Chrome Devtools Axi
layer5io/sistent
Control a Chrome browser session through the chrome-devtools-axi CLI - navigate, snapshot, click, fill forms, run JavaScript, inspect console and network, take screenshots, audit performance.
Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .claude/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .claude/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascriptType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .agents/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .agents/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .cursor/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .cursor/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/reversing-obfuscated-javascript--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .gemini/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .gemini/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills reversing-obfuscated-javascriptInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .github/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .github/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .opencode/skills/reversing-obfuscated-javascript && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reversing-obfuscated-javascript" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/reversing-obfuscated-javascript into .opencode/skills/reversing-obfuscated-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reversing-obfuscated-javascript", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reversing-obfuscated-javascriptReverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…
Reversing Obfuscated Javascript is an agent skill from trilwu/secskills. Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow obfuscation with webcrack/synchrony/restringer, and locating a signing or crypto routine in a live bundle via Chrome DevTools. Use when a page ships a huge minified bundle, when code is full of 0x hex identifiers and a rotated string array, when a .js.map is reachable, or when you must find where a request signature or token…
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Browser testing. It works with JavaScript, webpack and Chrome DevTools. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reversing Obfuscated Javascript loads about 2.3k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 1,188 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,188 words, ~2,278 tokens.
.claude/skills/reversing-obfuscated-javascript/SKILL.md (or your agent's skills folder).Client-side JavaScript ships the whole program to the reader — there is no stripped binary here, only code deliberately made unreadable. That changes the job: you are almost never recovering missing information, you are undoing a transformation. Identify the transformation first, reverse it with the tool built for it, and fall back to hand-written AST passes only for the custom layer no off-the-shelf tool knows.
.js you need to read_0x1234 identifiers, a big string array, and a rotation IIFE
at the top — the obfuscator.io signature.js.map sourcemap is reachable, or webpack left //# sourceMappingURLindex.android.bundle,
main.jsbundle, Hermes magic bytes) — use reversing-react-native-apps.unpacking-protected-binaries for the VM-lifting approach.hunting-web-backdoors for planted web
payloads and auditing-supply-chain for a malicious package.testing-web-applications; come back here only to recover a client-side
algorithm it needs.analyzing-binaries territory.Running the wrong deobfuscator produces plausible garbage. Read the first few hundred bytes and classify:
| What you see | Transformation | Reverse it with |
|---|---|---|
| Short names, no whitespace, readable strings | Minification only | An unminifier / prettier + rename |
webpackChunk, a module map {123: function(e,t,n){…}} | Webpack/Rollup bundling | Unbundle to per-module files |
//# sourceMappingURL=… or a reachable .map | Nothing — the source is right there | Sourcemap recovery |
_0x hex names + one big string array + a rotation IIFE | obfuscator.io string-array | webcrack / synchrony / restringer |
Nested ternaries, while(true){switch(_0x..)} dispatcher | Control-flow flattening | AST pass to relink the switch |
debugger in a setInterval, self-defending function | Anti-debug / self-defense | Strip the guard before other passes |
Most real bundles are layered: webpack on the outside, obfuscator.io on a few modules, a hand-rolled string cipher on the one function that matters. Peel outermost first.
A reachable sourcemap ends the job before it starts — it contains the original, pre-transform source. Check for it every time, because a large fraction of "obfuscated" production bundles ship or leak one:
//# sourceMappingURL= comment at the bundle's end, and the sibling
.js.map even when the comment was stripped (try <bundle>.map).webpack:// paths inside the map.unwebpack-sourcemap or a short
source-map script walks sourcesContent back to a directory tree.Treat a leaked production sourcemap as a finding in its own right when you are assessing the app, not just a convenience.
webcrack is the first tool for a bundle, because it does three of the
layers at once: unminify, unpack webpack/browserify into per-module files, and
undo obfuscator.io string-array and control-flow obfuscation. Run it, then read
the module tree it produces rather than the single blob.
For a bundle that is only obfuscator.io, a dedicated deobfuscator is often
cleaner: synchrony or restringer both resolve the string array,
reverse the rotation, inline the decoder calls, and flatten the trivial control
flow. Compare their output — they fail on different edge cases.
When no tool fully handles the custom layer, write an AST pass with Babel:
parse to an AST, @babel/traverse to find the pattern (a specific decoder call,
a constant-folded expression, the flattening dispatcher), transform the nodes,
and regenerate. This is the durable skill — obfuscators change, but string-array
decoding, constant folding, and dead-branch elimination are the same AST
operations every time. Prototype the matcher in AST Explorer against the real
code before scripting it.
