Agent skill

Reversing Obfuscated Javascript

by trilwu in trilwu/secskills

Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…

MITAuto-check passedSecurity

Install Reversing Obfuscated Javascript

skills CLI
$ npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills reversing-obfuscated-javascript --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reversing-obfuscated-javascript .claude/skills/reversing-obfuscated-javascript && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reversing-obfuscated-javascript
GitHub stars
156
Token cost
~2.3k tokens
SKILL.md length
1,188 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…

  • A page ships a huge minified bundle
  • SKILL.md covers When to Use, When NOT to Use, Identify the Layer Before… and Sourcemaps: Try This First,…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Code is full of 0x hex identifiers and a rotated string array

What it does

Reversing Obfuscated Javascript is an agent skill from trilwu/secskills. Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow obfuscation with webcrack/synchrony/restringer, and locating a signing or crypto routine in a live bundle via Chrome DevTools. Use when a page ships a huge minified bundle, when code is full of 0x hex identifiers and a rotated string array, when a .js.map is reachable, or when you must find where a request signature or token…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Browser testing. It works with JavaScript, webpack and Chrome DevTools. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A page ships a huge minified bundle
  • Code is full of 0x hex identifiers and a rotated string array
  • A .js.map is reachable
  • You must find where a request signature

Example prompts

  • “/reversing-obfuscated-javascript”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reversing Obfuscated Javascript loads about 2.3k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 1,188 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,188 words, ~2,278 tokens.

Download SKILL.mdSave it as .claude/skills/reversing-obfuscated-javascript/SKILL.md (or your agent's skills folder).
name
reversing-obfuscated-javascript
description
Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow obfuscation with webcrack/synchrony/restringer, and locating a signing or crypto routine in a live bundle via Chrome DevTools. Use when a page ships a huge minified bundle, when code is full of _0x hex identifiers and a rotated string array, when a .js.map is reachable, or when you must find where a request signature or token is computed.
verified
2026-08-07

Reversing Obfuscated JavaScript

Client-side JavaScript ships the whole program to the reader — there is no stripped binary here, only code deliberately made unreadable. That changes the job: you are almost never recovering missing information, you are undoing a transformation. Identify the transformation first, reverse it with the tool built for it, and fall back to hand-written AST passes only for the custom layer no off-the-shelf tool knows.

When to Use

  • A page or extension ships a large minified/bundled .js you need to read
  • Code is full of _0x1234 identifiers, a big string array, and a rotation IIFE at the top — the obfuscator.io signature
  • A .js.map sourcemap is reachable, or webpack left //# sourceMappingURL
  • You must locate where a request signature, HMAC, token, or crypto key is computed inside a running bundle
  • Reproducing a client-side algorithm (an anti-bot signal, a licence check, a paywall gate) from the shipped code

When NOT to Use

  • React Native / Hermes mobile bundles (index.android.bundle, main.jsbundle, Hermes magic bytes) — use reversing-react-native-apps.
  • A custom bytecode VM or virtualized-JS obfuscator where control flow is interpreted, not just flattened — that is devirtualization; use unpacking-protected-binaries for the VM-lifting approach.
  • Malicious JS in a compromised site or npm package where the goal is IOCs and behaviour, not readability — use hunting-web-backdoors for planted web payloads and auditing-supply-chain for a malicious package.
  • Testing the web app itself (the endpoints the JS calls, XSS, auth) — use testing-web-applications; come back here only to recover a client-side algorithm it needs.
  • WASM modules loaded by the page — that is analyzing-binaries territory.

Identify the Layer Before Touching a Tool

Running the wrong deobfuscator produces plausible garbage. Read the first few hundred bytes and classify:

What you seeTransformationReverse it with
Short names, no whitespace, readable stringsMinification onlyAn unminifier / prettier + rename
webpackChunk, a module map {123: function(e,t,n){…}}Webpack/Rollup bundlingUnbundle to per-module files
//# sourceMappingURL=… or a reachable .mapNothing — the source is right thereSourcemap recovery
_0x hex names + one big string array + a rotation IIFEobfuscator.io string-arraywebcrack / synchrony / restringer
Nested ternaries, while(true){switch(_0x..)} dispatcherControl-flow flatteningAST pass to relink the switch
debugger in a setInterval, self-defending functionAnti-debug / self-defenseStrip the guard before other passes

Most real bundles are layered: webpack on the outside, obfuscator.io on a few modules, a hand-rolled string cipher on the one function that matters. Peel outermost first.

