本文へ移動
cccskills
無料GitHub で公開

reverse-engineer

Tear down a competitor's repo or product into a feature inventory and adoption choices. Use when: comparing us to another tool or asking what to steal.

インストール方法を見る

含まれるファイル(41)

  • SKILL.md8.4 KB
  • .gitignore19 B
  • agents/openai.yaml296 B
  • fixtures/cc-sdd-v2.1.0/cli-surface-contracts.txt1.4 KB
  • fixtures/cc-sdd-v2.1.0/clone-metadata.json156 B
  • fixtures/cc-sdd-v2.1.0/docs-features.txt454 B
  • fixtures/cc-sdd-v2.1.0/feature-registry.yaml843 B
  • references/invocation.md5.5 KB
  • references/reverse-engineer.feature2.4 KB
  • references/templates/postmortem.md.tmpl433 B
  • references/templates/security/attack-surface.md.tmpl310 B
  • references/templates/security/authn-authz.md.tmpl294 B
  • references/templates/security/crypto-review.md.tmpl283 B
  • references/templates/security/dataflow.md.tmpl298 B
  • references/templates/security/findings.md.tmpl236 B
  • references/templates/security/reproducibility.md.tmpl237 B
  • references/templates/security/threat-model.md.tmpl331 B
  • references/templates/spec-architecture.md.tmpl918 B
  • references/templates/spec-clone-mvp.md.tmpl545 B
  • references/templates/spec-clone-vs-use.md.tmpl465 B
  • references/templates/spec-code-map.md.tmpl624 B
  • references/templates/vibe-report.md.tmpl404 B
  • scripts/binary/analyze_binary.sh6.0 KB
  • scripts/binary/capture_cli_help.sh8.2 KB
  • scripts/binary/extract_embedded_archives.py4.0 KB
  • scripts/binary/list_embedded_archives.py3.7 KB
  • scripts/extract_docs_features.sh839 B
  • scripts/extract_sitemap_paths.sh892 B
  • scripts/fetch_url.py853 B
  • scripts/generate_feature_catalog_md.py2.9 KB
  • scripts/generate_feature_inventory_md.py1.4 KB
  • scripts/repo_fixture_test.sh14.4 KB
  • scripts/reverse_engineer.py79.8 KB
  • scripts/scaffold_feature_registry.py2.2 KB
  • scripts/security/generate_sbom.sh1.3 KB
  • scripts/security/scan_secrets.sh1.7 KB
  • scripts/security/validate_security_audit.sh2.4 KB
  • scripts/self_test.sh14.5 KB
  • scripts/validate_feature_registry.py5.8 KB
  • scripts/validate-output.sh4.2 KB
  • scripts/validate.sh2.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Reverse Engineer

Reverse-engineer an external system into two things: a teardown (the evidence: feature inventory, machine-checkable registry and specs, optionally a security audit) and a steal-map (the decision: what to adopt into our surfaces and what to leave behind). A decision row that must cite evidence can be re-checked by anyone; a decision made from impressions cannot be re-checked by its own author. Deciding from a competitor's README is the failure this skill exists to prevent.

⚠️ Constraints — Hard Guardrails (MANDATORY)

  • Only operate on code/binaries you own or have explicit written authorization to analyze — this matters because unauthorized teardown is the legal/IP line.
  • Do not provide steps to bypass protections/ToS or to extract proprietary source/system prompts.
  • Do not output reconstructed proprietary source or embedded prompts (index only; redact in reports) — to prevent reproducing protected IP.
  • Redact secrets/tokens/keys if encountered; run the secret-scan gate over outputs to prevent credential leakage.
  • Always separate docs say vs code proves vs hosted/control-plane.

Evidence rules

  • Tag every capability by its source. code: their source, binary or teardown registry shows it; cite the file:line or registry entry and record what the code actually does, which is often narrower than the claim. docs: a README, doc page or announcement says it; unverified. hosted: a service or control plane you cannot inspect.
  • No code access, no steal. With only docs, a README or a landing page, every row about their implementation is docs and unverified. It can be gap, park or reject, never steal.
  • Prove our side on the live tree. A have row cites our file. Every "missing" row carries the search that proved it (command and scope). Check what our current stack already offers before calling anything missing.
  • Independently checked, not self-report. Facts on how they implement a capability come from code, cross-checked by a fresh reader, never from one context's summary. Model family is optional metadata, not a trust requirement.
  • The steal is the pattern, not the platform. Their robustness is usually one idea (unification, a gate, a reconcile loop). Re-express it in our primitives; never vendor their runtime or storage engine.

Phase 1 — teardown

With an authorized clone or binary, the script clones (pinned), scans the CLI/config/artifact surface, writes the inventory, registry and specs, and validates the teardown:

python3 skills/reverse-engineer/scripts/reverse_engineer.py <product> --mode=repo \
  --upstream-repo="https://github.com/org/repo.git" --upstream-ref=v1.0.0 \
  --output-dir=".agents/scratch/reverse-engineer/<product>/"

Binary mode requires --authorized; use the bundled demo fixture if you lack authorization for a real binary. Flags, output inventory, earlier output paths, fixtures and the self-test are in the invocation reference.

Without code access (only a README, docs site or landing page), skip the script: build the inventory and steal-map by hand with each row tagged docs or hosted, and say that no teardown validator ran. When the code is readable but the script cannot run on it, read the code directly and cite file:line for each code row; the validator gap still gets reported.

