Use this skill to score, refine, backtest, and govern Codex/Claude skills: assess whether notes are installable skills, create evals, prepare Skill Bench structure, compare SKILL.md quality, define trigger/negative-trigger tests, track drift, maintain versions, record changes, and enforce admission gates for new Skills. Trigger when the user asks to rate skills, use Skill Bench, convert notes into usable skills, evaluate trigger accuracy, maintain a skills library, score a new Skill before accepting it, run backtests, or Chinese requests such as SKILLS评分, 技能评分, 可用SKILLS, 新增Skill准入, Skill Bench跑分, 回测, 漂移测试, 长期治理, 版本号, 变更记录, 触发词优化, 负例测试, or 技能库治理.
Orchestration entry for Web/H5 reverse-engineering work only when the user explicitly asks for LOOP, closed-loop handling, multi-agent/three-role verification, repeated validation, execution ledger, acceptance report, or when a prior attempt failed because evidence, repeat verification, cleanup, impact, or backend acceptance was incomplete. It coordinates executor, verifier, and governor roles with loop ledger, acceptance report, fixture freshness, and metrics. Do not trigger for ordinary one-pass crawler tasks, simple fixture freshness checks, or single-tool JS work; use reverse-js-crawler or the relevant support tool first.
Internal/support tool for locating the JS source of one concrete encrypted request field, sign, x-sign, authKey, or token. Use directly only when the user explicitly asks for an atomic entry-location task such as "找加密入口", "签名怎么算", or "这个请求头字段哪里生成"; otherwise let reverse-js-crawler or website-314-api-delivery choose it. Do not trigger for generic crawler delivery, ordinary request inspection, challenge/WAF backend acceptance, or non-encrypted parameters.
Internal/support tool for running a previously identified browser encryption module in Node.js with env_core.js, prototype/native-function shims, and minimal stubs. Use directly only when the user explicitly asks for 补环境, Node里跑, webpack模块提取, or when an entry skill has already located the module and needs browser-to-Node reproduction. Do not trigger for ordinary browser debugging, AST deobfuscation, generic Node.js code, crawler delivery, or unresolved API discovery.
Extract page-level JavaScript runtime dependencies and verify Browser, Node, V8, and PageRuntime output parity for authorized targets or localhost labs without generating risk tokens or defeat behavior.
Adapt reverse-engineering workflows only for owned or explicitly authorized targets with scope, allowed hosts, rate limits, stop conditions, redaction, and business data assertions.
Primary entry for focused Web/H5 crawler reverse engineering and interface restoration: page reconnaissance, real API discovery, JavaScript sign/token/cookie source tracing, request reproduction, data collection scripts, UI/API parity, and fresh replay evidence for a bounded route or stage. Trigger for JS reverse, crawler reverse, API restoration, encrypted parameters, sign/x-sign/authKey source tracing, web data collection, request reproduction, 逆向采集, JS逆向, 接口还原, 接口复现, 加密参数, 请求复现, 批量采集, 数据清洗, or 采集脚本交付. Do not use as the first entry for full FastAPI/service delivery, explicit LOOP/multi-agent closure, skill governance, stable adapter production, or challenge/WAF-specific evidence; route those to the corresponding entry or conditional skill.
Use this skill when a user gives a new website or existing target site and asks for end-to-end pure-interface implementation, FastAPI interface test delivery, API service delivery, or optional integration with a local base framework such as 314 after the Python interfaces are verified. Trigger for requests such as new website crawler, pure API implementation, FastAPI test API, site-to-service delivery, search/cart/order/payment flow, flight booking interface, 314 framework, flight_cwl_common_314, local base framework, 接口实现, 纯接口, FastAPI接口测试, 网站接入, 新站点接入, 查询/加车/生单/支付, 加解密全部实现, 314基础框架, 本地基础框架, 提供接口, 服务化, or 长期可维护接口交付.