Back to directory

dsh-reverse-skill

Curated pickMaintenance: Active

dhicoc/dsh-reverse-skill

Complete reverse-skill (87 SKILL.md) as a DeepSeek Harness (dsh) Cordis plugin — reverse engineering, authorized pentesting and security research skill pack.

View on GitHub
$ npm install

174

stars

22

forks

PowerShell

Language

MIT

License

2026-08-14

Created

2026-09-29

Last push

MIT-licensed dsh Cordis plugin that ships reverse-skill's 87 SKILL.md files (45 domain + 42 CTF skills) inside the package and auto-registers them after a one-line `dsh plugin add` — for authorized reverse engineering, pentesting and security research.

DSH integration

Native runtime

Author-claimed

Safety audit

Unaudited

Last verified

2026-08-27

License

MIT

01What can it help you accomplish?

  • Bring the full reverse-skill pack into DeepSeek Harness — run reverse engineering, authorized penetration testing and security research skills inside dsh conversations

    87 SKILL.md files ship inside the plugin and load automatically: 45 domain skills (skills/) plus 42 CTF-track skills (CTF-Sandbox-Orchestrator/), with the root SKILL.md acting as a reverse-skill-router

    Reverse engineers, security researchers and CTF players using DeepSeek Harness who want the skill pack to load with the plugin instead of maintaining a candidate list by hand (authorized use only)

  • Use the skill pack as a build-free preset — mount skills/ and CTF-Sandbox-Orchestrator/ directories directly

    Skills loaded via dsh's `customSkillDirs` config key pointing at ./dsh-reverse-skill/skills and ./dsh-reverse-skill/CTF-Sandbox-Orchestrator, no npm build required

    Users who want to skip the plugin build flow and quickly mount the skill directories, accepting dsh's flat discovery (root SKILL.md router is not picked up)

02How to install into DeepSeek Harness

Prerequisites

  • `cordis` / `dsh-skill` are peer dependencies provided by the dsh runtime — the README says they are used here only for types and build

Installation steps

  1. 01

    Install dependencies and build: run `npm install`, then `npm run build` (tsc generates lib/ and lib/types/)

    $ npm install

  2. 02

    Install and activate from GitHub (recommended): run `dsh plugin add github:dhicoc/dsh-reverse-skill` — dsh reads cordis.patch.yml, inserts the reverse-skill Cordis plugin into the current profile and auto-registers 87 skills at startup

    $ dsh plugin add github:dhicoc/dsh-reverse-skill

  3. 03

    Optional build-free fallback: point dsh `customSkillDirs` at ./dsh-reverse-skill/skills and ./dsh-reverse-skill/CTF-Sandbox-Orchestrator to mount the pack as a preset

Verify the integration

  • Run `npm test` at the repo root — it recompiles the plugin and asserts all 87 packaged skills are discoverable via `list()`, have no duplicate names, and `get()` returns a non-empty body (a UTF-8 BOM / CRLF SKILL.md fixture is auto-removed after the test)

03DSH integration and capability boundaries

DSH integrationNative runtime

Native dsh Cordis plugin — installed and activated via the official dsh CLI in one line (`dsh plugin add github:dhicoc/dsh-reverse-skill`); at startup the plugin registers all 87 SKILL.md skills into ctx.skills via `ctx.skills.registerProvider(...)`.

  • Data-driven recursive skill scanning (zero handwritten lists)

    skills/ and CTF-Sandbox-Orchestrator/ directories containing SKILL.md files→Each SKILL.md becomes a SkillCandidate with a resourceBase directory, exposed through a registered SkillProvider that returns the full body on get()

    adding or removing a skill only requires changing the directory — the plugin syncs automatically
  • Model-invoked and manual skill calling

    the 87 skills registered into ctx.skills→models call skills automatically through ctx.skills → tool-skill; users can also invoke skills by name (subject to each SKILL.md's user-invocable flag)

  • Build-free preset mounting

    skills/ and CTF-Sandbox-Orchestrator/ directories shipped with the repo→skills mounted directly via dsh's customSkillDirs config key, without building

    the preset fallback relies on dsh's flat discovery (direct subdirectories only), so the root SKILL.md router is not discovered — the plugin path is recommended
  • Re-runnable verification (npm test)

    npm test at the repo root→recompiles the plugin and asserts all 87 packaged skills are discoverable via list(), have no duplicate names, and get() returns a non-empty body; also verifies UTF-8 BOM / CRLF SKILL.md files are not silently skipped

04Who is it for? When not to use it?

