Open-source project
soevai/MetaSword avatar
soevai/MetaSword

MetaSword is a themed launcher for reverse engineering and pentest tools

二次元风格逆向渗透集成工具箱,内置AI Agent,面向安全研究与技术学习

402 stars33 forksJavaScriptMIT

At a glance

What is it?
MetaSword is an MIT-licensed desktop toolbox whose README names IDA Pro, x64dbg, dnSpy, Cheat engine, Burp Suite, Yakit and Tscan as the tools it works with. The repository is three files deep with all implementation in `app/`, and the AI agent the project description advertises appears nowhere in the documentation.
Who is it for?
Treat MetaSword as a themed launcher to try on a machine where you already have the professional tools installed, and judge it by whether the UI earns its place against your own launcher or dock.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 14 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 5, 2026, and from our analysis. They are not legal advice.

Editorial analysis

app/ holds the implementation, and the README is mostly screenshots

The repository has three top-level entries: `LICENSE`, `README.md` and `app/`. That is the entire tree as published, with the primary language recorded as JavaScript and the licence as MIT.

What the README contains is a title, a short piece of prose in Chinese, and then a sequence of feature sections whose contents are image references: two named interface themes, a tool category page, a reverse engineering section, a penetration testing section and a user interface section. There is no install command, no package manifest, no configuration file and no changelog in the tree.

The homepage is separate from the repository, at `https://www.52tt.pro/tools/sword/`. Builds come from GitHub Releases rather than a package registry, so there is no `pip`, `npm` or `apt` route here.

For a project whose pitch is a coherent toolkit, what is missing from the repository is as informative as what is there. There are no screenshots you can inspect from the source tree alone, no dependency list, and nothing that tells you what the launcher requires of the tools it drives.

IDA Pro, x64dbg, dnSpy and Cheat engine are named as collaborators

The reverse engineering section claims a one-stop experience for disassembly, debugging and analysis, and then names four tools it supports: `IDA Pro`, `x64dbg`, `dnSpy` and `Cheat engine`.

The word used is collaboration, and the README does not go further than that. It does not say whether the launcher invokes these programs, attaches to a running process, drives their command line, or configures them. It does not describe a plugin interface, a plugin directory, or a manifest format. It does not state which versions it was built against, and for a tool that reads other tools' memory layouts, versions matter more than they usually do.

What can be said from the file list is that none of these four is bundled. None of them is MIT licensed, and none appears as a vendored directory in a tree that holds nothing but `app/`. So the practical model is that you install them yourself, and MetaSword sits on top.

That makes the project's own claim the thing to test. Whether a single window around four already-installed tools saves you time depends entirely on what it does between them, and the README does not answer that.

Burp Suite, Yakit and Tscan are listed as environments

The penetration testing section has a similar shape. It covers attack-surface scoring during organised defence exercises, protocol analysis and CTF work, and it names four environments: `Burp Suite`, `Yakit`, `Tscan` and `ez`.

The framing word here is environment rather than tool, which is a different claim from what the reverse engineering section makes. An environment suggests MetaSword provides the surrounding conditions: a workspace, notes, targets, maybe capture and replay, while the named programs remain the tools you act with. Either reading is possible from the text.

Four of the seven named programs are Chinese-market tools or an open-source Chinese platform, which is consistent with the project's audience and its 52tt.pro host. `Yakit` in particular is itself an all-in-one security platform, so a launcher that integrates it sits in an unusual position, offering a shell around something that already is a toolbox.

None of this is described as an API, a config file or a script. The README does not say how these four are wired in either.

The AI agent is in the project description and nowhere else

The repository description says this is an anime-styled reverse engineering and penetration testing toolbox with a built-in AI Agent, aimed at security research and technical learning. The README never mentions it.

There is no section on it, no screenshot described in the text, no model name, no provider, no key configuration, and no statement about what it is allowed to do. Given that the rest of the README is careful to name seven external tools by name, the omission reads as unfinished rather than as a deliberate privacy choice.

This matters more than the other gaps, because an agent inside a reverse engineering launcher has an unusual risk profile. A process that reads another program's memory, launches debuggers and watches traffic is in a position to act on a model suggestion, and an agent that can do that needs a stated boundary on what it will touch. The repository gives you none.

So the AI agent is the part of this project to verify before anything else, and verifying it means running it, since the answer is not in the source tree.

The default branch is named v1.1.0-Beta

The default branch is `v1.1.0-Beta`, which is unusual enough to be worth reading twice. A branch named after a version that is also marked beta means the published code and the published release are the same thing by construction.

The release history shows a single entry named `Latest` dated 2026-09-03. It carries no version number, so there is no tag to compare a checkout against, and no way to tell from the repository whether the release artefact matches the default branch at any later point.

The last push to that branch was on 2026-09-23, three weeks after the release, which is normal activity for a project in beta and also means the release does not contain whatever changed in those three weeks.

Nothing here is archived, so this is a live project. What it is not is a project with a release trail you can audit. For a tool that sits next to debuggers and traffic interceptors, being able to say exactly which build you have is worth more than it would be for a static library.

Two theme names and one category page are the whole interface story

The feature list names two themes, one described as the origin palette and one in a muted purple-grey, then a tool category page, then the reverse engineering and penetration sections. The user interface section claims a minimal, lightweight design that is friendly to beginners while maximising efficiency for advanced users, which is the sort of sentence that describes a target rather than a behaviour.

There is nothing in the repository about theming beyond the names. No theme file format, no user stylesheet directory, no documented settings key. For a launcher whose selling point is partly visual identity, that is the second-largest gap after the AI agent.

The categories themselves are also unlisted. The tool category page is named as a destination, and the README does not enumerate what is in it, so you cannot tell from the text whether it holds twenty launch targets or two hundred.

What is documented, then, is a category of software rather than a capability: a themed front end over professional tools you install yourself, aimed at people learning security work on a Windows desktop.

Editorial conclusion

Treat MetaSword as a themed launcher to try on a machine where you already have the professional tools installed, and judge it by whether the UI earns its place against your own launcher or dock. Do not adopt it as a research platform on the strength of its description, because the built-in AI agent that headline claim rests on is not described in the README, the implementation sits entirely in `app/`, and the repository publishes no package metadata, tests or install instructions. Verify first that the release you download matches what the tool actually launches, since the repository offers a single unnamed release from 2026-09-03 while the default branch is named `v1.1.0-Beta`.

Frequently asked questions

What is MetaSword used for?

It is presented as a themed launcher for reverse engineering and penetration testing work, aimed at security research and technical learning. The README names the tools it works with rather than describing tasks it performs on its own.

Which tools does MetaSword work with?

For reverse engineering it names `IDA Pro`, `x64dbg`, `dnSpy` and `Cheat engine`. For penetration testing it names `Burp Suite`, `Yakit`, `Tscan` and `ez` as environments. None of them is bundled in the repository.

How do I install MetaSword?

The README gives no install command and the repository holds only `LICENSE`, `README.md` and `app/`, with no package manifest. Builds come from GitHub Releases, and the project has a separate homepage at `https://www.52tt.pro/tools/sword/`.

Does MetaSword have a built-in AI agent?

The repository description says it does, and the README never mentions it again. No model, provider, key configuration or documented behaviour appears in the documentation available in the repository.

What licence is MetaSword under?

MIT, with the `LICENSE` file at the repository root. The named third-party tools it works with carry their own licences and are not redistributed.

Official sources

  1. License: MIT
  2. Project website
  3. README
  4. Releases
  5. soevai/MetaSword on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/soevai-metasword.svg)](https://hysenlabs.com/projects/soevai-metasword)