Skip to main content
GitHub-Repository

oh_my_reverse_skill

oh_my_reverse_skill enthält 15 gesammelte Skills von zy950618, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
15
Stars
9
aktualisiert
2026-07-12
Forks
1
Berufsabdeckung
2 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

skills-evaluation-governance
Sonstige Computerberufe

Use this skill to score, refine, backtest, and govern Codex/Claude skills: assess whether notes are installable skills, create evals, prepare Skill Bench structure, compare SKILL.md quality, define trigger/negative-trigger tests, track drift, maintain versions, record changes, and enforce admission gates for new Skills. Trigger when the user asks to rate skills, use Skill Bench, convert notes into usable skills, evaluate trigger accuracy, maintain a skills library, score a new Skill before accepting it, run backtests, or Chinese requests such as SKILLS评分, 技能评分, 可用SKILLS, 新增Skill准入, Skill Bench跑分, 回测, 漂移测试, 长期治理, 版本号, 变更记录, 触发词优化, 负例测试, or 技能库治理.

2026-07-12
web-h5-loop-engineering
Softwareentwickler

Orchestration entry for Web/H5 reverse-engineering work only when the user explicitly asks for LOOP, closed-loop handling, multi-agent/three-role verification, repeated validation, execution ledger, acceptance report, or when a prior attempt failed because evidence, repeat verification, cleanup, impact, or backend acceptance was incomplete. It coordinates executor, verifier, and governor roles with loop ledger, acceptance report, fixture freshness, and metrics. Do not trigger for ordinary one-pass crawler tasks, simple fixture freshness checks, or single-tool JS work; use reverse-js-crawler or the relevant support tool first.

2026-07-12
find-crypto-entry
Softwareentwickler

Internal/support tool for locating the JS source of one concrete encrypted request field, sign, x-sign, authKey, or token. Use directly only when the user explicitly asks for an atomic entry-location task such as "找加密入口", "签名怎么算", or "这个请求头字段哪里生成"; otherwise let reverse-js-crawler or website-314-api-delivery choose it. Do not trigger for generic crawler delivery, ordinary request inspection, challenge/WAF backend acceptance, or non-encrypted parameters.

2026-07-12
env-patch
Softwareentwickler

Internal/support tool for running a previously identified browser encryption module in Node.js with env_core.js, prototype/native-function shims, and minimal stubs. Use directly only when the user explicitly asks for 补环境, Node里跑, webpack模块提取, or when an entry skill has already located the module and needs browser-to-Node reproduction. Do not trigger for ordinary browser debugging, AST deobfuscation, generic Node.js code, crawler delivery, or unresolved API discovery.

2026-07-09
js-page-runtime-parity
Softwareentwickler

Extract page-level JavaScript runtime dependencies and verify Browser, Node, V8, and PageRuntime output parity for authorized targets or localhost labs without generating risk tokens or defeat behavior.

2026-07-09
authorized-target-adapter
Softwareentwickler

Adapt reverse-engineering workflows only for owned or explicitly authorized targets with scope, allowed hosts, rate limits, stop conditions, redaction, and business data assertions.

2026-07-08
reverse-js-crawler
Softwareentwickler

Primary entry for focused Web/H5 crawler reverse engineering and interface restoration: page reconnaissance, real API discovery, JavaScript sign/token/cookie source tracing, request reproduction, data collection scripts, UI/API parity, and fresh replay evidence for a bounded route or stage. Trigger for JS reverse, crawler reverse, API restoration, encrypted parameters, sign/x-sign/authKey source tracing, web data collection, request reproduction, 逆向采集, JS逆向, 接口还原, 接口复现, 加密参数, 请求复现, 批量采集, 数据清洗, or 采集脚本交付. Do not use as the first entry for full FastAPI/service delivery, explicit LOOP/multi-agent closure, skill governance, stable adapter production, or challenge/WAF-specific evidence; route those to the corresponding entry or conditional skill.

