Model or dataset
lingbol088-spec/reverse-flow-skill avatar
lingbol088-spec/reverse-flow-skill

reverse-flow-skill: a CTF reverse engineering workflow for AI agents and Codex

面向 AI Agent / Codex 的本地 CTF 逆向工程流程技能。加载后通过“真心为你”进入逆向模式,默认在本地沙盒、CTF、crackme、wargame 或训练靶场环境中工作,按“分析 → 报告 → 逆向 → 深度逆向 → 漏洞研判 → 用户选择下一步”的流程推进。

910 stars328 forksPythonMIT

At a glance

What is it?
This is a prompt-and-script skill that pushes an AI agent through a fixed reverse engineering pipeline inside a local sandbox. It is written for CTF, crackme and wargame work, and its install step is a single directory copy into the Codex skills folder.
Who is it for?
Adopt reverse-flow-skill if you already run Codex or a comparable agent and you want reverse engineering tasks to follow a repeatable analysis, report, reverse, deep reverse and vulnerability assessment order instead of drifting. Do not adopt it if you need a packaged tool with a versioned installer, a Windows-first workflow without a bash equivalent, or any use outside a sandbox, CTF or explicitly authorized environment.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 69 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What reverse-flow-skill is for, and who it is aimed at

reverse-flow-skill is a skill package for an AI agent, described in its README as a local CTF reverse engineering workflow skill for AI Agent and Codex. The problem it addresses is not disassembly or decompilation. It addresses the fact that an agent asked to reverse a binary tends to wander: it may jump straight to a patch, skip triage, or produce an answer with no recorded evidence. The skill imposes a sequence instead. The README states the flow as analysis, then report, then reverse, then deep reverse, then vulnerability assessment, then a user choice of next step.

The intended user is someone working in a local sandbox, a CTF, a crackme or wargame, a training range, or an offline sample analysis environment. The README says the skill treats those as the default context, so the user does not have to repeat that this is a CTF or a local range every turn. That default is a design decision with consequences, and it is worth reading carefully before you install anything.

The interaction model is split by language. The README describes an English core prompt with Chinese user interaction: execution rules, tool selection and flow control are written in English for model stability, while the activation phrase, report structure and next-step menu are Chinese. If your team does not read Chinese, the entry point and the output structure will need translation before the skill fits your process.

How the pipeline advances from triage to a next-step menu

The mechanism is a fixed stage machine rather than a free-form assistant. The README lists six stages in a single chain: analysis, report, reverse, deep reverse, vulnerability assessment, and user choice of the next step. The report stage comes second, before any patching, which means the agent is expected to record what it found before it acts on it. The final stage hands control back to the user rather than letting the agent continue on its own.

A second mechanism handles imprecise requests. The README gives a normalization table mapping colloquial phrasing to intended action. Unlock XX maps to locating a feature gate or validation branch, explaining the logic, and giving a local patch or the correct input path. Remove XX maps to locating a check routine, recording evidence, and giving a patch or debugging plan on a copy. Bypass anti-debug maps to analyzing the anti-debug logic and offering a local debugging configuration or patch option. Make it pass maps to recovering the validation logic and deriving the expected input, state transition or flag format. Get the flag maps to analyzing the verification flow, the encoding or encryption logic, and the trigger condition.

The README also states that when a user request is unclear, the skill performs intent recovery first instead of stopping. Combined with the table, that means the agent is instructed to guess at a category and proceed. This is the part of the design I would watch: intent recovery is useful when the guess is cheap to correct, but on a real binary a wrong category sends the agent down a check-routine hunt when the user wanted something else.

The repository layout backs the description. The top level holds LICENSE, README.md and a skills directory, and the skill itself lives under skills/reverse-flow with SKILL.md, README.md, an agents/openai.yaml file, references and scripts.

Installing reverse-flow-skill into the Codex skills directory

The README gives one installation step: copy the skill directory into the Codex skills directory. The example is PowerShell, which suggests a Windows-first authoring environment. There is no package on a registry and no installer script for the skill itself.

powershell
Copy-Item -Recurse ".\skills\reverse-flow" "$env:USERPROFILE\.codex\skills\reverse-flow"

Run this from the repository root. The destination path is built from the USERPROFILE environment variable plus .codex\skills, so the result should be a reverse-flow folder inside your Codex skills directory. If you are on Linux or macOS, the README does not provide an equivalent command, and you will need to translate the copy yourself.

