MIT-licensed dsh Cordis plugin that ships reverse-skill's 87 SKILL.md files (45 domain + 42 CTF skills) inside the package and auto-registers them after a one-line `dsh plugin add` — for authorized reverse engineering, pentesting and security research.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-08-27
License
MIT
01What can it help you accomplish?
Bring the full reverse-skill pack into DeepSeek Harness — run reverse engineering, authorized penetration testing and security research skills inside dsh conversations
87 SKILL.md files ship inside the plugin and load automatically: 45 domain skills (skills/) plus 42 CTF-track skills (CTF-Sandbox-Orchestrator/), with the root SKILL.md acting as a reverse-skill-router
Reverse engineers, security researchers and CTF players using DeepSeek Harness who want the skill pack to load with the plugin instead of maintaining a candidate list by hand (authorized use only)
Use the skill pack as a build-free preset — mount skills/ and CTF-Sandbox-Orchestrator/ directories directly
Skills loaded via dsh's `customSkillDirs` config key pointing at ./dsh-reverse-skill/skills and ./dsh-reverse-skill/CTF-Sandbox-Orchestrator, no npm build required
Users who want to skip the plugin build flow and quickly mount the skill directories, accepting dsh's flat discovery (root SKILL.md router is not picked up)
02How to install into DeepSeek Harness
Prerequisites
- `cordis` / `dsh-skill` are peer dependencies provided by the dsh runtime — the README says they are used here only for types and build
Installation steps
- 01
Install dependencies and build: run `npm install`, then `npm run build` (tsc generates lib/ and lib/types/)
$ npm install
- 02
Install and activate from GitHub (recommended): run `dsh plugin add github:dhicoc/dsh-reverse-skill` — dsh reads cordis.patch.yml, inserts the reverse-skill Cordis plugin into the current profile and auto-registers 87 skills at startup
$ dsh plugin add github:dhicoc/dsh-reverse-skill
- 03
Optional build-free fallback: point dsh `customSkillDirs` at ./dsh-reverse-skill/skills and ./dsh-reverse-skill/CTF-Sandbox-Orchestrator to mount the pack as a preset
Verify the integration
- Run `npm test` at the repo root — it recompiles the plugin and asserts all 87 packaged skills are discoverable via `list()`, have no duplicate names, and `get()` returns a non-empty body (a UTF-8 BOM / CRLF SKILL.md fixture is auto-removed after the test)
03DSH integration and capability boundaries
Native dsh Cordis plugin — installed and activated via the official dsh CLI in one line (`dsh plugin add github:dhicoc/dsh-reverse-skill`); at startup the plugin registers all 87 SKILL.md skills into ctx.skills via `ctx.skills.registerProvider(...)`.
Data-driven recursive skill scanning (zero handwritten lists)
skills/ and CTF-Sandbox-Orchestrator/ directories containing SKILL.md files→Each SKILL.md becomes a SkillCandidate with a resourceBase directory, exposed through a registered SkillProvider that returns the full body on get()
adding or removing a skill only requires changing the directory — the plugin syncs automaticallyModel-invoked and manual skill calling
the 87 skills registered into ctx.skills→models call skills automatically through ctx.skills → tool-skill; users can also invoke skills by name (subject to each SKILL.md's user-invocable flag)
Build-free preset mounting
skills/ and CTF-Sandbox-Orchestrator/ directories shipped with the repo→skills mounted directly via dsh's customSkillDirs config key, without building
the preset fallback relies on dsh's flat discovery (direct subdirectories only), so the root SKILL.md router is not discovered — the plugin path is recommendedRe-runnable verification (npm test)
npm test at the repo root→recompiles the plugin and asserts all 87 packaged skills are discoverable via list(), have no duplicate names, and get() returns a non-empty body; also verifies UTF-8 BOM / CRLF SKILL.md files are not silently skipped
04Who is it for? When not to use it?
Good for
- Reverse engineers, security researchers and CTF players using DeepSeek Harness who want the skill pack to load with the plugin instead of maintaining a candidate list by hand (authorized use only)
- Users who want to skip the plugin build flow and quickly mount the skill directories, accepting dsh's flat discovery (root SKILL.md router is not picked up)
Not for
- The repo is for authorized reverse engineering, penetration testing and security research only — users must ensure they have legal authorization for the target system; the repository disclaims all unauthorized behavior.
