Dsl Vm Reverse
sickn33/agentic-awesome-skills
Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics.
Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverse --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .claude/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .claude/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverse --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .agents/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .agents/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverse --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .cursor/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .cursor/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zhaoxuya520/reverse-skill.git --path skills/reverse-engineering/dsl-vm-reverse--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverse --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .gemini/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .gemini/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .github/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .github/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zhaoxuya520/reverse-skill dsl-vm-reverse --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/reverse-engineering/dsl-vm-reverse .opencode/skills/dsl-vm-reverse && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dsl-vm-reverse" agent skill from https://github.com/zhaoxuya520/reverse-skill/tree/main/skills/reverse-engineering/dsl-vm-reverse into .opencode/skills/dsl-vm-reverse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsl-vm-reverse", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dsl-vm-reverseReverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.
Dsl Vm Reverse is an agent skill from zhaoxuya520/reverse-skill. Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. Use when analyzing IIFE or switch-based opcode dispatchers, extracting instruction tables, recovering bytecode semantics, capturing VM state at runtime, or reconstructing execution flow.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware. It works with WebAssembly and JavaScript. The repository describes itself as: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base…. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cab634b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
target-page.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dsl Vm Reverse loads about 2.3k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 384 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zhaoxuya520/reverse-skill at commit cab634b, republished under its MIT licence (© zhaoxuya520). 384 words, ~2,291 tokens.
.claude/skills/dsl-vm-reverse/SKILL.md (or your agent's skills folder).NOW: 确认当前任务是自定义 JS opcode VM / 风控引擎,不是标准 WASM 或普通 webpackNOW: case-init 直到 scope.md 就绪;离线样本用 offline / labACT: 从「3. 通用逆向工作流」Phase 1 做文件分类,不要停在目录用于逆向基于 JavaScript 实现的自定义 WASM 虚拟机/风控引擎
当目标文件符合以下 任意特征 时使用本 skill:
| # | 特征 | 说明 |
|---|---|---|
| 1 | IIFE 开头 + 大量单字母变量名 | !function(){var U=void 0,y=parseInt,E0=Function,...} |
| 2 | 包含 DG() 或类似函数含 switch-case 循环 | 解释器主循环,d[7]&31 解码 opcode |
| 3 | 大文件(500KB+)但零字节占比 < 1% | 非标准 WASM,纯 JS |
| 4 | 包含 C[number] 常量表引用 | C[9][xxx] 函数表/字符串表 |
| 5 | 单行压缩代码 | 583KB 单行,混淆变量名 |
| 条件 | 非本 skill | 转至 |
|---|---|---|
文件以 \x00asm 开头 | 标准 WASM 二进制 | reverse-engineering/languages.md |
文件以 Uint8Array([0,97,115,109]) 含 WASM 魔术字 | WASM 嵌入式 | 提取 .wasm 后转 IDA/Ghidra |
标准 Webpack 打包(function(e,t,n){...}) | 普通 JS | js-reverse/ |
| 零字节占比 > 20% | WASM 二进制 | reverse-engineering/languages.md |
// 特征 1: IIFE 入口,单字母变量映射数字常量
!function(){
var U=void 0, y=parseInt, E0=Function, AN=Uint8Array;
var E=15, l=10, m=12, x=16, S=13, $=11;
// 数字常量映射为变量名,替代原始数字
...
}
// 特征 2: 解释器主循环 DG()
function DG(C, d, ...) {
var d = []; // 数组模拟 WASM stack/locals
for (d[7] = x; d[7] !== U;) {
var aE = d[7] & 31; // 低 5 位 = opcode
var O = d[7] >> 5 & 31; // 高 5 位 = sub-operation
switch (aE) {
case 0: /* ... */ d[7] = 612; break;
case 1: /* ... */
// ... N 个 case
}
}
}
// 特征 3: 常量表 C[9] 存储函数索引和字符串
// C[9][0] = ["pc"] → 函数参数描述
// C[9][667] = "string" → 字符串常量
// C[9][x] = number → 函数索引
// 特征 4: W(C[index], null, ...) 调用模式
// W = Function.prototype.call.bind(call)
// 所有内置函数通过 C[index] 索引调用
// 特征 5: 指令编码格式
// d[7] = opcode(bit 0-4) | subop(bit 5-9) | operand(bit 10+)每条指令编码为 32 位整数:
bit 0-4: opcode (0-N)
bit 5-9: sub-operation (0-31)
bit 10-31: operand/立即数
解码:
aE = d[7] & 31 → opcode
O = d[7] >> 5 & 31 → sub-operation
d[other] = d[7] >> 10 → operand# 检查是否为 DSL VM
python3 << 'EOF'
with open('target.js', 'rb') as f:
head = f.read(100)
# 1. 检查 WASM 魔术字
if head[:4] == b'\x00asm':
print("标准 WASM 二进制")
exit()
# 2. 检查零字节占比
data = open('target.js', 'rb').read()
zero_pct = data.count(b'\x00') / len(data) * 100
print(f"零字节占比: {zero_pct:.1f}%")
if zero_pct > 20:
print("WASM 二进制")
elif head[:2] == b'!f':
# 检查单字母变量模式
if b'var U=void 0' in head or b'U=void 0,y=parseInt' in head:
print("→ DSL VM!")
