case-review skill
Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
Is the case-review skill safe?
Clean: nothing in its files matched our rules. We read 3 files in the folder on 2026-09-28.
No findings.
Install the case-review skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill mkdir -p ~/.claude/skills cp -r /tmp/reverse-skill/skills/case-review ~/.claude/skills/case-review
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Evidence Graph Review
Use this skill when a reverse engineering, forensics, CTF, or authorized security case needs a defensible handoff. It audits the existing work// package without changing the case or touching a target.
Scope
This skill covers:
- Scope metadata and target-activity readiness
- Evidence record structure and reproducibility fields
- References from work items and timeline entries to Evidence
- Structured Findings and Paths in report Markdown
- Optional SHA-256 verification for case-local artifacts
- A Markdown or JSON review result for a report handoff
It MUST NOT perform reconnaissance, exploitation, dynamic instrumentation, or target changes. Those actions belong to the routed analysis skill and require the case scope gate.
ACTION REQUIRED
- NOW: read ../field-journal/precedent-reverse.md and confirm that this is a review of an existing authorized case package.
- NOW: confirm the case path and choose read-only review mode.
- NEXT: read ../tool-index.md; this skill uses only Python 3 standard library and does not require bootstrap.
- NEXT: run python3 scripts/review_case.py --format markdown.
- ACT: resolve every error, then rerun the review before claiming a handoff is complete.
Tool dependencies
No network access or third-party package is required.
Workflow
Phase 1: Intake
Run the review against the existing case directory:
python3 skills/case-review/scripts/review_case.py work/<case> --format markdownConfirm that scope.md, timeline.md, workitems.md, and evidence/ are present. A non-strict review reports scope warnings while a strict review treats warnings as handoff blockers.
建议下一步(选一个编号)
- 修复 scope.md 中的授权、范围或 network_profile 字段
- 继续检查 Evidence 记录的可复现命令和来源
- 导出当前 review 结果并附到阶段性报告
- 换 JSON 输出接入 CI 或其他审查工具
- 暂停,先确认审查范围
Phase 2: Traceability
Review the checks for:
- Evidence IDs that do not exist
- Findings without evidence_ids
- Paths without an allowed path_type or Evidence reference
- Work items and timeline entries pointing to unknown Evidence
- Unlinked Evidence records
- Validated Findings with low confidence
An offline observation may use repro_command: n/a only when its notes field explicitly documents the offline limitation.
Use JSON when another tool needs stable fields:
python3 skills/case-review/scripts/review_case.py work/<case> --format json建议下一步(选一个编号)
- 补写缺失的 Evidence,并保留原始命令
- 将候选 Finding 绑定到 Evidence 后重新审查
- 为调用链或攻击链补充 P-id 和 Path 步骤
- 生成 Markdown handoff summary
- 换回 PRIMARY skill 继续分析
Phase 3: Fixity verification
When an Evidence record contains both contenthash and artifactpath, verify the case-local artifact:
python3 skills/case-review/scripts/review_case.py work/<case> --verify-hashes --strictThe script accepts sha256:<64 hex characters> and checks that the artifact remains inside the case root. A hash mismatch is a hard failure.
The PowerShell Evidence helper can record a hash while appending a record:
powershell -File skills/scripts/append-evidence.ps1 -CaseRoot work\<case> -Id E-001 -Title "Sample hash" -ReproCommand "sha256sum evidence/sample.bin" -ArtifactPath "evidence\sample.bin"建议下一步(选一个编号)
- 修复 hash mismatch 或替换已污染的工作副本
- 为未固定的原始文件补充 SHA-256 和 artifact_path
- 继续进入报告生成阶段
- 导出 JSON 结果供 CI 保存
- 暂停并请求人工复核
Phase 4: Handoff
Use strict mode before a final report or specialist handoff:
python3 skills/case-review/scripts/review_case.py work/<case> --strict --format markdown > work/<case>/report/case-review.mdThe command is read-only with respect to the case unless shell redirection is explicitly used to save its output. The review is not legal advice and does not replace organizational evidence handling procedures.
建议下一步(选一个编号)
- 将通过的 review 结果交给 docs-generator/ 生成正式报告
- 回到 PRIMARY skill 补齐新的分析证据
- 归档 Markdown 和 JSON review 结果
- 暂停并请求人工复核
Language behavior contract
- Internal reasoning, tool selection, and phase control: English.
- User-visible messages, section labels, reports, and next-step menus: Chinese unless the user requests another language.
- Default bilingual labels place Chinese first and English second, separated by /.
Bootstrap boundary
This skill has no third-party dependency. If Python 3 is unavailable, the only allowed recovery action is the repository bootstrap path when a Python capability is registered for the current platform. If no such capability is registered, stop and report the missing runtime. Do not guess executable paths, download packages, or perform a manual install from inside this skill.
Routing context
Upstream entry: any reverse, forensics, CTF, or authorized security skill that has produced a case package.
Downstream exit: docs-generator/ for a formal report, or the original PRIMARY skill when the graph is incomplete.
Related modules: ops/evidence-finding-path.md, ops/timeline-workitem.md, digital-forensics/, reverse-engineering/, and docs-generator/.
References
- NIST SP 800-86: Guide to Integrating Forensic Techniques into Incident Response
- SWGDE Best Practices for Computer Forensic Acquisitions
- SWGDE Best Practices for Archiving Digital and Multimedia Evidence
任务完成自检
- [ ] 我是否审查了 scope.md、timeline.md、workitems.md 和 evidence/?
- [ ] 所有 Finding 是否引用了现存 Evidence?
- [ ] 所有 Path 是否包含合法 path_type 和 Evidence 引用?
- [ ] 是否执行了 hash verification,或记录了未执行原因?
- [ ] 是否以 strict 模式重新运行并保存了 review 结果?
More skills from zhaoxuya520/reverse-skill
- Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
- Capk-reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
- Cattack-chainUse for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
- Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
- Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
- Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
- Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
- Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
- Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-android-hookingInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI boundary inspection, and app trust-boundary analysis. Use when the user asks to hook an APK, inspect signer logic, trace Java or native boundaries, bypass pinning or root checks, inspect shared prefs or app databases, or replay accepted mobile requests. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.