- The upstream 43 OpenAI Agents SDK agents/*.yaml definitions are not portable: they cannot map to dsh's ctx.subagent (dsh only launches Codex / Claude Code CLIs), so these agent definitions are not included in the plugin.
- allowed-tools / disallowed-tools are not enforced by dsh — dsh currently treats them as unknown fields and defers evaluation, so tool constraints inside skills must be guaranteed at the harness layer.
05Compatibility, maintenance and safety notes
- The repo is for authorized reverse engineering, penetration testing and security research only — users must ensure they have legal authorization for the target system; the repository disclaims all unauthorized behavior.
- The upstream 43 OpenAI Agents SDK agents/*.yaml definitions are not portable: they cannot map to dsh's ctx.subagent (dsh only launches Codex / Claude Code CLIs), so these agent definitions are not included in the plugin.
- allowed-tools / disallowed-tools are not enforced by dsh — dsh currently treats them as unknown fields and defers evaluation, so tool constraints inside skills must be guaranteed at the harness layer.
- External MCP servers referenced inside skill bodies (e.g. burp-mcp) are outside the plugin's scope and must be configured separately via dsh's mcp.servers.
MIT · actively maintained (last push 2026-08-22; wraps upstream reverse-skill, 27k★, MIT); no formal release yet
06Frequently asked questions
How do I install dsh-reverse-skill?
Recommended: run `dsh plugin add github:dhicoc/dsh-reverse-skill` to install and activate from GitHub in one line — dsh reads cordis.patch.yml, inserts the plugin into the current profile and auto-registers 87 skills at startup. You can also `npm install` and `npm run build` first, or reference the package name @dhicoc/dsh-reverse-skill in your dsh config.
How are the skills invoked after installation?
The plugin calls ctx.skills.registerProvider(...) inside apply(ctx) and registers all 87 skills into ctx.skills. Models call them automatically through ctx.skills → tool-skill, and users can invoke skills by name, subject to each SKILL.md's user-invocable flag.
What are the known limitations?
The upstream 43 OpenAI Agents SDK agents/*.yaml definitions cannot map to dsh's ctx.subagent and are not included; allowed-tools / disallowed-tools are not enforced by dsh (treated as unknown fields), so tool constraints must be guaranteed at the harness layer; external MCP servers referenced by skills (e.g. burp-mcp) are outside the plugin and must be configured via dsh's mcp.servers.
Can I use it without building?
Yes — the repo ships the full skills/ and CTF-Sandbox-Orchestrator/ directories, which can be mounted directly through dsh's customSkillDirs without building. Note the preset fallback uses dsh's flat discovery (direct subdirectories only), so the root SKILL.md router is not discovered — the plugin path is recommended.
Do I need npm install / build?
For the plugin form, run `npm install` then `npm run build` (tsc generates lib/ and lib/types/). After building, `npm test` recompiles the plugin and asserts all 87 skills are discoverable via list(), have no duplicate names, and get() returns a non-empty body.
07Related DSH workflows
distilly
by titanwings
Meta-skill turning source material into a versioned Person Profile skill with incremental merge, correction layer, rollback, per-host install.
dsh-market
by dsh-market
插件市场 (plugin marketplace): 打开 Settings → Plugin Market 浏览/搜索/一键安装社区插件;安装源限制为 curated awesome-dsh-plugin 注册表(其余拒绝),默认禁用构建脚本(pnpm>=10 需显式开启)。
ai_animation
by unclecheng-li
Generate standalone animated HTML diagrams, presentations, notes, protocol visualizations, and UI demos from prompts.
aegis
by ganyuanran
Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across long tasks.
08Data and sources
把上游 [`zhaoxuya520/reverse-skill`](https://github.com/zhaoxuya520/reverse-skill)(27k★,MIT)全部 **87 个 SKILL.md** 原样封装成一个 ds…
本仓库已声明 `dsh.bundle` manifest(见 `cordis.patch.yml`),因此可直接用一行命令安装并激活:
dsh plugin add github:dhicoc/dsh-reverse-skill
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