Sourcemaps: Try This First, Always

A reachable sourcemap ends the job before it starts — it contains the original, pre-transform source. Check for it every time, because a large fraction of "obfuscated" production bundles ship or leak one:

  • The //# sourceMappingURL= comment at the bundle's end, and the sibling .js.map even when the comment was stripped (try <bundle>.map).
  • Webpack dev artifacts and source in webpack:// paths inside the map.
  • Recover files with a sourcemap consumer — unwebpack-sourcemap or a short source-map script walks sourcesContent back to a directory tree.

Treat a leaked production sourcemap as a finding in its own right when you are assessing the app, not just a convenience.

Unbundling and Deobfuscation

webcrack is the first tool for a bundle, because it does three of the layers at once: unminify, unpack webpack/browserify into per-module files, and undo obfuscator.io string-array and control-flow obfuscation. Run it, then read the module tree it produces rather than the single blob.

For a bundle that is only obfuscator.io, a dedicated deobfuscator is often cleaner: synchrony or restringer both resolve the string array, reverse the rotation, inline the decoder calls, and flatten the trivial control flow. Compare their output — they fail on different edge cases.

When no tool fully handles the custom layer, write an AST pass with Babel: parse to an AST, @babel/traverse to find the pattern (a specific decoder call, a constant-folded expression, the flattening dispatcher), transform the nodes, and regenerate. This is the durable skill — obfuscators change, but string-array decoding, constant folding, and dead-branch elimination are the same AST operations every time. Prototype the matcher in AST Explorer against the real code before scripting it.

Two failure modes to expect:

  • A deobfuscator that runs the code to "evaluate" the string decoder can execute a payload. For untrusted or malicious bundles, do the string resolution statically or in an isolated sandbox — never eval an unknown bundle on your host to read it.
  • Self-defending / debug-protection re-obfuscates or spins a debugger loop when tampered with. Strip the guard function first (delete the node, or override setInterval) or every downstream pass fights it.
Show full SKILL.md (457 more words)Show less

Finding a Routine in a Live Bundle

When static reading is slow — a signing function buried in a megabyte of modules — drive the running page with Chrome DevTools instead:

  • Break on the behaviour, not the code. XHR/fetch breakpoints stop when the signed request fires; the call stack then walks straight back through the signing function. DOM and event-listener breakpoints do the same for UI-triggered logic.
  • Pretty-print in the Sources panel ({}) makes a minified function steppable without any offline work.
  • Hook property access from the console — Object.defineProperty or a Proxy on the object whose method computes the value logs every call and argument with a stack trace, so you see inputs and outputs without reading the math.
  • Override the file with a local, prettified, console.log-instrumented copy (DevTools Local Overrides) to watch the real values flow at runtime.

Runtime observation and static reading are complementary: DevTools tells you which function matters; the AST work tells you what it computes so you can reproduce it offline.

Scope and Authorization

Reading and deobfuscating a bundle you lawfully retrieved is analysis. Two edges need care. Reproducing and replaying a request-signing routine against the origin — the usual reason to reverse an anti-bot signal — acts against that service and needs the same authorization as any other testing; keep it to systems you are permitted to test, and see testing-web-applications. And a sourcemap or bundle pulled from a third-party site is that party's code: recovering it for a security assessment you are engaged to do is fine, lifting a proprietary algorithm for reuse is a different matter.

Rationalizations to Reject

  • "It's obfuscated, so it's slow manual work." Classify first — a reachable sourcemap or a clean webcrack run turns hours into minutes. Hand-reading is the last resort, not the first move.
  • "webcrack's output has a weird spot, so it failed." Layered obfuscation means one tool clears the outer layers and leaves the custom inner one. That residue is the interesting function; switch to an AST pass on it, don't restart.
  • "I'll just eval the string-decoder to get the plaintext." On an untrusted bundle that runs attacker code on your host. Resolve strings statically or sandboxed.
  • "The variable names are gone, so the logic is gone." Minification and obfuscation rename and reshape; they do not delete. Unlike a stripped native binary, the full program is present — you are undoing a transform, not reconstructing lost information.
  • "DevTools is for debugging, not reversing." A fetch breakpoint plus a property hook locates a signing routine faster than reading the bundle, and gives you live inputs and outputs for free.

