Agent skill

Re Java

by dslsdzc in dslsdzc/rev-skills

Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件

Apache-2.0Auto-check passedSecurity

Install Re Java

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-java -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-java --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-java .claude/skills/re-java && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-java
GitHub stars
117
Token cost
~1.4k tokens
SKILL.md length
423 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件

  • Works in 5 steps: jar/war 解包 → 类结构识别 → 逻辑还原(CFR / JD-GUI) → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls java, brew and apt; reaches benf.org and repo1.maven.org

What it does

Re Java is an agent skill from dslsdzc/rev-skills. Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Java, Homebrew and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-java”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. jar/war 解包
  2. 类结构识别
  3. 逻辑还原(CFR / JD-GUI)
  4. 混淆识别与字符串解密
  5. 动态(可选;沙箱内执行 [[re-sandbox]])

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • java
    • brew
    • apt
    • dnf
    • curl
    • choco

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • benf.org
    • repo1.maven.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Java loads about 1.4k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 423 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 423 words, ~1,409 tokens.

Download SKILL.mdSave it as .claude/skills/re-java/SKILL.md (or your agent's skills folder).
name
re-java
description
Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件
capabilities
bytecode-parser

Java 字节码逆向(CFR / JD-GUI / javap)

何时使用 / 何时不用

  • 用:jar/war/class 样本还原 Java 逻辑;定位注册码/密钥/网络逻辑;处理 ProGuard/Allatori 混淆与 Java 加固
  • 用:恶意 Java 样本([[re-malware]] → [[re-managed]] 路径)静态还原
  • 不用:Android DEX 直接分析([[re-apk]];转成 jar 后可回本技能)
  • 不用:非 Java(.NET 走 [[re-dotnet]]、脚本走 [[re-script-deob]]、native 走 [[re-binary-core]])
  • 注意:动态步骤默认沙箱([[re-analyze/platform-tips]] 最高原则);解包产物先备份

工具准备

参考 [[re-analyze/platform-tips]]——反编译/解包为静态步骤,免沙箱;动态验证按最高原则进沙箱。

JDK(javap / jar / java 运行时)
  • Debian/Ubuntu: apt install openjdk-17-jdk
  • Fedora: dnf install java-17-openjdk;Arch: pacman -S jdk17-openjdk
  • macOS: brew install openjdk(或 brew install --cask temurin)
  • Windows: choco install temurin 或官方安装器
  • 验证: java -version && javap -version
unzip(jar = zip 容器)
  • Linux: apt install unzip / dnf install unzip / pacman -S unzip;macOS: brew install unzip
  • 验证: unzip -v
CFR(jar CLI 反编译器,零依赖)
  • 下载(无依赖,只需 JRE): curl -L -o cfr.jar https://www.benf.org/other/cfr/cfr-0.152.jar
  • 验证: java -jar cfr.jar --help
JD-GUI(GUI 反编译器)
  • GitHub java-decompiler/jd-gui release zip → 解压,Linux/macOS: java -jar jd-gui-1.6.6.jar(zip 内含各平台可执行)
  • 验证: GUI 启动并能 File > Open 打开 jar
procyon(备选反编译器)
  • Maven Central: curl -L -o procyon-decompiler.jar https://repo1.maven.org/maven2/org/bitbucket/mstrobel/procyon-decompiler/0.6.0/procyon-decompiler-0.6.0.jar
  • 验证: java -jar procyon-decompiler.jar --help

操作步骤

按顺序执行,每步记录证据(路径 + sha256,见 [[re-triage]])。

  1. jar/war 解包:

    sh
    jar tf app.jar                 # 先看清单(JDK 自带 jar 工具)
    unzip -o app.jar -d unpacked/
    unzip -p app.jar META-INF/MANIFEST.MF   # Main-Class / 加固标记
    • war: 类在 WEB-INF/classes/,依赖在 WEB-INF/lib/
    • fat jar(Spring Boot): 类在 BOOT-INF/classes/,嵌套依赖 BOOT-INF/lib/*.jar 需逐个解
    • aar(Android): 内含 classes.jar,解出后再按本技能处理
    • Multi-Release jar: 同路径多版本类在 META-INF/versions/N/(N=9/11/17…)下覆盖——运行时按 JDK 选版加载,逆向按目标 JDK 看对应层,别只看顶层
  2. 类结构识别:

