Agent skill

Case Review

by sickn33 in sickn33/agentic-awesome-skills

Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes.

MITAuto-check passedSecurity

Install Case Review

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill case-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills case-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/case-review .claude/skills/case-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
case-review
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
665 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes.

  • Works in 4 steps: Intake → Traceability → Fixity verification → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers When to Use, Scope, Tool dependencies and Workflow, plus 10 more sections
  • Calls python3

What it does

Case Review is an agent skill from sickn33/agentic-awesome-skills. Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware and Quality gates. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Reverse engineering and malware
  • Tasks that involve Quality gates

Example prompts

  • “/case-review”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Intake
  2. Traceability
  3. Fixity verification
  4. Handoff

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • swgde.org
    • csrc.nist.gov
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Case Review loads about 1.6k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 665 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 665 words, ~1,611 tokens.

Download SKILL.mdSave it as .claude/skills/case-review/SKILL.md (or your agent's skills folder).
name
case-review
description
Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes.
risk
safe
source
https://github.com/zhaoxuya520/reverse-skill
source_repo
zhaoxuya520/reverse-skill
source_type
community
date_added
2026-08-25
license
MIT
license_source
https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE

Evidence Graph Review

When to Use

  • Before delivering an analysis report, verify traceability and completeness.
  • Auditing whether conclusions are backed by recorded evidence.

Use this skill when a reverse engineering, forensics, CTF, or authorized security case needs a defensible handoff. It audits the existing work/<case>/ package without changing the case or touching a target.

Scope

This skill covers:

  • Scope metadata and target-activity readiness
  • Evidence record structure and reproducibility fields
  • References from work items and timeline entries to Evidence
  • Structured Findings and Paths in report Markdown
  • Optional SHA-256 verification for case-local artifacts
  • A Markdown or JSON review result for a report handoff

It MUST NOT perform reconnaissance, exploitation, dynamic instrumentation, or target changes. Those actions belong to the routed analysis skill and require the case scope gate.

Tool dependencies

ToolRequiredPurposeAuto-bootstrap
Python 3.9+YesRuns the read-only case review scriptNo, use the platform Python installation

No network access or third-party package is required.

Workflow

Phase 1: Intake

Run the review against the existing case directory:

bash
python3 skills/case-review/scripts/review_case.py work/<case> --format markdown

Confirm that scope.md, timeline.md, workitems.md, and evidence/ are present. A non-strict review reports scope warnings while a strict review treats warnings as handoff blockers.

建议下一步(选一个编号)

  1. 修复 scope.md 中的授权、范围或 network_profile 字段
  2. 继续检查 Evidence 记录的可复现命令和来源
  3. 导出当前 review 结果并附到阶段性报告
  4. 换 JSON 输出接入 CI 或其他审查工具
  5. 暂停,先确认审查范围
Phase 2: Traceability

Review the checks for:

  • Evidence IDs that do not exist
  • Findings without evidence_ids
  • Paths without an allowed path_type or Evidence reference
  • Work items and timeline entries pointing to unknown Evidence
  • Unlinked Evidence records
  • Validated Findings with low confidence

An offline observation may use repro_command: n/a only when its notes field explicitly documents the offline limitation.

Use JSON when another tool needs stable fields:

bash
python3 skills/case-review/scripts/review_case.py work/<case> --format json

建议下一步(选一个编号)

  1. 补写缺失的 Evidence,并保留原始命令
  2. 将候选 Finding 绑定到 Evidence 后重新审查
  3. 为调用链或攻击链补充 P-id 和 Path 步骤
  4. 生成 Markdown handoff summary
  5. 换回 PRIMARY skill 继续分析
Phase 3: Fixity verification

When an Evidence record contains both content_hash and artifact_path, verify the case-local artifact:

bash
python3 skills/case-review/scripts/review_case.py work/<case> --verify-hashes --strict

The script accepts sha256:<64 hex characters> and checks that the artifact remains inside the case root. A hash mismatch is a hard failure.

