逆向工程 Case Review

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计CaseReview

Case Review:zhaoxuya520/reverse-skill: case-review,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

逆向工程 Case Review

摘要

Case Review:zhaoxuya520/reverse-skill: case-review,适用于安全分析、取证与威胁排查场景。

> 来源: zhaoxuya520/reverse-skill (15.7k stars) — 安全技能路由

> 原文件: skills/case-review/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析)

这个 skill 是干嘛的

reverse-skill 整合了逆向工程 / 渗透测试 / CTF / 安全分析的"技能路由包" — 52 个 skill,每个对应一类目标(APK/二进制/前端/网络/IoT/Mac/Win)。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"逆向 / 渗透 / CTF / 取证 / 漏洞"时,触发对应 skill

2. skill 会先 check 用户是否取得授权(否则 ask user)

3. 按 skill 流程执行(取证镜像 / 静态分析 / 动态调试 / 漏洞利用)

4. 涉及破坏性操作前必须 ask user

5. 完工后让 Agent 跑自检

👤 用户需要做什么?

1. 告诉 Agent 你要分析的目标(APK / ELF / JS / 固件 / 等)

2. 如果需要提供文件/镜像/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(zhaoxuya520/reverse-skill/skills/case-review/SKILL.md,截断到 12k chars)

---

name: case-review

description: Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.

---

Evidence Graph Review

Use this skill when a reverse engineering, forensics, CTF, or authorized security case needs a defensible handoff. It audits the existing `work/<case>/` package without changing the case or touching a target.

Scope

This skill covers:

It MUST NOT perform reconnaissance, exploitation, dynamic instrumentation, or target changes. Those actions belong to the routed analysis skill and require the case scope gate.

ACTION REQUIRED

1. `NOW`: read `../field-journal/precedent-reverse.md` and confirm that this is a review of an existing authorized case package.

2. `NOW`: confirm the case path and choose read-only review mode.

3. `NEXT`: read `../tool-index.md`; this skill uses only Python 3 standard library and does not require bootstrap.

4. `NEXT`: run `python3 scripts/review_case.py <case-root> --format markdown`.

5. `ACT`: resolve every error, then rerun the review before claiming a handoff is complete.

Tool dependencies

| Tool | Required | Purpose | Auto-bootstrap |

|------|----------|---------|---------------|

| Python 3.9+ | Yes | Runs the read-only case review script | No, use the platform Python installation |

No network access or third-party package is required.

Workflow

Phase 1: Intake

Run the review against the existing case directory:

python3 skills/case-review/scripts/review_case.py work/<case> --format markdown

Confirm that `scope.md`, `timeline.md`, `workitems.md`, and `evidence/` are present. A non-strict review reports scope warnings while a strict review treats warnings as handoff blockers.

建议下一步(选一个编号)

1. 修复 scope.md 中的授权、范围或 network_profile 字段

2. 继续检查 Evidence 记录的可复现命令和来源

3. 导出当前 review 结果并附到阶段性报告

4. 换 JSON 输出接入 CI 或其他审查工具

5. 暂停,先确认审查范围

Phase 2: Traceability

Review the checks for:

An offline observation may use `repro_command: n/a` only when its `notes` field explicitly documents the offline limitation.

Use JSON when another tool needs stable fields:

python3 skills/case-review/scripts/review_case.py work/<case> --format json

建议下一步(选一个编号)

1. 补写缺失的 Evidence,并保留原始命令

2. 将候选 Finding 绑定到 Evidence 后重新审查

3. 为调用链或攻击链补充 P-id 和 Path 步骤

4. 生成 Markdown handoff summary

5. 换回 PRIMARY skill 继续分析

Phase 3: Fixity verification

When an Evidence record contains both `content_hash` and `artifact_path`, verify the case-local artifact:

python3 skills/case-review/scripts/review_case.py work/<case> --verify-hashes --strict

The script accepts `sha256:<64 hex characters>` and checks that the artifact remains inside the case root. A hash mismatch is a hard failure.

The PowerShell Evidence helper can record a hash while appending a record:

powershell -File skills/scripts/append-evidence.ps1 -CaseRoot work\<case> -Id E-001 -Title "Sample hash" -ReproCommand "sha256sum evidence/sample.bin" -ArtifactPath "evidence\sample.bin"

建议下一步(选一个编号)

1. 修复 hash mismatch 或替换已污染的工作副本

2. 为未固定的原始文件补充 SHA-256 和 artifact_path

3. 继续进入报告生成阶段

4. 导出 JSON 结果供 CI 保存

5. 暂停并请求人工复核

Phase 4: Handoff

Use strict mode before a final report or specialist handoff:

python3 skills/case-review/scripts/review_case.py work/<case> --strict --format markdown > work/<case>/report/case-review.md

The command is read-only with respect to the case unless shell redirection is explicitly used to save its output. The review is not legal advice and does not replace organizational evidence handling procedures.

建议下一步(选一个编号)

1. 将通过的 review 结果交给 `docs-generator/` 生成正式报告

2. 回到 PRIMARY skill 补齐新的分析证据

3. 归档 Markdown 和 JSON review 结果

4. 暂停并请求人工复核

Language behavior contract

Bootstrap boundary

This skill has no third-party dependency. If Python 3 is unavailable, the only allowed recovery action is the repository bootstrap path when a Python capability is registered for the current platform. If no such capability is registered, stop and report the missing runtime. Do not guess executable paths, download packages, or perform a manual install from inside this skill.

Routing context

**Upstream entry**: any reverse, forensics, CTF, or authorized security skill that has produced a case package.

**Downstream exit**: `docs-generator/` for a formal report, or the original PRIMARY skill when the graph is incomplete.

**Related modules**: `ops/evidence-finding-path.md`, `ops/timeline-workitem.md`, `digital-forensics/`, `reverse-engineering/`, and `docs-generator/`.

References

任务完成自检

常见问题(FAQ)

使用「Case Review」这个 skill 能解决什么问题?

本 skill 专注于Case Review,zhaoxuya520/reverse-skill: case-review。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Case Review」?

当你需要在Case Review相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Case Review」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。

FAQ

👤 用户需要做什么?

1. 告诉 Agent 你要分析的目标(APK / ELF / JS / 固件 / 等)

2. 如果需要提供文件/镜像/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

[ ] 是否以 strict 模式重新运行并保存了 review 结果?
使用「Case Review」这个 skill 能解决什么问题?

本 skill 专注于Case Review,zhaoxuya520/reverse-skill: case-review。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Case Review」?

当你需要在Case Review相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Case Review」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。