2026-07-08
website-314-api-delivery
Softwareentwickler

Use this skill when a user gives a new website or existing target site and asks for end-to-end pure-interface implementation, FastAPI interface test delivery, API service delivery, or optional integration with a local base framework such as 314 after the Python interfaces are verified. Trigger for requests such as new website crawler, pure API implementation, FastAPI test API, site-to-service delivery, search/cart/order/payment flow, flight booking interface, 314 framework, flight_cwl_common_314, local base framework, 接口实现, 纯接口, FastAPI接口测试, 网站接入, 新站点接入, 查询/加车/生单/支付, 加解密全部实现, 314基础框架, 本地基础框架, 提供接口, 服务化, or 长期可维护接口交付.

2026-07-08
ai-reverse-skill-creator
Softwareentwickler

Internal governance support for creating or modifying reverse-engineering skill packages and trigger descriptions. Use when the user explicitly asks to create/update a reverse-engineering skill resource, optimize a SKILL.md description, or generate skill-specific evals. For scoring, admission, drift, trigger convergence, or SKILLS library governance, prefer skills-evaluation-governance. Do not trigger for ordinary Web/H5 reverse-engineering tasks or general code edits.

2026-07-08
browser-fingerprint-surface-lab
Softwareentwickler

Observe browser fingerprint surfaces, profile consistency, and risk-state attribution in localhost or authorized labs without concealment, fingerprint falsification, proxy avoidance, or clearance-cookie recycling.

2026-07-08
fingerprint-block-reason-diagnostics
Softwareentwickler

Record and attribute observed browser fingerprint and risk-block signals such as webdriver, canvas, WebGL, WebRTC, timezone, language, permissions, headers, and client hints without evasion.

2026-07-08
imperva-waf-reese84
Softwareentwickler

Conditional escalation skill for confirmed Imperva/Incapsula/Reese84 work. Use only when the user explicitly names 84盾, Reese84, Incapsula, Imperva, x-d-token, reese84 cookie, or when current evidence shows Reese84/Incapsula markers such as SWJIYLWA/CWUDNSAI/SWUDNSAI challenge HTML or protected business API rejection tied to those markers. It records token identity, WAF acceptance evidence, and backend acceptance boundaries. Do not trigger for generic anti-bot, generic fingerprint, ordinary sign/token, Cloudflare/Akamai/DataDome, or crawler delivery without Imperva/Reese84 evidence.

2026-07-08
ast-deobfuscate
Softwareentwickler

Internal/support tool for Babel AST deobfuscation of a specific obfuscated JavaScript file or snippet: string-array decoding, control-flow flattening, dead-code removal, and related transforms. Use directly only when the user explicitly asks for deobfuscation/还原/反混淆 or provides code with clear _0x/string-array/switch-flattening/sojson/OB markers. Do not trigger for ordinary minified code, generic JS reverse tasks, formatting, crawler delivery, or endpoint reproduction.

2026-07-08
karpathy-guidelines
Softwareentwickler

Auxiliary foundation guideline for engineering discipline. Use only as a supporting quality checklist when another Skill or coding task is already selected and the work involves implementation, review, refactoring, or verification. It is not a business-task entry point and must not independently handle Web/H5 reverse engineering, challenge, WAF, model training, API delivery, or site-specific workflows.

2026-07-08
site-api-adapter
Softwareentwickler

Conditional post-verification skill for turning already stable reverse-engineering findings into a reusable site API adapter: adapter.yaml, request/response schema, route classification, prompt-router rules, runbook, smoke tests, and service boundary documentation. Trigger only when the user explicitly asks for adapter标准化, adapter.yaml, schema/runbook/prompt-router, 接口化沉淀, or when website-314-api-delivery calls it after real API reproduction is verified. Do not trigger while endpoints, sign/token, challenge/WAF, or business acceptance are still being discovered.

2026-07-08