INF/classes/,依赖在 WEB-INF/lib/BOOT-INF/classes/,嵌套依赖 BOOT-INF/lib/*.jar 需逐个解classes.jar,解出后再按本技能处理META-INF/versions/N/(N=9/11/17…)下覆盖——运行时按 JDK 选版加载,逆向按目标 JDK 看对应层,别只看顶层类结构识别:
javap -c -p unpacked/com/example/Main.class # 字节码(-c)+ 私有成员(-p)
javap -v unpacked/com/example/Main.class # 常量池/元数据Main-Class → javap -c -p <入口类> 看 main 逻辑xxd -l 8 <类>.class → CA FE BA BE + minor(2) + major(2);Java 版本 = major − 44(52=Java 8、55=11、61=17、65=21,实测 JDK 21 产物 major=65);javap -v 首行直接打印 minor/majorjavap -v 列条目类型(String/Class/NameAndType/Methodref/Utf8 等)——字符串字面量、类名、签名全在常量池,混淆样本的明文串先在这里找逻辑还原(CFR / JD-GUI):
java -jar cfr.jar app.jar --outputdir cfr_out/ # 整包还原为 Java 源码
java -jar cfr.jar unpacked/com/example/Main.class # 单类还原
java -jar procyon-decompiler.jar -jar app.jar -o procyon_out/ # 备选File > Open → 左侧树浏览 → File > Save All Sources 导出混淆识别与字符串解密:
a/b/c、javap -l 无 LineNumberTable/LocalVariableTable(调试信息被剥)com.allatori.* 水印类、StringEncryptor 调用(字符串加密)com.zelix.* 类特征grep -rn 'StringEncryptor\|decrypt(' cfr_out/ | head动态(可选;沙箱内执行 [[re-sandbox]]):
jdb -classpath app.jar com.example.Main
> stop in com.example.Main.checkKey # 下断点
> print key # 取变量
> eval new com.example.Util().decrypt("密文") # 直接调用解密方法取明文Java.perform(function () {
var c = Java.use("com.example.Main");
c.checkKey.implementation = function (k) {
console.log("key = " + k);
return this.checkKey(k);
};
});a/b/c 类、a(...) 方法,无法定位目标逻辑;原因——ProGuard shrink+obfuscate 重命名抹掉语义;对策——从字符串入手:grep 明文 URL/提示语 → 在反编译产物里找引用它的类(grep -rn "提示语" cfr_out/)→ 沿调用链恢复语义StringEncryptor.decrypt("...") 调用,看不到任何明文;原因——字符串运行时才解密;对策——静态定位解密算法与 key → python3 复刻批量还原;或动态在解密调用后取明文(JDB eval / Frida),沙箱内执行javap -c -p 字节码手工修正,多反编译器交叉验证javap 输出损坏、文件头非标准;原因——加固器加密 class 字节码、运行时才解密(本质是壳);对策——先脱加固:运行时 dump class(attach agent / 专用脱壳工具为主;-Xbootclasspath 仅 JDK 8 可用,JDK 9+ 已移除该选项)→ 对脱出的标准 class 再反编译;思路同 [[re-anti-analysis]] 的"先脱壳后分析"javap 报 major version 65 之类不支持;原因——class 文件版本高于本机 JDK 工具版本;对策——按 major−44 换算目标 Java 版本,装对应或更新的 JDK;只读版本与常量池可先用 xxd 手工看头字段,不必等工具unzip -o 解出顶层类后反编译,逻辑与运行时行为不符(版本分支消失);原因——多版本类在 META-INF/versions/N/,不同 JDK 加载不同层;对策——解包后检查 META-INF/versions/,按目标 JDK 选层分析;顶层与 versions 层的差异就是版本条件逻辑lambda$xxx$n 方法或 invokedynamic 调用;原因——lambda 体编译为合成私有方法 + invokedynamic 引导;对策——javap -v -p 的 BootstrapMethods 表定位 lambda 体方法(捕获变量在合成方法参数里),按普通方法分析即可© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-java of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Java next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Java this skilldslsdzc/rev-skills | 117 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Mole CLI Release Flowtw93/Mole | 69k | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | |
| Reproduce macOS Python FlavorsNuitka/Nuitka | 15k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| CodexBar macOS Releasesteipete/CodexBar | 22k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Releaseeugene1g/agent-safehouse | 2.1k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 |
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
Nuitka/Nuitka
Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.
steipete/CodexBar
Releases a signed, notarized CodexBar build: confirms the changelog, resolves signing credentials from 1Password, runs the release script in tmux, and updates the Sparkle appcast and Homebrew tap.
eugene1g/agent-safehouse
Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…
fzyzcjy/flutter_rust_bridge
A skill your agent uses when preparing, installing, diagnosing, or explaining the host Android Emulator environment for flutterrustbridge local runtime validation, including Android SDK command-line…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件. Re Java is an agent skill from dslsdzc/rev-skills.
Re Java fits situations like: security work in your project.
Run `npx skills add dslsdzc/rev-skills --skill re-java -a claude-code`. Or copy the skill folder (.claude/skills/re-java in dslsdzc/rev-skills) into .claude/skills/re-java in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-java -a codex`. Or copy the skill folder (.claude/skills/re-java in dslsdzc/rev-skills) into .agents/skills/re-java in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-java -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-java, .gemini/skills/re-java, .github/skills/re-java and .opencode/skills/re-java in your project.
Going by SKILL.md and its folder, Re Java needs the command-line tools its instructions call (java, brew, apt, dnf, curl and choco). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: benf.org and repo1.maven.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Java is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Java: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Mole CLI Release Flow (tw93/Mole, 69k stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars) and CodexBar macOS Release (steipete/CodexBar, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.