else:
print("普通 JS IIFE")
EOFimport re
with open('target.js', 'r', errors='replace') as f:
s = f.read()
# 提取开头 2000 字符的 var X=数字 映射
mappings = re.findall(r'var\s+(\w+)\s*=\s*(\d+)', s[:2000])
print('常量映射:')
for name, val in mappings:
print(f" {name:4s} = {val:3d} (0x{int(val):02x})")# 1. 提取所有 case
all_cases = re.findall(r'case\s+(\d+):', s)
unique = sorted(set(int(c) for c in all_cases))
print(f"总 case: {len(all_cases)} 个")
print(f"唯一 opcode: {len(unique)} 个: {unique}")
# 2. 分类每个 opcode
for op in unique:
idx = s.find(f'case {op}:')
snippet = s[idx:idx+200]
if 'd[7]=' in snippet:
op_type = 'BRANCH'
elif 'return' in snippet:
op_type = 'RETURN'
elif 'W(C[' in snippet:
op_type = 'CALL'
elif 'new' in snippet:
op_type = 'ALLOC'
elif 'try' in snippet or 'catch' in snippet:
op_type = 'EXCEPTION'
else:
op_type = 'ARITH/STORE'
print(f" opcode {op:2d}: {op_type}")const_refs = re.findall(r'C\[9\]\[(\d+)\]', s)
unique_refs = sorted(set(int(x) for x in const_refs))
print(f"C[9] 引用: {len(unique_refs)} 个索引")
print(f"范围: {min(unique_refs)} - {max(unique_refs)}")
# 对每个引用分析上下文
for ref in unique_refs[:20]:
idx = s.find(f'C[9][{ref}]')
ctx = s[max(0,idx-50):idx+80]
clean = ''.join(c if c.isprintable() else ' ' for c in ctx)
print(f" C[9][{ref}] → {clean}")导出函数(如 getToken)通过以下路径定位:
1. 找 AWSCInner.register() 或类似注册调用
2. 确定注册的模块和工厂函数
3. 找工厂函数返回的对象 → 导出函数定义位置
4. 若函数名不在 JS 中 → 在 C[9] 常量表中作字节码存储
5. 追踪调用链:
AWSCInner._modules['fy'].getToken()
→ W(C[函数索引], null, ...)
→ DG() 解释器执行编码后的指令序列// 注入最小 AWSC 兼容环境
const fakeEnv = {
AWSCInner: {
_modules: {},
register(name, moduleName, factory) {
this._modules[moduleName] = factory();
}
}
};
// 执行 DSL VM 代码
dslVmCode();
// 获取导出
const token = fakeEnv.AWSCInner._modules['fy'].getToken({});| Opcode | 操作类型 | 特征 |
|---|---|---|
| 0 | BRANCH | d[7]=xxx 无条件跳转 |
| 1 | CALL | W(C[Y],null,function(){...}) 嵌入函数调用 |
| 2 | ARITH | d[4]=0, d[7]=72 变量赋值 |
| 3 | ARITH | d[0]=d[1][C[x]], d[5]=d[0]<d[3] 比较运算 |
| 4 | STORE | d[8]=d[5]in d[4] 属性访问/存在检查 |
| 5 | ARITH | d[8]=d[4]-d[8] 算术运算 |
| 6 | RETURN | return gV, throw 返回/抛出异常 |
| 7 | ALLOC | d[6]=[], d[6][C[8]](...) push 操作 |
| 8 | BRANCH | d[7]=d[k]?512:425 条件跳转 |
| 9 | STRING | d[6][C[t]]=d[m], new fh(...) 正则 |
| 10 | ALLOC | 函数参数准备、调用栈创建 |
| 11 | STRING | new fh("\\s",d[5]) 正则匹配 |
| 12 | STORE | P[d[9]]=d[4][C[H]](d[3]) 数据传递 |
| 13 | CALL | C[9][113]=d[9] 模块初始化 |
| 14 | STRING | d[8]=d[9]+d[m] 字符串拼接 |
| 15 | RETURN | return EL; 函数返回 |
| 16 | ALLOC | var r,P,Z,B... 局部变量声明 |
| 17 | ALLOC | (Z=[])[C[8]](69,T,445) 静态数组初始化 |
| 18 | TABLE | 函数表/类型表初始化 |
| 19 | EXCEPTION | try{for(var RK=x;... try-catch 循环 |
| 20 | DOM | Is[d[o]] DOM 操作 |
| 21 | STORE | 安全获取全局/对象属性 |
| 22 | STRING | new fh(r,v) 字符串/正则处理 |
| 23 | BRANCH | try...catch 安全获取 + 条件跳转 |
| 24 | CALL | W(C[2],null,8,z,FL) 多参数函数调用 |
| 25 | EXCEPTION | try{...}catch(C){...} 异常捕获 + 跳转 |
from selenium import webdriver
driver = webdriver.Chrome()
# 注入反检测
driver.execute_cdp_cmd("Page.addScriptToEvaluateOnNewDocument", {
"source": r"""
Object.defineProperty(navigator, 'webdriver', {get: () => false});
Object.defineProperty(navigator, 'plugins', {get: () => [1,2,3,4,5]});
Object.defineProperty(navigator, 'languages', {get: () => ['zh-CN','zh','en']});
"""
})
# 发送 CDP 原生鼠标事件
driver.execute_cdp_cmd("Input.dispatchMouseEvent", {
"type": "mousePressed",
"x": 549.5, "y": 441.2,
"button": "left", "buttons": 1,
"clickCount": 1, "pointerType": "mouse"
})const { chromium } = require('playwright');
async function run() {
const browser = await chromium.launch();
const page = await browser.newPage();
// 拦截网络请求
await page.route('**/api/**', async route => {
await route.continue_();
});
await page.goto('https://target-page.com');
// 等待 DSL VM 初始化
await page.waitForFunction(() => {
return window.AWSCInner &&
window.AWSCInner._modules &&
window.AWSCInner._modules['fy'];
});
// 执行操作
await page.mouse.move(500, 400);
await page.mouse.down();
// ... 操作序列
await page.mouse.up();