The PowerShell Evidence helper can record a hash while appending a record:

powershell
powershell -File skills/scripts/append-evidence.ps1 -CaseRoot work\<case> -Id E-001 -Title "Sample hash" -ReproCommand "sha256sum evidence/sample.bin" -ArtifactPath "evidence\sample.bin"

建议下一步(选一个编号)

  1. 修复 hash mismatch 或替换已污染的工作副本
  2. 为未固定的原始文件补充 SHA-256 和 artifact_path
  3. 继续进入报告生成阶段
  4. 导出 JSON 结果供 CI 保存
  5. 暂停并请求人工复核
Show full SKILL.md (286 more words)Show less
Phase 4: Handoff

Use strict mode before a final report or specialist handoff:

bash
python3 skills/case-review/scripts/review_case.py work/<case> --strict --format markdown > work/<case>/report/case-review.md

The command is read-only with respect to the case unless shell redirection is explicitly used to save its output. The review is not legal advice and does not replace organizational evidence handling procedures.

建议下一步(选一个编号)

  1. 将通过的 review 结果交给 docs-generator/ 生成正式报告
  2. 回到 PRIMARY skill 补齐新的分析证据
  3. 归档 Markdown 和 JSON review 结果
  4. 暂停并请求人工复核

Language behavior contract

  • Internal reasoning, tool selection, and phase control: English.
  • User-visible messages, section labels, reports, and next-step menus: Chinese unless the user requests another language.
  • Default bilingual labels place Chinese first and English second, separated by /.

Bootstrap boundary

This skill has no third-party dependency. If Python 3 is unavailable, the only allowed recovery action is the repository bootstrap path when a Python capability is registered for the current platform. If no such capability is registered, stop and report the missing runtime. Do not guess executable paths, download packages, or perform a manual install from inside this skill.

Routing context

Upstream entry: any reverse, forensics, CTF, or authorized security skill that has produced a case package.

Downstream exit: docs-generator/ for a formal report, or the original PRIMARY skill when the graph is incomplete.

Related modules: ops/evidence-finding-path.md, ops/timeline-workitem.md, digital-forensics/, reverse-engineering/, and docs-generator/.

References

任务完成自检

  • 我是否审查了 scope.md、timeline.md、workitems.md 和 evidence/?
  • 所有 Finding 是否引用了现存 Evidence?
  • 所有 Path 是否包含合法 path_type 和 Evidence 引用?
  • 是否执行了 hash verification,或记录了未执行原因?
  • 是否以 strict 模式重新运行并保存了 review 结果?

Limitations

  • Expects a structured case layout (scope, evidence, findings); ad-hoc notes need pre-organization.
  • Reviews documentation quality, not the technical correctness of findings.

Adapted from zhaoxuya520/reverse-skill (MIT).

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/case-review of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Case Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Case Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Case Review this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Case Review

What does Case Review do?

Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes. Case Review is an agent skill from sickn33/agentic-awesome-skills. Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes.

When should I use Case Review?

Case Review fits situations like: tasks that involve Reverse engineering and malware; tasks that involve Quality gates.

How do I install Case Review in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill case-review -a claude-code`. Or copy the skill folder (skills/case-review in sickn33/agentic-awesome-skills) into .claude/skills/case-review in your project. Claude Code loads it when a task matches its description.

How do I install Case Review in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill case-review -a codex`. Or copy the skill folder (skills/case-review in sickn33/agentic-awesome-skills) into .agents/skills/case-review in your project. Codex loads it when a task matches its description.

Can I use Case Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill case-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/case-review, .gemini/skills/case-review, .github/skills/case-review and .opencode/skills/case-review in your project.

What does Case Review need to run?

Going by SKILL.md and its folder, Case Review needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Case Review access the network?

SKILL.md names 3 domains. As links in the text: swgde.org, csrc.nist.gov and github.com. This is read from the text; nothing was executed.

Is Case Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Case Review use?

Case Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Case Review use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Case Review?

Skills that share tags, products or a category with Case Review: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Case Review?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.