CtrlK
BlogDocsLog inGet started
Tessl Logo

js-reverse

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/js-reverse/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable orchestration skill with a clear staged workflow and verified one-level reference bundle; the main gaps are implicit mid-stage validation checkpoints and minor verbosity.

Suggestions

Add explicit validation checkpoints inside the Capture/Patch stages (e.g. 'after each patch: re-run and confirm first divergence advanced before continuing') rather than relying on the end self-check.

Move the full js-reverse_* tool mapping table or the bootstrap table into a reference file, keeping only the most-used mappings inline to further trim tokens.

Tighten the '路由上下文' block to a compact routing list; the upstream/peer/downstream prose largely duplicates the '必读引用' and 适用范围 sections.

DimensionReasoningScore

Conciseness

Mostly lean imperative rules and tight stage descriptions that assume Claude's competence; minor verbosity in '适用范围' and '路由上下文' that could be trimmed without losing meaning.

4 / 5

Actionability

Concrete tool-name mappings (js-reverse_list_scripts, etc.) and an executable PowerShell bootstrap command give largely actionable guidance, with only minor gaps where guidance stays rule-based rather than copy-paste.

4 / 5

Workflow Clarity

A clear five-stage Observe→Capture→Rebuild→Patch→DeepDive sequence with per-stage goals, a '必须产出' checkpoint for Observe, and an end completion self-check; validation checkpoints within later stages are implicit rather than explicit.

4 / 5

Progressive Disclosure

Twelve one-level-deep reference files all exist and are listed in a dedicated '必读引用' section with routing context; navigation is clear, though some inline lists (tool mapping, bootstrap table) could arguably live in references.

4 / 5

Total

16

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-bounded description that answers both what and when and routes to adjacent skills, but its trigger terms are jargon-heavy and miss the natural phrases a user would say.

Suggestions

Add natural user-facing trigger phrasing to the description, e.g. 'Use when the user asks to reverse a frontend signature, find an encrypted parameter, or reproduce a browser-side algorithm locally'.

Include common synonyms / file-type triggers a user might mention (e.g. 'XHR/fetch 签名', 'webpack 混淆') alongside the technical terms.

Tighten '证据化输出' into a concrete deliverable like '生成可复现的取证报告' to reduce residual abstraction.

DimensionReasoningScore

Specificity

Names the domain (frontend JS reverse engineering) and several concrete actions — 签名链路定位, 页面观察取证, 运行时采样, 本地补环境复现, 证据化输出 — giving good coverage with only minor abstract phrasing like '证据化输出'.

4 / 5

Completeness

Both 'what' (frontend JS reverse engineering) and 'when' (适用于签名链路定位…) are present, with the 适用于 trigger clause explicit; the 'when' could be framed more in natural user phrasing rather than capability listing.

4 / 5

Trigger Term Quality

Relevant keywords exist (前端 JavaScript 逆向, 签名, CDP, Hook) but they lean technical and miss common natural variations a user would actually say, e.g. no plain synonyms or file-extension triggers.

3 / 5

Distinctiveness Conflict Risk

Clear niche tied to js-reverse_* and jshookmcp, with explicit routing to adjacent skills (ida-reverse, reverse-engineering), giving low conflict risk with only minor overlap against sibling reverse skills.

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.