Once the folder is in place, the activation phrase is the literal text 真心为你. The README shows the prompt the skill returns after activation: it announces that reverse mode is entered and asks for a sample, binary, firmware, APK, script, crash log, patch diff or analysis target, then restates the six-stage flow. A usage example in the README combines the skill handle with the phrase.

text
使用 $reverse-flow 分析这个样本。真心为你

The second README example is more specific and is the one worth copying when you first try it: enter reverse mode, upload a crackme, and ask for the flag validation logic. If the agent does not respond with the reverse-mode prompt, the skill was not discovered, and the placement of the folder is the first thing to check.

The four Python scripts that carry the workflow

The skill is not only prompt text. The README lists four scripts under skills/reverse-flow/scripts, and they map onto the early stages of the pipeline. create_case.py opens a case with a name, a goal and an output directory. triage_artifact.py takes an artifact and writes triage output. tool_audit.py checks the toolchain against a named profile. report_from_triage.py consumes triage JSON and emits an initial report.

powershell
python ".\skills\reverse-flow\scripts\create_case.py" --case-name sample-audit --goal "local CTF reverse analysis" --out ".\work"
python ".\skills\reverse-flow\scripts\triage_artifact.py" ".\sample.bin" --out ".\work\sample-audit\triage"
python ".\skills\reverse-flow\scripts\tool_audit.py" --profile native --out ".\work\sample-audit\tools\native-tool-audit.md"
python ".\skills\reverse-flow\scripts\report_from_triage.py" ".\work\sample-audit\triage\*.json" --out ".\work\sample-audit\reports\initial-report.md"

The flags shown are the ones the README documents: --case-name, --goal, --out, --profile. The profile value in the example is native. The output paths form a case directory convention: work, then sample-audit, then triage, tools and reports subfolders. The report script takes a glob, so it expects the triage stage to have written JSON into that triage folder first.

This is the most concrete part of the project and also the least documented. The README gives the script names and one invocation each but does not describe what triage_artifact.py detects, what profiles tool_audit.py accepts beyond native, or what fields the triage JSON contains. Treat the four commands as a starting point to run and inspect, not as a specified interface.

Where reverse-flow-skill is the wrong choice

The default context is the main limitation. The README states the skill assumes a local CTF environment, crackme or wargame, a local training range, an authorized sandbox reverse engineering experiment, or an offline sample analysis environment. If your work does not sit inside one of those, this skill is not the tool. It is not positioned for analyzing software you are not authorized to analyze, and the normalization table's patch and bypass entries only make sense on a copy in a sandbox.

The engineering limitations are separate. First, the install is a folder copy with no versioning, no dependency declaration and no uninstall path. The README does not document rollback. Upgrading means replacing the copied directory and hoping nothing in your local edits is lost. Second, the README does not state a Python version requirement or list the scripts' dependencies, even though the scripts are Python and the repository's primary language is Python. Third, the documented install command is PowerShell only. Fourth, the README carries community links and a sponsorship section alongside the MIT license text, and the license section as rendered is thin; the repository does have a LICENSE file at the top level, so the MIT terms are in the repository rather than only in the README prose.

There is also a scope limit worth naming plainly. This is a workflow skill. It does not ship a disassembler, a debugger or a decompiler. It organizes an agent's use of whatever toolchain you already have, and tool_audit.py exists precisely because the skill expects to check for tools rather than provide them. If you were hoping for an analysis engine, you are looking at the wrong layer.

How it differs from a general purpose agent skill

The realistic alternative is not another reverse engineering product. It is a general agent skill or plain prompting: you write your own instructions, or you install a broad skill collection and let the agent decide its own order of operations. The difference in approach is that reverse-flow-skill fixes the order. Analysis, then a report, then reversing, then deep reversing, then vulnerability assessment, then a user decision. A general skill leaves that sequence to the model, which is more flexible and less predictable.