}DSL VM 生成的 token 通常与浏览器上下文强绑定(TLS JA3 指纹、IP、Cookie、请求头等),脱离浏览器后服务端可检测到上下文不匹配。不建议使用纯协议方案。
| Code | 含义 | 处理 |
|---|---|---|
| 0 | 验证通过 ✅ | 取出 sessionId + sig |
| 300 | 风控拦截 | 被拦截,无法通过 |
| 8778 | 验证失败,需重试 | 重试操作 |
| 8776 | 操作太快,需重试 | 增加延迟后重试 |
| 69634 | 通用失败 | 检查参数是否正确 |
var X=数字)?| 类型 | 路由 |
|---|---|
| 目标类型: WASM / DSL VM / 自定义指令集 | reverse-engineering/dsl-vm-reverse/SKILL.md |
| 用户意图: "DSL VM / 风控引擎逆向" | 本 skill |
| 工具链: Playwright / Selenium CDP | 浏览器注入方案 |
DSL VM 逆向路径:
reverse-engineering/dsl-vm-reverse/ → Phase 1-6 工作流
↓ 若需要捕获运行时数据
browser-automation/ → Playwright/Selenium CDP
↓ 若需要分析 API 协议层
js-reverse/ → Observe→Capture→Rebuild© zhaoxuya520, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/reverse-engineering/dsl-vm-reverse of zhaoxuya520/reverse-skill.
Open the folder on GitHubat commit cab634b
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in zhaoxuya520/reverse-skill, which our catalogue first saw on October 7, 2026.
Dsl Vm Reverse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dsl Vm Reverse this skillzhaoxuya520/reverse-skill | 41k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Dsl Vm Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Wine Assembly Connectvgrichina/berrry-wine | 116 | — | ~1.9k | Automated safety check: Pass | MIT | |
| R0crawl Skillsmanyuegong33/r0crawl_skills | 312 | — | ~1.2k | Automated safety check: Pass | None | |
| JS Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics.
vgrichina/berrry-wine
Connect to a Windows 98 game or app that a person is running in their browser on wine-assembly, then see its screen and play it with mouse and keyboard.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
sickn33/agentic-awesome-skills
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
LottieFiles/dotlottie-web
Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).
zhaoxuya520/reverse-skill
Turns text, notes, code, schemas or tables into diagram source in Mermaid, Graphviz DOT, PlantUML or SVG, and renders files when you ask for an image or PDF.
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic…
zhaoxuya520/reverse-skill
A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
Works with
Categories
Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. Dsl Vm Reverse is an agent skill from zhaoxuya520/reverse-skill. Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.
Dsl Vm Reverse fits situations like: switch-based opcode dispatchers; extracting instruction tables; recovering bytecode semantics; capturing VM state at runtime.
Run `npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a claude-code`. Or copy the skill folder (skills/reverse-engineering/dsl-vm-reverse in zhaoxuya520/reverse-skill) into .claude/skills/dsl-vm-reverse in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a codex`. Or copy the skill folder (skills/reverse-engineering/dsl-vm-reverse in zhaoxuya520/reverse-skill) into .agents/skills/dsl-vm-reverse in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaoxuya520/reverse-skill --skill dsl-vm-reverse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsl-vm-reverse, .gemini/skills/dsl-vm-reverse, .github/skills/dsl-vm-reverse and .opencode/skills/dsl-vm-reverse in your project.
Going by SKILL.md and its folder, Dsl Vm Reverse needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: target-page.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dsl Vm Reverse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dsl Vm Reverse: Dsl Vm Reverse (sickn33/agentic-awesome-skills, 47k stars), Wine Assembly Connect (vgrichina/berrry-wine, 116 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 312 stars) and JS Reverse (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zhaoxuya520 (a GitHub user) maintains it in zhaoxuya520/reverse-skill, which has 40,590 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on September 22, 2026.
Source: zhaoxuya520/reverse-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.