Case Review:zhaoxuya520/reverse-skill: case-review,适用于安全分析、取证与威胁排查场景。
Case Review:zhaoxuya520/reverse-skill: case-review,适用于安全分析、取证与威胁排查场景。
> 来源: zhaoxuya520/reverse-skill (15.7k stars) — 安全技能路由
> 原文件: skills/case-review/SKILL.md
> 模型推荐: claude-opus-4-7 (安全分析)
reverse-skill 整合了逆向工程 / 渗透测试 / CTF / 安全分析的"技能路由包" — 52 个 skill,每个对应一类目标(APK/二进制/前端/网络/IoT/Mac/Win)。
michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。
---
1. 用户提到"逆向 / 渗透 / CTF / 取证 / 漏洞"时,触发对应 skill
2. skill 会先 check 用户是否取得授权(否则 ask user)
3. 按 skill 流程执行(取证镜像 / 静态分析 / 动态调试 / 漏洞利用)
4. 涉及破坏性操作前必须 ask user
5. 完工后让 Agent 跑自检
1. 告诉 Agent 你要分析的目标(APK / ELF / JS / 固件 / 等)
2. 如果需要提供文件/镜像/哈希,按 Agent 提示提供
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
---
name: case-review
description: Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
---
Use this skill when a reverse engineering, forensics, CTF, or authorized security case needs a defensible handoff. It audits the existing `work/<case>/` package without changing the case or touching a target.
This skill covers:
It MUST NOT perform reconnaissance, exploitation, dynamic instrumentation, or target changes. Those actions belong to the routed analysis skill and require the case scope gate.
1. `NOW`: read `../field-journal/precedent-reverse.md` and confirm that this is a review of an existing authorized case package.
2. `NOW`: confirm the case path and choose read-only review mode.
3. `NEXT`: read `../tool-index.md`; this skill uses only Python 3 standard library and does not require bootstrap.
4. `NEXT`: run `python3 scripts/review_case.py <case-root> --format markdown`.
5. `ACT`: resolve every error, then rerun the review before claiming a handoff is complete.
| Tool | Required | Purpose | Auto-bootstrap |
|------|----------|---------|---------------|
| Python 3.9+ | Yes | Runs the read-only case review script | No, use the platform Python installation |
No network access or third-party package is required.
Run the review against the existing case directory:
python3 skills/case-review/scripts/review_case.py work/<case> --format markdown
Confirm that `scope.md`, `timeline.md`, `workitems.md`, and `evidence/` are present. A non-strict review reports scope warnings while a strict review treats warnings as handoff blockers.
1. 修复 scope.md 中的授权、范围或 network_profile 字段
2. 继续检查 Evidence 记录的可复现命令和来源
3. 导出当前 review 结果并附到阶段性报告
4. 换 JSON 输出接入 CI 或其他审查工具
5. 暂停,先确认审查范围
Review the checks for:
An offline observation may use `repro_command: n/a` only when its `notes` field explicitly documents the offline limitation.
Use JSON when another tool needs stable fields:
python3 skills/case-review/scripts/review_case.py work/<case> --format json
1. 补写缺失的 Evidence,并保留原始命令
2. 将候选 Finding 绑定到 Evidence 后重新审查
3. 为调用链或攻击链补充 P-id 和 Path 步骤
4. 生成 Markdown handoff summary
5. 换回 PRIMARY skill 继续分析
When an Evidence record contains both `content_hash` and `artifact_path`, verify the case-local artifact:
python3 skills/case-review/scripts/review_case.py work/<case> --verify-hashes --strict
The script accepts `sha256:<64 hex characters>` and checks that the artifact remains inside the case root. A hash mismatch is a hard failure.
The PowerShell Evidence helper can record a hash while appending a record:
powershell -File skills/scripts/append-evidence.ps1 -CaseRoot work\<case> -Id E-001 -Title "Sample hash" -ReproCommand "sha256sum evidence/sample.bin" -ArtifactPath "evidence\sample.bin"
1. 修复 hash mismatch 或替换已污染的工作副本
2. 为未固定的原始文件补充 SHA-256 和 artifact_path
3. 继续进入报告生成阶段
4. 导出 JSON 结果供 CI 保存
5. 暂停并请求人工复核
Use strict mode before a final report or specialist handoff:
python3 skills/case-review/scripts/review_case.py work/<case> --strict --format markdown > work/<case>/report/case-review.md
The command is read-only with respect to the case unless shell redirection is explicitly used to save its output. The review is not legal advice and does not replace organizational evidence handling procedures.
1. 将通过的 review 结果交给 `docs-generator/` 生成正式报告
2. 回到 PRIMARY skill 补齐新的分析证据
3. 归档 Markdown 和 JSON review 结果
4. 暂停并请求人工复核
This skill has no third-party dependency. If Python 3 is unavailable, the only allowed recovery action is the repository bootstrap path when a Python capability is registered for the current platform. If no such capability is registered, stop and report the missing runtime. Do not guess executable paths, download packages, or perform a manual install from inside this skill.
**Upstream entry**: any reverse, forensics, CTF, or authorized security skill that has produced a case package.
**Downstream exit**: `docs-generator/` for a formal report, or the original PRIMARY skill when the graph is incomplete.
**Related modules**: `ops/evidence-finding-path.md`, `ops/timeline-workitem.md`, `digital-forensics/`, `reverse-engineering/`, and `docs-generator/`.
本 skill 专注于Case Review,zhaoxuya520/reverse-skill: case-review。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Case Review相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。
1. 告诉 Agent 你要分析的目标(APK / ELF / JS / 固件 / 等)
2. 如果需要提供文件/镜像/哈希,按 Agent 提示提供
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
本 skill 专注于Case Review,zhaoxuya520/reverse-skill: case-review。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Case Review相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。