The second difference is the normalization table. A general skill relies on the model to infer what unlock or make it pass means in a reversing context. This project writes the mapping down as a table, so the interpretation is part of the artifact rather than something the model improvises each session. That is the strongest argument for the project: the mapping is inspectable and editable.

The third difference is the case directory convention. The four scripts write into a named case folder with triage, tools and reports subfolders, and the report is generated from triage JSON rather than from conversation history. A general skill typically leaves artifacts wherever the conversation put them. If you value a reproducible folder per sample, that convention is the reason to pick this over a generic skill; if you value an agent that adapts its process to the target, a general skill will fit better.

Maintenance, licence and what to check before adopting

The repository is not archived. The last push was on 2026-07-24, which is recent enough that the project cannot be described as abandoned, but the README documents no release cadence, no changelog and no upgrade procedure. The only release listed is a Python one-click deployment version dated 2026-07-01. On the evidence available, plan for the cost of maintaining your own copy: the install is a directory copy, so every update is a manual replacement, and the README gives no way to tell which version you are running.

The licence is MIT, stated in the README and present as a LICENSE file at the repository root. MIT is permissive, which means the usual obligations apply: keep the licence text with any redistribution. Nothing in the repository suggests a copyleft or commercial restriction. This is a description of what the repository states, not legal advice; if you are redistributing the skill inside a product, have your own counsel read the LICENSE file rather than the README summary.

The practical checklist before you commit to it is short. Confirm the scripts folder contains the four Python files the README names. Confirm your agent loads skills from the path you copied into. Run create_case.py once into a scratch directory and look at what it creates before you point the skill at a real sample. And read SKILL.md, since the README describes the skill's behaviour at a summary level while SKILL.md is where the actual instructions live.

Editorial conclusion

Adopt reverse-flow-skill if you already run Codex or a comparable agent and you want reverse engineering tasks to follow a repeatable analysis, report, reverse, deep reverse and vulnerability assessment order instead of drifting. Do not adopt it if you need a packaged tool with a versioned installer, a Windows-first workflow without a bash equivalent, or any use outside a sandbox, CTF or explicitly authorized environment. Before relying on it, verify three things yourself: that the scripts directory and its four Python entry points exist in your checkout, that your agent actually discovers skills placed under the Codex skills path, and that the flow it imposes matches how you want a report structured. The README documents no rollback and no upgrade procedure, so plan on replacing the copied folder by hand.

Frequently asked questions

How do I install reverse-flow-skill for Codex?

The README gives one step: copy the skills/reverse-flow directory into your Codex skills directory, using the PowerShell Copy-Item -Recurse example with the destination $env:USERPROFILE\.codex\skills\reverse-flow. There is no package registry install and no installer script for the skill itself.

What does the activation phrase 真心为你 do in reverse-flow-skill?

It is the startup word that puts the agent into reverse mode. After activation the skill replies that reverse mode is entered and asks for a sample, binary, firmware, APK, script, crash log, patch diff or analysis target, then states the six-stage flow.

What is the workflow order in reverse-flow-skill?

The README states the order as analysis, report, reverse, deep reverse, vulnerability assessment, and then a user choice of the next step. The report stage comes before the reversing stages, and the last stage returns control to the user.

Which environments does reverse-flow-skill assume by default?

The README says the skill defaults to a local CTF environment, crackme or wargame, a local training range, an authorized sandbox reverse engineering experiment, or an offline sample analysis environment. The stated purpose of that default is that the user does not have to repeat each turn that the target is a CTF or a local range.

What Python scripts does reverse-flow-skill ship with?

The README lists create_case.py, triage_artifact.py, tool_audit.py and report_from_triage.py under skills/reverse-flow/scripts. They cover case creation, artifact triage, toolchain auditing against a profile, and generating an initial report from triage JSON.

What licence does reverse-flow-skill use?

The repository is MIT licensed, stated in the README and present as a LICENSE file at the top level. MIT is permissive, so the usual obligation to keep the licence text with redistributions applies.

Official sources

  1. Issues
  2. License: MIT
  3. lingbol088-spec/reverse-flow-skill on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/lingbol088-spec-reverse-flow-skill.svg)](https://hysenlabs.com/projects/lingbol088-spec-reverse-flow-skill)