    sh
    javap -c -p unpacked/com/example/Main.class    # 字节码(-c)+ 私有成员(-p)
    javap -v unpacked/com/example/Main.class       # 常量池/元数据
    • 找入口:MANIFEST.MF 的 Main-Class → javap -c -p <入口类> 看 main 逻辑
    • 混淆程序集先看类名是否可读(a/b/c → 步骤 4)
    • class 文件头速查:xxd -l 8 <类>.class → CA FE BA BE + minor(2) + major(2);Java 版本 = major − 44(52=Java 8、55=11、61=17、65=21,实测 JDK 21 产物 major=65);javap -v 首行直接打印 minor/major
    • 常量池:计数在 major 之后(u16,索引 0 占位),javap -v 列条目类型(String/Class/NameAndType/Methodref/Utf8 等)——字符串字面量、类名、签名全在常量池,混淆样本的明文串先在这里找
  3. 逻辑还原(CFR / JD-GUI):

    sh
    java -jar cfr.jar app.jar --outputdir cfr_out/           # 整包还原为 Java 源码
    java -jar cfr.jar unpacked/com/example/Main.class        # 单类还原
    java -jar procyon-decompiler.jar -jar app.jar -o procyon_out/   # 备选
    • JD-GUI: File > Open → 左侧树浏览 → File > Save All Sources 导出
    • 关键类/方法用两个反编译器交叉验证(CFR 对 lambda/现代字节码还原更好,JD-GUI 对老代码更顺)
  4. 混淆识别与字符串解密:

    • ProGuard: 类/方法名全变 a/b/c、javap -l 无 LineNumberTable/LocalVariableTable(调试信息被剥)
    • Allatori: 反编译产物出现 com.allatori.* 水印类、StringEncryptor 调用(字符串加密)
    • ZKM(Zelix KlassMaster): com.zelix.* 类特征
    • 检测: grep -rn 'StringEncryptor\|decrypt(' cfr_out/ | head
    • 字符串加密处理:定位解密类与算法(key/变换方式)→ python3 复刻批量还原;或动态取明文(步骤 5,沙箱内)——先静态还原,静态卡住再动态
  5. 动态(可选;沙箱内执行 [[re-sandbox]]):

    • JDB(桌面 JVM):
      sh
      jdb -classpath app.jar com.example.Main
      > stop in com.example.Main.checkKey     # 下断点
      > print key                             # 取变量
      > eval new com.example.Util().decrypt("密文")   # 直接调用解密方法取明文
    • Frida(Android Java 应用,转 [[re-mobile]]/[[re-apk]] 域):
      js
      Java.perform(function () {
        var c = Java.use("com.example.Main");
        c.checkKey.implementation = function (k) {
          console.log("key = " + k);
          return this.checkKey(k);
        };
      });
    • 桌面 JVM 无 Frida Java API → 用 JDB / 自写 Java agent
Show full SKILL.md (123 more words)Show less

跨域联合

  • [[re-managed]]:网关工作流步骤②(反编译)③(去混淆)固定调用本技能
  • [[re-malware]]:Java 恶意样本路径(re-malware → re-managed → 本技能静态还原)
  • Android 侧:[[re-apk]] / [[re-mobile]](DEX 转 jar 后可回本技能);动态 [[re-frida]](Android)
  • 底座 [[re-binary-core]]:初勘([[re-triage]]);native/JNI 部分