References

  • reversing-react-native-apps — Hermes/RN mobile JS bundles
  • unpacking-protected-binaries — VM-based / virtualized obfuscation
  • hunting-web-backdoors — malicious planted web JS
  • testing-web-applications — testing the endpoints a recovered algorithm calls
  • reviewing-cryptography — once a client-side crypto/signing routine is recovered

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/reversing-obfuscated-javascript of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Reversing Obfuscated Javascript next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reversing Obfuscated Javascript compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reversing Obfuscated Javascript this skilltrilwu/secskills156—~2.3kAutomated safety check: PassMIT
Chrome Devtools Axilayer5io/sistent1382 repos~989Automated safety check: PassApache-2.0
Browser Tools981377660LMT/algorithm-study2781 repos~1.3kAutomated safety check: PassNone
Idleon Live CdpMrJoiny/Idleon-Injector112—~1.2kAutomated safety check: PassNone
Chrome Devtoolseinverne/dotfiles1211 repos~1.6kAutomated safety check: NotesApache-2.0
Browser Testing With Devtoolsshashankswe2020-ux/whoop-mcp166—~3kAutomated safety check: WarnMIT

Similar skills

  • Chrome Devtools Axi

    layer5io/sistent

    Control a Chrome browser session through the chrome-devtools-axi CLI - navigate, snapshot, click, fill forms, run JavaScript, inspect console and network, take screenshots, audit performance.

    138 GitHub starsUsed in 2 repos~989 tokens
    Testing & QAAuto-check passed
  • Browser Tools

    981377660LMT/algorithm-study

    Interactive browser automation via Chrome DevTools Protocol.

    278 GitHub starsUsed in 1 repo~1.3k tokens
    Productivity & AutomationAuto-check passed
  • Idleon Live Cdp

    MrJoiny/Idleon-Injector

    Inspect and interact with a running Legends of Idleon session through the Chrome DevTools Protocol on port 32123.

    112 GitHub stars~1.2k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Chrome Devtools

    einverne/dotfiles

    Browser automation, debugging, and performance analysis using Puppeteer CLI scripts.

    121 GitHub starsUsed in 1 repo~1.6k tokens
    Data & AnalyticsAuto-check: notes
  • Browser Testing With Devtools

    shashankswe2020-ux/whoop-mcp

    Tests in real browsers. An agent skill from shashankswe2020-ux/whoop-mcp.

    166 GitHub stars~3k tokensUpdated today
    Testing & QAAuto-check: warnings
  • Agent Cdp

    gronxb/codex-relay

    Chrome DevTools Protocol CLI workflow for runtime, console, network, trace, memory, and JavaScript CPU profiling analysis.

    678 GitHub stars~956 tokensUpdated today
    MobileAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    156 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Reversing Obfuscated Javascript

What does Reversing Obfuscated Javascript do?

Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…. Reversing Obfuscated Javascript is an agent skill from trilwu/secskills.io string-array and control-flow obfuscation with webcrack/synchrony/restringer, and locating a signing or crypto routine in a live bundle via Chrome DevTools.

When should I use Reversing Obfuscated Javascript?

Reversing Obfuscated Javascript fits situations like: A page ships a huge minified bundle; code is full of 0x hex identifiers and a rotated string array; A .js.map is reachable; you must find where a request signature.

How do I install Reversing Obfuscated Javascript in Claude Code?

Run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a claude-code`. Or copy the skill folder (secskills-core/skills/reversing-obfuscated-javascript in trilwu/secskills) into .claude/skills/reversing-obfuscated-javascript in your project. Claude Code loads it when a task matches its description.

How do I install Reversing Obfuscated Javascript in Codex?

Run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a codex`. Or copy the skill folder (secskills-core/skills/reversing-obfuscated-javascript in trilwu/secskills) into .agents/skills/reversing-obfuscated-javascript in your project. Codex loads it when a task matches its description.

Can I use Reversing Obfuscated Javascript in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reversing-obfuscated-javascript -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reversing-obfuscated-javascript, .gemini/skills/reversing-obfuscated-javascript, .github/skills/reversing-obfuscated-javascript and .opencode/skills/reversing-obfuscated-javascript in your project.

What does Reversing Obfuscated Javascript need to run?

SKILL.md names no scripts, command-line tools or credentials: Reversing Obfuscated Javascript is instructions for the agent only.

Does Reversing Obfuscated Javascript access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Reversing Obfuscated Javascript safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Reversing Obfuscated Javascript use?

Reversing Obfuscated Javascript is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reversing Obfuscated Javascript use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Reversing Obfuscated Javascript?

Skills that share tags, products or a category with Reversing Obfuscated Javascript: Chrome Devtools Axi (layer5io/sistent, 138 stars), Browser Tools (981377660LMT/algorithm-study, 278 stars), Idleon Live Cdp (MrJoiny/Idleon-Injector, 112 stars) and Chrome Devtools (einverne/dotfiles, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reversing Obfuscated Javascript?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.