用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/boshu2/agentops --skill reverse-engineer命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Use Agent Mail as an optional messaging and file-reservation adapter for explicitly coordinated writers. Triggers: "coordinate writers", "reserve files".
Operate explicit orchestrator, implementer, validator, and scribe roles through a caller-selected agent runtime. Triggers: "agent-native factory", "role-shaped agent panes", "persistent workers".
Initialize minimal AgentOps documentation and verdict storage without taking over repository workflow. Triggers: "bootstrap AgentOps", "initialize AgentOps docs".
正在显示 SKILL.md
| name | reverse-engineer |
| description | Reverse-engineer an authorized repo, binary |
Reverse-engineer an external system into two things: a mechanically-verifiable teardown (feature inventory + registry + specs, optionally a security audit) and a steal-map — what to adopt into our surfaces, what to leave behind. The teardown is the evidence; the steal-map is the decision. Separating them works because a decision row that must cite a registry entry can be re-checked by anyone, while a decision made from impressions cannot be re-checked by its own author. The original failure mode this skill exists to prevent: reading a competitor's README and "deciding" from vibes.
Triggers: "reverse-engineer X", "tear down Y", "what should we steal from Z", "evaluate competitor/upstream", "should we fork/adopt/build-native".
Produce evidence, not vibes. The script clones (pinned), scans CLI/config/artifact surface, and writes a feature inventory + machine-checkable registry + spec set.
python3 skills/reverse-engineer/scripts/reverse_engineer.py <product> --mode=repo \
--upstream-repo="https://github.com/org/repo.git" --upstream-ref=v1.0.0 \
--output-dir=".agents/scratch/reverse-engineer/<product>/"
Binary mode requires --authorized (see Invocation Contract + Self-Test). Use the bundled demo fixture if you lack authorization for a real binary.
Map each capability the teardown found onto our surfaces. This is the part that turns research into a decision. Emit .agents/scratch/reverse-engineer/<product>/steal-map.md with a table; every row cites the teardown evidence and the matching surface in our repo.
| Their capability | Our surface today | Verdict |
|---|---|---|
<feature> | <our file / skill / CLI, or "none"> | have / gap / steal / park / reject |
Verdict rules (hard-won — apply them, do not skip):
Discipline that makes the map trustworthy:
If adopting a steal is a one-way door (an architecture fork, a new bounded context, or a migration), do not decide it here. Hand the steal-map to Plan. Dueling Idea Genies or Premortem may challenge the choice as advisory evidence. Plan alone shapes the selected option in the existing intent source; neither strategy grants readiness or continuation authority.
Required: product_name. Common flags: --mode=repo|binary|both, --upstream-repo, --upstream-ref (pins the clone to a specific commit/tag/branch; the resolved SHA is recorded in clone-metadata.json on any clone), --output-dir (default .agents/scratch/reverse-engineer/<product>/), --security-audit, --materialize-archives (authorized-only opt-in; embedded-archive extraction is off/index-only by default), --authorized (mandatory for binary mode — refuses without it). Full list: python3 skills/reverse-engineer/scripts/reverse_engineer.py --help.
Phase-1 teardown under output_dir/: feature-inventory.md, feature-registry.yaml, feature-catalog.md, spec-architecture.md, spec-code-map.md, spec-clone-vs-use.md, spec-clone-mvp.md, plus spec-cli-surface.md only when a CLI is detected and clone-metadata.json only when the script performs a clone (i.e., --upstream-repo is supplied and the target is not already checked out); --upstream-ref pins which commit, it is not what triggers the file. Security mode adds output_dir/security/: threat-model.md, attack-surface.md, dataflow.md, crypto-review.md, authn-authz.md, findings.md, reproducibility.md, validate-security-audit.sh. Phase-2: steal-map.md.
Artifact directory: the exact --output-dir, defaulting to
$REPO/.agents/scratch/reverse-engineer/<product>/.
Filename convention: the fixed phase-1 and phase-2 names above; security
files live only in the security/ child directory.
Serialization/schema format: registry is YAML, clone metadata is one JSON object, and inventories/specs/steal-map are nonempty Markdown files.
Validator command: with $output_dir, $security_audit, $sbom, and
$upstream_ref_set (each flag 0|1) set:
set -euo pipefail
required=(feature-inventory.md feature-registry.yaml feature-catalog.md spec-architecture.md spec-code-map.md spec-clone-vs-use.md spec-clone-mvp.md analysis-root-path.txt validate-feature-registry.py steal-map.md)
for name in "${required[@]}"; do
test -f "$output_dir/$name"
test ! -L "$output_dir/$name"
test -s "$output_dir/$name"
done
test -f "$output_dir/docs-features.txt"
test ! -L "$output_dir/docs-features.txt"
test ! -L "$output_dir/spec-cli-surface.md"
if [[ -e "$output_dir/spec-cli-surface.md" ]]; then
test -f
-s
python3
[[ == 1 ]];
-f
! -L
jq -e >/dev/null
[[ == 0 ]]
grep -Fqx
[[ == 1 ]];
-x
[[ == 1 ]];
--sbom
[[ == 0 ]]
--no-sbom
[[ == 0 ]]
[[ == 0 ]]
--upstream-ref pins the clone (fetch FETCH_HEAD, record SHA) so contracts can be committed as golden fixtures and diffed across runs. Regression test: bash skills/reverse-engineer/scripts/repo_fixture_test.sh. To update a fixture when contracts legitimately change, re-run with the new pinned ref, copy the contract files into fixtures/<product>/, and commit.
bash skills/reverse-engineer/scripts/self_test.sh
Must show: feature inventory generated, registry generated, registry validator exits 0; in security mode validate-security-audit.sh exits 0 and the secret scan passes.
Run the skill for cc-sdd with --mode=repo --upstream-repo="https://github.com/gotalab/cc-sdd.git" --upstream-ref=v1.0.0. It clones the pinned source, scans the surface, writes inventory/registry/specs, and maps each feature onto our surfaces (have, gap, steal, park, or reject) in steal-map.md. Supply selected steals to Plan.
Run the skill for ao with --authorized --mode=binary --binary-path="$(command -v ao)" --security-audit. It performs authorized static analysis plus the security suite under output_dir/security/; the secret-scan check must pass.
| Problem | Cause | Solution |
|---|---|---|
| Refuses binary analysis | Missing --authorized | Add --authorized (explicit written authorization required). |
No clone-metadata.json | --upstream-repo not passed | Pass --upstream-repo (and optionally --upstream-ref). |
| Fixture diff fails | Upstream changed / stale golden | Re-run pinned, refresh fixtures/, commit. |
spec-cli-surface.md missing | No Node/Python/Go CLI detected | Surface is documented in spec-code-map.md instead. |
| Steal-map is all "steal" | Skipped the park/reject rules | Substrate we delegate is park; doctrine conflicts are reject — not everything novel is worth adopting. |
have/gap/steal/park/reject — not everything marked "steal".Downstream handoff: give the validated steal-map.md to Plan for
one-way-door candidates; ordinary have, park, and
reject decisions remain evidence-backed terminal rows.