Agent skill

MCP JS Reverse Playbook

by haikow in haikow/claude-reverse-skills

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse 工具。

No licenceAuto-check passedAgent Workflows

Install MCP JS Reverse Playbook

skills CLI
$ npx skills add haikow/claude-reverse-skills --skill mcp-js-reverse-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install haikow/claude-reverse-skills mcp-js-reverse-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/haikow/claude-reverse-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-js-reverse-playbook .claude/skills/mcp-js-reverse-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-js-reverse-playbook
GitHub stars
114
Token cost
~771 tokens
SKILL.md length
166 words
Files
13 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse 工具。

  • Works in 5 steps: Observe → Capture → Rebuild → …
  • Tasks that involve MCP servers
  • SKILL.md covers 适用范围, 当前环境默认工具映射, 核心原则 and 五阶段工作流, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

MCP JS Reverse Playbook is an agent skill from haikow/claude-reverse-skills. 在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse 工具。

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `references/ast-deobfuscation.md`, `references/automation-entry.md` and `references/env-patching.md`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol and JavaScript. The repository describes itself as: Claude Code 逆向工程 skill 集合 (apk/ida/radare2/js) + IDA MCP 接入,跨平台 Linux/Mac/Windows.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/mcp-js-reverse-playbook”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Observe
  2. Capture
  3. Rebuild
  4. Patch
  5. DeepDive

What it can do on your machine

Read from SKILL.md and the folder at commit 8491b3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP JS Reverse Playbook loads about 771 tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 166 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~771
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 166 words (~771 tokens).

name
mcp-js-reverse-playbook

Read the full SKILL.md on GitHub

Files

SKILL.md and 12 other files (references) in skills/mcp-js-reverse-playbook of haikow/claude-reverse-skills.

  • SKILL.md
  • references/ast-deobfuscation.md
  • references/automation-entry.md
  • references/env-patching.md
  • references/fallbacks.md
  • references/instrumentation.md
  • references/local-rebuild.md
  • references/mcp-task-template.md
  • references/node-env-rebuild.md
  • references/output-contract.md
  • references/task-artifacts.md
  • references/task-input-template.md
  • references/tool-defaults.md

Open the folder on GitHubat commit 8491b3b

Compare with similar skills

MCP JS Reverse Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP JS Reverse Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP JS Reverse Playbook this skillhaikow/claude-reverse-skills114—~771Automated safety check: PassNone
Generate Codeful MCP Toolmicrosoft/power-platform-skills984—~3.1kAutomated safety check: NotesMIT
Build Audit Logsactivepieces/activepieces25k1 repos~5.9kAutomated safety check: PassCustom licence
SlintMoosync/Moosync259—~2.4kAutomated safety check: PassGPL-3.0
Browser Testing With Devtoolsshashankswe2020-ux/whoop-mcp165—~3kAutomated safety check: WarnMIT
Bright Data MCPbrightdata/skills2641 repos~3.7kAutomated safety check: PassMIT

Similar skills

  • Generate Codeful MCP Tool

    microsoft/power-platform-skills

    Official

    Generate a self-contained JavaScript server runtime and registration metadata for an MCP codeful tool.

    984 GitHub stars~3.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Build Audit Logs

    activepieces/activepieces

    Build or review audit trails in TypeScript/JavaScript apps using evlog (pipelines, typed actions, denials, retention, compliance-style reviews).

    25k GitHub starsUsed in 1 repo~5.9k tokens
    Productivity & AutomationAuto-check passed
  • Slint

    Moosync/Moosync

    Expert guidance for building, debugging, and working with Slint GUI applications.

    259 GitHub stars~2.4k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Browser Testing With Devtools

    shashankswe2020-ux/whoop-mcp

    Tests in real browsers. An agent skill from shashankswe2020-ux/whoop-mcp.

    165 GitHub stars~3k tokensUpdated yesterday
    Testing & QAAuto-check: warnings
  • Bright Data MCP

    brightdata/skills

    Bright Data MCP handles ALL web data operations. An agent skill from brightdata/skills.

    264 GitHub starsUsed in 1 repo~3.7k tokens
    Productivity & AutomationAuto-check passed
  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed

Categories

Questions about MCP JS Reverse Playbook

What does MCP JS Reverse Playbook do?

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse 工具。. MCP JS Reverse Playbook is an agent skill from haikow/claude-reverse-skills.

When should I use MCP JS Reverse Playbook?

MCP JS Reverse Playbook fits situations like: tasks that involve MCP servers.

How do I install MCP JS Reverse Playbook in Claude Code?

Run `npx skills add haikow/claude-reverse-skills --skill mcp-js-reverse-playbook -a claude-code`. Or copy the skill folder (skills/mcp-js-reverse-playbook in haikow/claude-reverse-skills) into .claude/skills/mcp-js-reverse-playbook in your project. Claude Code loads it when a task matches its description.

How do I install MCP JS Reverse Playbook in Codex?

Run `npx skills add haikow/claude-reverse-skills --skill mcp-js-reverse-playbook -a codex`. Or copy the skill folder (skills/mcp-js-reverse-playbook in haikow/claude-reverse-skills) into .agents/skills/mcp-js-reverse-playbook in your project. Codex loads it when a task matches its description.

Can I use MCP JS Reverse Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add haikow/claude-reverse-skills --skill mcp-js-reverse-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-js-reverse-playbook, .gemini/skills/mcp-js-reverse-playbook, .github/skills/mcp-js-reverse-playbook and .opencode/skills/mcp-js-reverse-playbook in your project.

What does MCP JS Reverse Playbook need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP JS Reverse Playbook is instructions for the agent only.

Does MCP JS Reverse Playbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP JS Reverse Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP JS Reverse Playbook use?

No licence was found for MCP JS Reverse Playbook or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does MCP JS Reverse Playbook use?

About 771 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 814 tokens, read only when the agent opens those files.

What are the alternatives to MCP JS Reverse Playbook?

Skills that share tags, products or a category with MCP JS Reverse Playbook: Generate Codeful MCP Tool (microsoft/power-platform-skills, 984 stars), Build Audit Logs (activepieces/activepieces, 25k stars), Slint (Moosync/Moosync, 259 stars) and Browser Testing With Devtools (shashankswe2020-ux/whoop-mcp, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP JS Reverse Playbook?

haikow (a GitHub user) maintains it in haikow/claude-reverse-skills, which has 114 GitHub stars. The repository was last updated on June 30, 2026.

Source: haikow/claude-reverse-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.