Kernel Corpus Analysis
kernullist/PseudoForge
A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills js-reverse --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/js-reverse .claude/skills/js-reverse && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .claude/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills js-reverse --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/js-reverse .agents/skills/js-reverse && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .agents/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills js-reverse --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/js-reverse .cursor/skills/js-reverse && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .cursor/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/js-reverse--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills js-reverse --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/js-reverse .gemini/skills/js-reverse && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .gemini/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills js-reverseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/js-reverse .github/skills/js-reverse && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .github/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills js-reverse --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/js-reverse .opencode/skills/js-reverse && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "js-reverse" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/js-reverse into .opencode/skills/js-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-reverse", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
js-reverseFront-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.
JS Reverse is an agent skill from sickn33/agentic-awesome-skills. Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `references/ast-deobfuscation.md`, `references/automation-entry.md` and `references/env-patching.md`).
It sits in Security, covering Reverse engineering and malware. It works with JavaScript and Model Context Protocol. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are powershell).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
JS Reverse loads about 1.8k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 500 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 500 words, ~1,803 tokens.
.claude/skills/js-reverse/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
当任务属于以下场景时优先使用本 skill:
如果目标是二进制、APK、PE、ELF、DLL、SO,请改用 ida-reverse、radare2 或 reverse-engineering。
本 skill 不假设存在裸工具名,而是默认绑定当前客户端环境里可用的 js-reverse_* 工具。
如果当前任务明确提到 jshookmcp、JS hook、CDP、浏览器断点、网络拦截、SourceMap 或 AST 去混淆,也仍然走本 skill;只是把底层 MCP 面切到 jshookmcp,而不是把它当成一个新的总入口。
前提条件:jshookmcp 不是本地裸命令工具,而是一个要先下载、显式注册并启用的 MCP server。只有在所选客户端(Claude、Codex 等)的 MCP 配置里接入并启用后,相关工具面才真的可调用。
常用映射:
list_scripts -> js-reverse_list_scriptsget_script_source -> js-reverse_get_script_sourcesearch_in_sources -> js-reverse_search_in_sourcesbreak_on_xhr -> js-reverse_break_on_xhrevaluate_script -> js-reverse_evaluate_scriptget_paused_info -> js-reverse_get_paused_infoset_breakpoint_on_text -> js-reverse_set_breakpoint_on_textlist_network_requests -> js-reverse_list_network_requestsget_request_initiator -> js-reverse_get_request_initiatorget_websocket_messages -> js-reverse_get_websocket_messagestake_screenshot -> js-reverse_take_screenshotnew_page -> js-reverse_new_pagenavigate_page -> js-reverse_navigate_pageselect_page -> js-reverse_select_pageselect_frame -> js-reverse_select_framepause/resume -> js-reverse_pause_or_resume如果未来工具名前缀变化,先更新本节,不要在执行时临时猜测。
js-reverse 的增强执行面,不是独立总控@jshookmcp/jshook 下载并注册到 MCP 客户端配置里,然后确保该 server 已启用Observe → Capture → Rebuild 执行,只是在 Observe/Capture 阶段优先调用 jshookmcp 的浏览器与 Hook 能力Observe-firstHook-preferredBreakpoint-lastRebuild-orientedEvidence-first先页面观察,再最小化采样,再做本地补环境,不要跳过取证直接猜环境。
目标:先确认目标请求、相关脚本、候选函数,不猜环境。
默认动作:
js-reverse_new_page 或 js-reverse_navigate_page 打开目标页面js-reverse_list_network_requests 找目标请求js-reverse_get_request_initiator 回溯调用来源js-reverse_list_scripts、js-reverse_search_in_sources 缩小脚本范围必须产出:
目标:对目标请求做最小侵入采样,拿到参数样例、调用顺序、运行时证据。
规则:
js-reverse_break_on_xhrjs-reverse_evaluate_script 做轻量运行时观察js-reverse_get_paused_infojs-reverse_set_breakpoint_on_text目标:把页面证据整理成本地可迭代的 Node 复现材料。
规则:
window/document/navigator/crypto/storage目标:按报错和 first divergence 驱动补环境,直到本地脚本稳定跑出目标参数。
规则:
目标:本地跑通后,再做去混淆、控制流还原、业务逻辑提纯。
规则:
E-js-vmp;CFF+字符串数组(AE)→ E-js-deobf;DevTools/debugger 反调试(AF)→ E-js-anti-debug。完整触发表见 ../reverse-engineering/references/nonpe-format-cookbook.md;AST 细节仍用 references/ast-deobfuscation.mdjs-reverse_* 或 jshookmcp 的现成 MCP 能力直接取证,不要先写脚本重造能力references/fallbacks.md 回退references/output-contract.mdreferences/automation-entry.mdreferences/tool-defaults.mdreferences/task-input-template.mdreferences/mcp-task-template.mdreferences/task-artifacts.mdreferences/local-rebuild.mdreferences/env-patching.mdreferences/node-env-rebuild.mdreferences/instrumentation.mdreferences/ast-deobfuscation.md../reverse-engineering/references/nonpe-format-cookbook.md(AD/AE/AF)references/fallbacks.mdreferences/output-contract.md上游入口: skills/SKILL.md(总控)、routing.md
上游备选:
reverse-engineering/SKILL.md(如果目标不是前端 JS)下游出口:
references/env-patching.mdreferences/local-rebuild.md / references/node-env-rebuild.mdreferences/ast-deobfuscation.mdreferences/fallbacks.md同级关联模块: anything-analyzer MCP(浏览器自动化和 HTTP 捕获能力可以互补)
本 skill 依赖的 MCP 能力可通过统一自举系统安装;MCP 客户端注册必须显式选择目标,默认不会写任何客户端全局配置。
| 能力 | 可自动注册 | 方式 | 说明 |
|---|---|---|---|
| jshookmcp | ✓ | npm-mcp(npx 启动) | 显式选择 Claude / Codex / Both 后注册 |
| anything-analyzer | ✓ | local-http-mcp | 可自动启动服务;客户端注册须显式选择 |
| Node.js | ✓ | winget 安装 | 运行时依赖 |
# 安装并注册 jshookmcp;Codex 可替换为 Claude 或 Both
powershell -File "<skill-root>\scripts\bootstrap-reverse.ps1" -Capability @('jshookmcp') -McpHostTarget Codex
# 注册并启动 anything-analyzer
powershell -File "<skill-root>\scripts\bootstrap-reverse.ps1" -Capability @('anything-analyzer') -StartServices -McpHostTarget Codexjshookmcp 注册后仍需在 AI 客户端中启用该 MCP server 才能调用-McpHostTarget 时只安装/准备能力并返回 registration-required,不修改 Claude 或 Codex 配置anything-analyzer 需要 pnpm 和项目源码,bootstrap 会自动 clone 并安装依赖<br><br>## 任务完成自检(声称完成前 MUST 通过)
tool-index 使用了真实工具路径?Adapted from zhaoxuya520/reverse-skill (MIT).
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 12 other files (references) in skills/js-reverse of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 1e53ce2
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
JS Reverse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| JS Reverse this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Kernel Corpus Analysiskernullist/PseudoForge | 162 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Dsl Vm Reversezhaoxuya520/reverse-skill | 40k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Tiktok Account Auditaronhy/tiktok-agent-skills | 167 | — | ~492 | Automated safety check: Pass | MIT | |
| Rev Unicorn Debugindex-login/MobileRE-Skill | 111 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Karpathy Guidelinesindex-login/MobileRE-Skill | 111 | — | ~242 | Automated safety check: Pass | MIT |
kernullist/PseudoForge
A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…
zhaoxuya520/reverse-skill
Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.
aronhy/tiktok-agent-skills
A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research…
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
index-login/MobileRE-Skill
减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。
pardeike/DecompilerServer
A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Works with
Categories
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output. JS Reverse is an agent skill from sickn33/agentic-awesome-skills. Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.
JS Reverse fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a claude-code`. Or copy the skill folder (skills/js-reverse in sickn33/agentic-awesome-skills) into .claude/skills/js-reverse in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a codex`. Or copy the skill folder (skills/js-reverse in sickn33/agentic-awesome-skills) into .agents/skills/js-reverse in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill js-reverse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/js-reverse, .gemini/skills/js-reverse, .github/skills/js-reverse and .opencode/skills/js-reverse in your project.
SKILL.md names no scripts, command-line tools or credentials: JS Reverse is instructions for the agent only. Our summary lists: Node.js.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
JS Reverse is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 814 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with JS Reverse: Kernel Corpus Analysis (kernullist/PseudoForge, 162 stars), Dsl Vm Reverse (zhaoxuya520/reverse-skill, 40k stars), Tiktok Account Audit (aronhy/tiktok-agent-skills, 167 stars) and Rev Unicorn Debug (index-login/MobileRE-Skill, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.