常见坑与陷阱

  • ProGuard 改名后靠字符串交叉引用:现象——反编译全是 a/b/c 类、a(...) 方法,无法定位目标逻辑;原因——ProGuard shrink+obfuscate 重命名抹掉语义;对策——从字符串入手:grep 明文 URL/提示语 → 在反编译产物里找引用它的类(grep -rn "提示语" cfr_out/)→ 沿调用链恢复语义
  • Allatori/字符串加密需先解密:现象——反编译只见 StringEncryptor.decrypt("...") 调用,看不到任何明文;原因——字符串运行时才解密;对策——静态定位解密算法与 key → python3 复刻批量还原;或动态在解密调用后取明文(JDB eval / Frida),沙箱内执行
  • 反编译不完全正确:现象——CFR/JD-GUI 输出语法错误、goto/label 混乱、try-catch 结构诡异、lambda 还原失败;原因——字节码到 Java 不存在无损还原;对策——对照 javap -c -p 字节码手工修正,多反编译器交叉验证
  • Java 加固(如 Virbox)类似壳需先脱:现象——JD-GUI 打开报错/空白、javap 输出损坏、文件头非标准;原因——加固器加密 class 字节码、运行时才解密(本质是壳);对策——先脱加固:运行时 dump class(attach agent / 专用脱壳工具为主;-Xbootclasspath 仅 JDK 8 可用,JDK 9+ 已移除该选项)→ 对脱出的标准 class 再反编译;思路同 [[re-anti-analysis]] 的"先脱壳后分析"
  • javap 报 unsupported class file version:现象——javap 报 major version 65 之类不支持;原因——class 文件版本高于本机 JDK 工具版本;对策——按 major−44 换算目标 Java 版本,装对应或更新的 JDK;只读版本与常量池可先用 xxd 手工看头字段,不必等工具
  • Multi-Release jar 分析错层:现象——unzip -o 解出顶层类后反编译,逻辑与运行时行为不符(版本分支消失);原因——多版本类在 META-INF/versions/N/,不同 JDK 加载不同层;对策——解包后检查 META-INF/versions/,按目标 JDK 选层分析;顶层与 versions 层的差异就是版本条件逻辑
  • lambda 反编译出现合成方法:现象——CFR/JD-GUI 输出 lambda$xxx$n 方法或 invokedynamic 调用;原因——lambda 体编译为合成私有方法 + invokedynamic 引导;对策——javap -v -p 的 BootstrapMethods 表定位 lambda 体方法(捕获变量在合成方法参数里),按普通方法分析即可

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-java of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Java next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Java compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Java this skilldslsdzc/rev-skills117—~1.4kAutomated safety check: PassApache-2.0
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Mole CLI Release Flowtw93/Mole69k—~2.5kAutomated safety check: PassGPL-3.0
Reproduce macOS Python FlavorsNuitka/Nuitka15k—~1.7kAutomated safety check: PassAGPL-3.0
CodexBar macOS Releasesteipete/CodexBar22k—~1.5kAutomated safety check: PassMIT
Releaseeugene1g/agent-safehouse2.1k—~3.5kAutomated safety check: PassApache-2.0

Similar skills

  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.

    15k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CodexBar macOS Release

    steipete/CodexBar

    Releases a signed, notarized CodexBar build: confirms the changelog, resolves signing credentials from 1Password, runs the release script in tmux, and updates the Sparkle appcast and Homebrew tap.

    22k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release

    eugene1g/agent-safehouse

    Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…

    2.1k GitHub stars~3.5k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Frb Android Emulator Prepare

    fzyzcjy/flutter_rust_bridge

    A skill your agent uses when preparing, installing, diagnosing, or explaining the host Android Emulator environment for flutterrustbridge local runtime validation, including Android SDK command-line…

    5.4k GitHub stars~2.1k tokensUpdated yesterday
    MobileAuto-check: notes

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Re Java

What does Re Java do?

Java 字节码逆向:CFR/JD-GUI、jar 解包、Java 加固。触发词:Java、jar、字节码、JD-GUI、CFR、class文件. Re Java is an agent skill from dslsdzc/rev-skills.

When should I use Re Java?

Re Java fits situations like: security work in your project.

How do I install Re Java in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-java -a claude-code`. Or copy the skill folder (.claude/skills/re-java in dslsdzc/rev-skills) into .claude/skills/re-java in your project. Claude Code loads it when a task matches its description.

How do I install Re Java in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-java -a codex`. Or copy the skill folder (.claude/skills/re-java in dslsdzc/rev-skills) into .agents/skills/re-java in your project. Codex loads it when a task matches its description.

Can I use Re Java in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-java -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-java, .gemini/skills/re-java, .github/skills/re-java and .opencode/skills/re-java in your project.

What does Re Java need to run?

Going by SKILL.md and its folder, Re Java needs the command-line tools its instructions call (java, brew, apt, dnf, curl and choco). Our summary lists: Python 3.

Does Re Java access the network?

SKILL.md names 2 domains. In commands or code: benf.org and repo1.maven.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Re Java safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Java use?

Re Java is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Java use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Java?

Skills that share tags, products or a category with Re Java: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Mole CLI Release Flow (tw93/Mole, 69k stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars) and CodexBar macOS Release (steipete/CodexBar, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Java?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.