CtrlK
BlogDocsLog inGet started
Tessl Logo

binary-mobile-reversing

APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/binary-mobile-reversing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an extremely token-efficient, highly actionable reversing playbook with concrete commands and anticipated pitfalls, though its multi-step flows lack explicit validation checkpoints. Its biggest defect is structural: it references four bundle files that are absent from the skill, and inlines dense per-platform detail that belongs in those files.

Suggestions

Create the referenced bundle files (references/uniapp-apk-reverse-engineering.md, references/uniapp-apk-reversing.md, scripts/js_rc4_deobfuscate.js, scripts/chengzi_decrypt.py) or remove the broken reference line — currently every cited path is a dead link.

Split the deep per-platform detail (UniApp config-decryption offset tables, RC4 deobfuscation internals, ChengZi SDK decryption) into the per-topic references/*.md files, keeping SKILL.md as a short index with one 🚨 line per platform.

Add explicit validation checkpoints to the multi-step flows (e.g., verify the decoded JS parses with node before batch-decoding, confirm the extracted domain responds before treating it as an API host) with fix-and-retry guidance.

DimensionReasoningScore

Conciseness

Dense telegraphic notes with essentially zero padding and no explanation of concepts Claude already knows; the .so string-deobfuscation pattern is repeated in both the UniApp section and the generic section, a minor duplication that keeps it below anchor 5.

4 / 5

Actionability

Concrete copy-paste commands throughout ("apktool d / jadx", "strings -n8 libapp.so|grep 'https\?://'", "objection android sslpinning disable", "binwalk -Me"); the JS RC4 deobfuscation flow is described as an algorithm in prose rather than executable code, leaving minor gaps versus anchor 5.

4 / 5

Workflow Clarity

Sequences are conveyed via arrow chains (checksec → primitive → info leak → ROP → heap → arbitrary write) and 🚨 trap notes anticipate failure modes, but there are no explicit validation checkpoints or fix-and-retry feedback loops, matching anchor 3.

3 / 5

Progressive Disclosure

The body cites four bundle files ("references/uniapp-apk-reverse-engineering.md", "scripts/js_rc4_deobfuscate.js", "scripts/chengzi_decrypt.py") that do not exist in the bundle, and deep per-platform detail (zlib header offset tables, RC4 decoding internals) is inlined in one monolithic block instead of being split into those references — anchor 2, since the references are broken rather than merely unclear.

2 / 5

Total

13

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it names concrete capability areas, provides an explicit 'Use when...' trigger clause with natural file-extension keywords, and occupies a distinct niche. Its weaknesses are that capabilities are phrased as topic labels rather than actions, and it omits a few natural synonyms (decompile, iOS, binary analysis).

DimensionReasoningScore

Specificity

Lists several concrete capability areas ("UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件") with only minor coverage gaps; capabilities are stated as domain labels rather than action verbs, so it falls below the comprehensive anchor 5 but well above generic anchors.

4 / 5

Completeness

Explicitly answers both what (the enumerated capability list) and when ("Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits") with concrete trigger phrases, matching the anchor-5 example; the when-clause is explicit and specific, so anchor 4's caveat does not apply.

5 / 5

Trigger Term Quality

Natural keywords with file extensions are present ("reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits"), giving good coverage; common synonyms like "decompile", "binary analysis", and "iOS" are missing, so it does not reach anchor 5.

4 / 5

Distinctiveness Conflict Risk

A clear reversing niche with distinct triggers (UniApp, DCloud, .so, APK/EXE), but the breadth across mobile, PE, memory corruption, and IoT creates minor overlap risk with dedicated mobile-security or exploit-development skills.

4 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

referenced_paths_exist

Referenced path issues: 9 missing, 1 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.