Two failure modes to expect:
eval an unknown
bundle on your host to read it.debugger
loop when tampered with. Strip the guard function first (delete the node,
or override setInterval) or every downstream pass fights it.When static reading is slow — a signing function buried in a megabyte of modules — drive the running page with Chrome DevTools instead:
{}) makes a minified function
steppable without any offline work.Object.defineProperty or a
Proxy on the object whose method computes the value logs every call and
argument with a stack trace, so you see inputs and outputs without reading
the math.console.log-instrumented
copy (DevTools Local Overrides) to watch the real values flow at runtime.Runtime observation and static reading are complementary: DevTools tells you which function matters; the AST work tells you what it computes so you can reproduce it offline.
Reading and deobfuscating a bundle you lawfully retrieved is analysis. Two
edges need care. Reproducing and replaying a request-signing routine against
the origin — the usual reason to reverse an anti-bot signal — acts against that
service and needs the same authorization as any other testing; keep it to
systems you are permitted to test, and see testing-web-applications. And a
sourcemap or bundle pulled from a third-party site is that party's code:
recovering it for a security assessment you are engaged to do is fine, lifting a
proprietary algorithm for reuse is a different matter.
webcrack run turns hours into minutes. Hand-reading is
the last resort, not the first move.reversing-react-native-apps — Hermes/RN mobile JS bundlesunpacking-protected-binaries — VM-based / virtualized obfuscationhunting-web-backdoors — malicious planted web JStesting-web-applications — testing the endpoints a recovered algorithm callsreviewing-cryptography — once a client-side crypto/signing routine is recovered© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/reversing-obfuscated-javascript of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Reversing Obfuscated Javascript next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reversing Obfuscated Javascript this skilltrilwu/secskills | 156 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Chrome Devtools Axilayer5io/sistent | 138 | 2 repos | ~989 | Automated safety check: Pass | Apache-2.0 | |
| Browser Tools981377660LMT/algorithm-study | 278 | 1 repos | ~1.3k | Automated safety check: Pass | None | |
| Idleon Live CdpMrJoiny/Idleon-Injector | 112 | — | ~1.2k | Automated safety check: Pass | None | |
| Chrome Devtoolseinverne/dotfiles | 121 | 1 repos | ~1.6k | Automated safety check: Notes | Apache-2.0 | |
| Browser Testing With Devtoolsshashankswe2020-ux/whoop-mcp | 166 | — | ~3k | Automated safety check: Warn | MIT |
layer5io/sistent
Control a Chrome browser session through the chrome-devtools-axi CLI - navigate, snapshot, click, fill forms, run JavaScript, inspect console and network, take screenshots, audit performance.
981377660LMT/algorithm-study
Interactive browser automation via Chrome DevTools Protocol.
MrJoiny/Idleon-Injector
Inspect and interact with a running Legends of Idleon session through the Chrome DevTools Protocol on port 32123.
einverne/dotfiles
Browser automation, debugging, and performance analysis using Puppeteer CLI scripts.
shashankswe2020-ux/whoop-mcp
Tests in real browsers. An agent skill from shashankswe2020-ux/whoop-mcp.
gronxb/codex-relay
Chrome DevTools Protocol CLI workflow for runtime, console, network, trace, memory, and JavaScript CPU profiling analysis.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…. Reversing Obfuscated Javascript is an agent skill from trilwu/secskills.io string-array and control-flow obfuscation with webcrack/synchrony/restringer, and locating a signing or crypto routine in a live bundle via Chrome DevTools.
Reversing Obfuscated Javascript fits situations like: A page ships a huge minified bundle; code is full of 0x hex identifiers and a rotated string array; A .js.map is reachable; you must find where a request signature.
Run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a claude-code`. Or copy the skill folder (secskills-core/skills/reversing-obfuscated-javascript in trilwu/secskills) into .claude/skills/reversing-obfuscated-javascript in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a codex`. Or copy the skill folder (secskills-core/skills/reversing-obfuscated-javascript in trilwu/secskills) into .agents/skills/reversing-obfuscated-javascript in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reversing-obfuscated-javascript, .gemini/skills/reversing-obfuscated-javascript, .github/skills/reversing-obfuscated-javascript and .opencode/skills/reversing-obfuscated-javascript in your project.
SKILL.md names no scripts, command-line tools or credentials: Reversing Obfuscated Javascript is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reversing Obfuscated Javascript is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reversing Obfuscated Javascript: Chrome Devtools Axi (layer5io/sistent, 138 stars), Browser Tools (981377660LMT/algorithm-study, 278 stars), Idleon Live Cdp (MrJoiny/Idleon-Injector, 112 stars) and Chrome Devtools (einverne/dotfiles, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.