Good for

  • Reverse engineers, security researchers and CTF players using DeepSeek Harness who want the skill pack to load with the plugin instead of maintaining a candidate list by hand (authorized use only)
  • Users who want to skip the plugin build flow and quickly mount the skill directories, accepting dsh's flat discovery (root SKILL.md router is not picked up)

Not for

  • The repo is for authorized reverse engineering, penetration testing and security research only — users must ensure they have legal authorization for the target system; the repository disclaims all unauthorized behavior.
  • The upstream 43 OpenAI Agents SDK agents/*.yaml definitions are not portable: they cannot map to dsh's ctx.subagent (dsh only launches Codex / Claude Code CLIs), so these agent definitions are not included in the plugin.
  • allowed-tools / disallowed-tools are not enforced by dsh — dsh currently treats them as unknown fields and defers evaluation, so tool constraints inside skills must be guaranteed at the harness layer.

05Compatibility, maintenance and safety notes

  • The repo is for authorized reverse engineering, penetration testing and security research only — users must ensure they have legal authorization for the target system; the repository disclaims all unauthorized behavior.
  • The upstream 43 OpenAI Agents SDK agents/*.yaml definitions are not portable: they cannot map to dsh's ctx.subagent (dsh only launches Codex / Claude Code CLIs), so these agent definitions are not included in the plugin.
  • allowed-tools / disallowed-tools are not enforced by dsh — dsh currently treats them as unknown fields and defers evaluation, so tool constraints inside skills must be guaranteed at the harness layer.
  • External MCP servers referenced inside skill bodies (e.g. burp-mcp) are outside the plugin's scope and must be configured separately via dsh's mcp.servers.
2026-08-142026-08-22Not specified by the author

MIT · actively maintained (last push 2026-08-22; wraps upstream reverse-skill, 27k★, MIT); no formal release yet

06Frequently asked questions

How do I install dsh-reverse-skill?

Recommended: run `dsh plugin add github:dhicoc/dsh-reverse-skill` to install and activate from GitHub in one line — dsh reads cordis.patch.yml, inserts the plugin into the current profile and auto-registers 87 skills at startup. You can also `npm install` and `npm run build` first, or reference the package name @dhicoc/dsh-reverse-skill in your dsh config.

How are the skills invoked after installation?

The plugin calls ctx.skills.registerProvider(...) inside apply(ctx) and registers all 87 skills into ctx.skills. Models call them automatically through ctx.skills → tool-skill, and users can invoke skills by name, subject to each SKILL.md's user-invocable flag.

What are the known limitations?

The upstream 43 OpenAI Agents SDK agents/*.yaml definitions cannot map to dsh's ctx.subagent and are not included; allowed-tools / disallowed-tools are not enforced by dsh (treated as unknown fields), so tool constraints must be guaranteed at the harness layer; external MCP servers referenced by skills (e.g. burp-mcp) are outside the plugin and must be configured via dsh's mcp.servers.

Can I use it without building?

Yes — the repo ships the full skills/ and CTF-Sandbox-Orchestrator/ directories, which can be mounted directly through dsh's customSkillDirs without building. Note the preset fallback uses dsh's flat discovery (direct subdirectories only), so the root SKILL.md router is not discovered — the plugin path is recommended.

Do I need npm install / build?

For the plugin form, run `npm install` then `npm run build` (tsc generates lib/ and lib/types/). After building, `npm test` recompiles the plugin and asserts all 87 skills are discoverable via list(), have no duplicate names, and get() returns a non-empty body.

08Data and sources

  • Author-claimedgithub.com453f35d82bde…

    把上游 [`zhaoxuya520/reverse-skill`](https://github.com/zhaoxuya520/reverse-skill)(27k★,MIT)全部 **87 个 SKILL.md** 原样封装成一个 ds…

  • Author-claimedgithub.com453f35d82bde…

    本仓库已声明 `dsh.bundle` manifest(见 `cordis.patch.yml`),因此可直接用一行命令安装并激活:

  • Author-claimedgithub.com453f35d82bde…

    dsh plugin add github:dhicoc/dsh-reverse-skill

This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.

🏆

Best DeepSeek Harness Plugins

Twelve plugins worth installing first — picked from the whole catalog, across every category.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.