Vibeleaderboard
Index / tool
Visit github.com
Category
Cybersecurity
Rank
No. 1975Tools index

Previous survey · No. 1983 ·

Type
TOOL
Use case
Security & Identity
Interfaces
Agent Skill / Plugin
Latest release
v1.0.1
Date

About

A skills router pack for AI coding clients such as Claude Code, Cursor, Cline, and Kiro that directs an agent to the right method when it meets an APK, a binary, obfuscated frontend JavaScript, a CTF challenge, or an authorized penetration-testing target. The README advertises AI-powered routing, on-demand toolchain bootstrapping, and a self-evolving knowledge base, with bilingual English and Chinese docs plus rules and ops contracts; the repo includes a CTF sandbox orchestrator, a Burp MCP integration, and Kali tooling notes.

What it does

A pack of instruction files and helper scripts that a coding assistant reads before it starts security work. Hand the assistant an Android app, a compiled program, scrambled browser code, or a contest puzzle, and a matcher script picks one primary playbook from a fixed rule table instead of letting the model improvise commands. A setup step first records written permission and a network profile, and target action stays blocked until that record exists. Installers fetch scanners and decompilers on demand, and finished jobs get logged so the next similar task reuses the notes. Documentation ships in English and Chinese.

Why it's ranked here

The value here is discipline, not code. Most agent security packs are prompt piles. This one puts its routing decisions in one checked configuration, backs them with a regression suite that runs on two operating systems in continuous integration, and writes a hard consent gate into its rules: reading the repository is not permission to run it, and naming a target is not permission to attack it. That gate is rare in this category, and it is the reason to prefer this over an unstructured prompt collection. What it does not give you is the scanners and decompilers themselves. Those stay external, and you install them.

What's good

Three things stand out. The consent and scope model is explicit and repeated across the rule files: written authorization and a network profile must be on record before any target action, and a force flag is documented as unable to bypass that gate. The routing core is one structured table with a regression benchmark and cross-platform continuous integration, so a rule change that breaks matching fails the build. The proxy-control bridge ships with token authentication on by default and cross-origin access narrowed to the local machine, returning a rejection when the token is missing. Documentation is thorough and bilingual.

Tradeoffs

The counts do not line up. The landing page claims one number of routing rules and benchmark cases, while the file listing and the test runner cite lower figures, so the headline numbers do not agree. Almost all the weight is guidance, not executable capability: the scanners, decompilers, and the paid disassembler are installed by you, and one is commercial with no automated path. The scripts and most tooling assume Windows or Kali first, with generic Linux and macOS marked only as generic support. Continuous integration covers two operating systems, not the full matrix the docs describe. A large security payload corpus may be quarantined by antivirus.

How to use it well

Reach for this if you run a coding assistant on authorized reverse-engineering, contest, or permitted penetration work and you want the model to follow one repeatable path instead of guessing at tools. It fits teams that already have the underlying scanners and decompilers installed and want consistent routing plus evidence logging on top. It does not replace those tools, teach the tradecraft, or help with unauthorized targets: the rules block that by design. Read the on-demand installers closely before approving them, since they fetch and run external software. Solo users on macOS get the least polished path.

Technical notes+

The consent gate is spelled out in RULES.md and echoed in skills/SKILL.md and skills/MASTER-ROUTING.md: a route step then a case-init step must reach an authorized scope before any target action, with a documented force flag that cannot bypass it. The priority ladder in skills/MASTER-ROUTING.md lists rules through R45, while README.md and the docs cite differing rule and benchmark totals, so treat the exact counts as approximate. burp-mcp-full/mcp-bridge.js reads a bearer token from the home directory or an environment variable and attaches it to every call, returning an error on a 403 rejection; burp-mcp-full/README.md documents the local-only cross-origin policy and a default local port. SECURITY.md separates an executable surface from a passive payload corpus that can trip antivirus, and docs/PLATFORMS.md marks Linux and macOS as generic support.

Observed

License
MIT
Primary interfaces
Agent skill-router instruction files plus an MCP server bridging a web proxy tool
Distribution
Clone the Git repository; no published package-manager entry
Runtime prerequisites
Java (JDK), Node.js 22.12+, Python 3.x
Platform support
Windows and Kali as primary paths, Ubuntu/Debian and macOS as generic
Routing tests
In-repository routing regression suite, run in CI on Windows and Ubuntu
Consent model
Rules require recorded authorization and a network profile before any target action
Proxy bridge auth
Bearer token required by default; cross-origin access limited to the local host

Read from README.md, LICENSE, RULES.md, docs/ARCHITECTURE.md, docs/OVERVIEW.md, SECURITY.md, skills/SKILL.md, skills/MASTER-ROUTING.md, docs/PLATFORMS.md, burp-mcp-full/README.md, burp-mcp-full/mcp-bridge.js.

Tags

reverse-engineeringpentestingctfskillsecurity-researchclaude-code

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.