dhicoc/dsh-reverse-skill
Complete reverse-skill (85 SKILL.md) as a DeepSeek Harness (dsh) Cordis plugin — reverse engineering, authorized pentesting and security research skill pack.
Listed
30
Skill
Bundle verified
Preview
What it does
Complete reverse-skill pack (85 SKILL.md) as a DeepSeek Harness Cordis plugin: reverse engineering, authorized pentesting and security-research skill router.
Best for
- Authorized reverse-engineering, penetration-testing, CTF, and security-research workflows that benefit from a broad skill router.
- DSH users who want 85 packaged SKILL.md resources registered automatically through a Cordis provider.
- Researchers who need both general domain skills and CTF-oriented skill coverage in one plugin.
Not ideal for
- Any testing or access performed without explicit authorization from the target owner.
- Workflows that depend on the upstream OpenAI Agents SDK agent definitions, which are not included.
- Users expecting DSH to enforce allowed-tools/disallowed-tools fields or expecting referenced MCP servers such as burp-mcp to be bundled.
README
dsh-reverse-skill
reverse-skill 的完整 DeepSeek Harness(dsh)插件版。 把上游
zhaoxuya520/reverse-skill(25k★,MIT)全部 85 个 SKILL.md 原样封装成一个 dsh Cordis 插件,随包分发、随插件加载,无需手动维护候选清单。
这是什么
-
完整移植:85 个 skills =
skills/下 43 个(60+ 领域技能经去重后的真实 SKILL.md 数)+CTF-Sandbox-Orchestrator/下 42 个(CTF 赛道技能)。与上游一一对应,不裁剪、不挑捡。 -
插件形态(你选的):以 dsh 一等公民的
skillseam(ctx.skills)注册一个 provider,harness 启动时自动把全部技能注入可用技能库。 -
对比已有不完全移植:社区里的
dsh-reverse-security只移植了 45 个、且是 preset-only(无 Cordis 插件)。本仓库补齐到 85 个并提供正式插件入口。
适用范围(请遵守)
本仓库内容仅用于 授权的 逆向工程、渗透测试与安全研究。使用者须确保对目标系统拥有合法授权。一切未授权行为与本仓库无关。
目录结构
dsh-reverse-skill/
├── src/
│ └── index.ts # 数据驱动的 Cordis 插件:递归扫描并注册全部 SKILL.md
├── skills/ # 43 个领域技能(上游 skills/ 1:1 复制)
│ ├── reverse-skill-router/ # 路由技能(由上游 skills/SKILL.md 重构成目录)
│ ├── pentest-tools/ # 含嵌套子技能 src-hunter 等
│ └── reverse-engineering/ # 含嵌套子技能 dsl-vm-reverse 等
├── CTF-Sandbox-Orchestrator/ # 42 个 CTF 赛道技能
├── port.py # 归一化脚本(上游 → 本仓库的搬运/前导matter修正)
├── package.json
├── tsconfig.json
└── LICENSE # MIT(与上游一致)
相对路径:
src/index.ts通过fileURLToPath(new URL('../skills', import.meta.url))定位资源(编译后lib/index.js同样成立,因为skills/与lib/同属包根目录的相邻子目录)。注意这里不能再套一层dirname()——../skills这个 URL 已经指向目录本身,多套dirname会把它截断成包根目录,从而把node_modules里的 SKILL.md 也算进来。
安装(插件形态)
1. 安装依赖与构建
# 安装 peer 依赖(cordis / dsh-skill 由 dsh 运行时提供,这里用于类型与构建)
npm install
npm run build # tsc → 生成 lib/ 与 lib/types/
package.json 中已声明:
"main": "lib/index.js",
"types": "lib/types/index.d.ts",
"peerDependencies": {
"@deepseek-ai/cordis": "^4.0.1",
"@deepseek-ai/dsh-skill": "^0.0.1-rc.1"
}
2. 在 dsh 中启用本插件
本仓库已声明 dsh.bundle manifest(见 cordis.patch.yml),因此可直接用一行命令安装并激活:
# 从 GitHub 安装并激活(推荐)
dsh plugin add github:dhicoc/dsh-reverse-skill
安装后 dsh 会读取 cordis.patch.yml 把 reverse-skill 这个 Cordis 插件插入当前 profile,启动时自动注册 85 个技能。若你想在 profile / package 配置里手动引用,包名是 @dhicoc/dsh-reverse-skill:
# dsh 配置(示例,键名可能因版本而异)
plugins:
- "@dhicoc/dsh-reverse-skill"
加载后,插件在 apply(ctx) 里调用 ctx.skills.registerProvider(...),把 85 个技能注册进 ctx.skills。模型可通过 ctx.skills → tool-skill 自动调用,用户也可通过技能名手动调用(受各 SKILL.md 的 user-invocable 控制)。
3. (可选)非插件回退:直接当 preset 用
本仓库同时携带完整的 skills/ 与 CTF-Sandbox-Orchestrator/ 目录,可作为 preset 直接挂载,无需构建:
skills:
local:
customSkillDirs:
- "./dsh-reverse-skill/skills"
- "./dsh-reverse-skill/CTF-Sandbox-Orchestrator"
dsh 技能发现优先级(先命中先生效):项目
.dsh→ 项目.agents→customSkillDirs→ 用户.dsh→ 用户.agents。扁平发现,不接受递归**/SKILL.md,所以路由技能必须是reverse-skill-router/SKILL.md这样的目录结构(本仓库已处理好)。
插件工作原理(数据驱动,零手写清单)
src/index.ts 不做任何硬编码候选列表,而是:
- 递归遍历
skills/与CTF-Sandbox-Orchestrator/,找到每个SKILL.md; - 解析前导 matter(含把
metadata.user-invocable提升为顶层user-invocable、when_to_use→whenToUse的归一化); - 构造
SkillCandidate(含resourceBase: {kind:'directory', path}、结果缓存); - 注册一个
SkillProvider,get()时返回完整 body。
新增/删除技能只需改目录,插件自动同步。
可复跑验证
在仓库根目录运行:
npm test
该命令会重新编译插件,并通过实际注册的 SkillProvider 断言 85 个已打包技能都能被 list() 发现、名称无重复且均能按需 get() 返回非空正文。测试还会临时创建一个带 UTF-8 BOM 和 CRLF 的 SKILL.md,确认扫描器不会静默跳过此类文件;fixture 在测试结束后会自动删除。发布工作流也会在 npm publish 前运行同一检查。
已知限制(诚实告知)
-
agents/*.yaml不可移植:上游 43 个 OpenAI Agents SDK 的 agent 定义无法映射到 dsh 的ctx.subagent(dsh 仅支持拉起 Codex / Claude Code CLI)。这些 agent 定义未纳入插件。 -
allowed-tools/disallowed-tools不被 dsh 强制:dsh 当前把这两项视为未知字段,延迟执行。技能内的工具约束需自行在 harness 层保证。 -
camelCase 前导 matter 字段(如
when_to_use)会被 dsh 拒绝:port.py已统一修正为whenToUse、user-invocable等受支持字段。 -
MCP 工具(如 burp-mcp)需另行配置:技能正文里引用的外部 MCP server 不在本插件范围内,请按 dsh 的
mcp.servers自行接入。 -
文档链接已重写:正文内相对链接已改为
../(及 CTF 相关为../../CTF-Sandbox-Orchestrator/),以适配 dsh 扁平挂载路径。
License
LICENSE 为 MIT,与上游 reverse-skill 保持一致。内容版权归原 upstream 作者与贡献者;本仓库为 dsh 适配封装。
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:dhicoc/dsh-reverse-skill in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.