Phase 2 — steal-map

Map each capability onto our surfaces in .agents/scratch/reverse-engineer/<product>/steal-map.md. The script stops after validating Phase 1; it cannot truthfully decide whether our live tree has, lacks, or should adopt a capability. The caller authors the map from the registry plus a fresh read of our repository. A missing or malformed map is an incomplete skill result, not a script success relabelled as a decision.

Their capabilityOur surface todayVerdict
<feature> (code: <registry entry>, or docs, or hosted)<our file / skill / CLI>, or "none" plus the search that proved ithave / gap / steal / park / reject

Each row gets exactly one verdict:

  • have — our live tree already does it; cite the file and confirm it still holds.
  • steal — we lack it, code evidence shows how they do it, and it advances our core. Take the pattern, re-expressed in our primitives.
  • gap — we lack it and would want it if it holds up, but steal is not earned: their mechanism is docs or hosted only, or its value to our core is unshown. Name the evidence that would decide it.
  • park — real, but deliberately not ours to build now: substrate we delegate (for AgentOps, ADR-0009 keeps scheduling, supervision and queues external) or downstream of a bet we have not made. Name it, don't build it.
  • reject — conflicts with our doctrine (e.g. a completion edge with no check behind it, where we require checks and CI, plus one fresh judgment for a costly mistake).

When two seem to fit, reject beats park, and park beats steal or gap; between steal and gap, the evidence rules decide.

Route one-way-door adoptions into planning

If adopting a steal is a one-way door (an architecture fork, a new bounded context, a storage or data migration), do not decide it here. Hand the steal-map to Plan. Dueling Idea Genies or Premortem may challenge the choice as advisory evidence. Plan alone shapes the selected option in the existing intent source; neither strategy grants readiness or continuation authority.

Validation

After authoring steal-map.md, validate the complete output with $output_dir, $security_audit, $sbom, and $upstream_ref_set (each numeric flag 0|1):

bash skills/reverse-engineer/scripts/validate-output.sh \
  --output-dir "$output_dir" --phase complete \
  --security-audit "$security_audit" --sbom "$sbom" \
  --upstream-ref-set "$upstream_ref_set"

Give the validated steal-map.md to Plan for one-way-door candidates; ordinary have, park, and reject rows remain evidence-backed terminal decisions.

Quality Rubric

  • With an upstream ref, feature-registry.yaml and clone-metadata.json record the resolved commit.
  • Every row tags code/docs/hosted and cites teardown evidence and our matching surface, or "none" with the search that proved it.
  • Verdicts use the full set — have/gap/steal/park/reject — and no docs or hosted row is steal.
  • One-way-door adoptions are supplied to Plan, not decided here.
  • Secret-scan gate passed over all outputs; no proprietary source/prompts reproduced.
  • The complete-output validator exits 0 before handoff, or the report says it did not run (docs-only mode).
ProblemCauseSolution
Steal-map is all "steal"Skipped the park/reject rulesSubstrate we delegate is park; doctrine conflicts are reject — not everything novel is worth adopting.

See Also

  • plan — shape selected steals in the existing intent source
  • idea-genie — optional advisory challenge (duel mode)
  • premortem — optional advisory challenge of the exact plan
  • research — general exploration; this is its external-system specialization

Reference Documents

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use AtomLane to compile and execute safe atomic parallel plans on macOS and native Windows Preview for worthwhile independent argv tasks, dependency DAGs, supported platform entrypoints, or Apple-silicon operators. Use at task start or an execution boundary when structured local work may contain two or more worthwhile units; skip plain answers, one quick command, and work whose effects cannot be safely bounded.

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

add

無料

Register a deferred decision in the debt registry. Trigger by judgment, not a marker scan, whenever a future reader would ask "why this way?": an unmade decision, stub, loosened type, bypassed check, swallowed error, a default picked "for now", or a TODO/FIXME/HACK/XXX marker. Trigger immediately whenever you defer work, or when the user invokes $add. Over-register freely; the developer drops with "drop A", "drop A,C", or "drop all".

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

ADK 框架适配层。为 LangChain / EINO / AutoGen / AgentScope / CrewAI 提供框架特定的 代码模板、惯用模式、API 映射和项目结构,供 agent-dev-workshop Phase 5 代码生成使用。 每个框架 reference 文件标注 verified_date 用于版本锁定。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

中文调试修复技能。用于报错、测试失败、页面异常、功能不符合预期、需要定位根因并做最小修复时。触发语包括"进入调试模式""帮我修问题""报错了""测试失败""页面坏了""找根因"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

交互式 AI Agent 开发工作坊:通过 6 阶段深度协作对话,引导用户完成 Agent 需求分析、架构设计、 工具定义、Prompt 与编排设计、代码生成、验证迭代,产出可直接运行的 Agent 项目。 框架无关设计优先,支持 LangChain / EINO / AutoGen / AgentScope / CrewAI 等 ADK 框架。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

中文漂移审计技能。用于项目或学习过程变乱、上下文漂移、任务分叉、多个方案冲突、命名不一致、Codex 可能顺手改多了时。触发语包括"漂移检查""感觉跑偏了""项目变乱了""检查是否失控""分叉太多""上下文漂移"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2732026年10月10日 更新

hashgraph-online のスキルをすべて見る

このスキルの問題を報告する