Reverse-engineer an authorized repo, binary, or product into a verifiable feature inventory and adoption map. Triggers: "reverse-engineer X", "tear down Y", "what should we steal from Z", "evaluate competitor/upstream", "should we fork/adopt/build-native".
npx skills add https://github.com/boshu2/agentops --skill reverse-engineer
Reverse-engineer an external system into two things: a mechanically-verifiable teardown (feature inventory + registry + specs, optionally a security audit) and a steal-map — what to adopt into our surfaces, what to leave behind. The teardown is the evidence; the steal-map is the decision. Separating them works because a decision row that must cite a registry entry can be re-checked by anyone, while a decision made from impressions cannot be re-checked by its own author. The original failure mode this skill exists to prevent: reading a competitor's README and "deciding" from vibes.
Triggers: "reverse-engineer X", "tear down Y", "what should we steal from Z", "evaluate competitor/upstream", "should we fork/adopt/build-native".
Produce evidence, not vibes. The script clones (pinned), scans CLI/config/artifact surface, and writes a feature inventory + machine-checkable registry + spec set.
python3 skills/reverse-engineer/scripts/reverse_engineer.py <product> --mode=repo \
--upstream-repo="https://github.com/org/repo.git" --upstream-ref=v1.0.0 \
--output-dir=".agents/research/<product>/"
Binary mode requires --authorized (see Invocation Contract + Self-Test). Use the bundled demo fixture if you lack authorization for a real binary.
Map each capability the teardown found onto our surfaces. This is the part that turns research into a decision. Emit .agents/research/<product>/steal-map.md with a table; every row cites the teardown evidence and the matching surface in our repo.
| Their capability | Our surface today | Verdict |
|---|---|---|
| <feature> | <our file / skill / CLI, or "none"> | have / gap / steal / park / reject |
Verdict rules (hard-won — apply them, do not skip):
Discipline that makes the map trustworthy:
each capability from code, cross-checked by a fresh reader — never from a
README or one context's summary. Model family is optional metadata, not a
trust requirement.
If adopting a steal is a one-way door (an architecture fork, a new bounded
context, or a migration), do not decide it here. Hand the steal-map to Plan.
Dueling Idea Genies or Premortem may challenge the choice as advisory
evidence. Plan alone shapes the selected option in the existing intent source;
neither strategy grants readiness or continuation authority.
Required: product_name. Common flags: --mode=repo|binary|both, --upstream-repo, --upstream-ref (pins the clone to a specific commit/tag/branch; the resolved SHA is recorded in clone-metadata.json on any clone), --output-dir (default .agents/research/<product>/), --security-audit, --materialize-archives (authorized-only opt-in; embedded-archive extraction is off/index-only by default), --authorized (mandatory for binary mode — refuses without it). Full list: python3 skills/reverse-engineer/scripts/reverse_engineer.py --help.
Phase-1 teardown under output_dir/: feature-inventory.md, feature-registry.yaml, feature-catalog.md, spec-architecture.md, spec-code-map.md, spec-clone-vs-use.md, spec-clone-mvp.md, plus spec-cli-surface.md only when a CLI is detected and clone-metadata.json only when the script performs a clone (i.e., --upstream-repo is supplied and the target is not already checked out); --upstream-ref pins which commit, it is not what triggers the file. Security mode adds output_dir/security/: threat-model.md, attack-surface.md, dataflow.md, crypto-review.md, authn-authz.md, findings.md, reproducibility.md, validate-security-audit.sh. Phase-2: steal-map.md.
--output-dir, defaulting to$REPO/.agents/research/<product>/.
files live only in the security/ child directory.
object, and inventories/specs/steal-map are nonempty Markdown files.
$output_dir, $security_audit, $sbom, and$upstream_ref_set (each flag 0|1) set:
set -euo pipefail
required=(feature-inventory.md feature-registry.yaml feature-catalog.md spec-architecture.md spec-code-map.md spec-clone-vs-use.md spec-clone-mvp.md analysis-root-path.txt validate-feature-registry.py steal-map.md)
for name in "${required[@]}"; do
test -f "$output_dir/$name"
test ! -L "$output_dir/$name"
test -s "$output_dir/$name"
done
test -f "$output_dir/docs-features.txt"
test ! -L "$output_dir/docs-features.txt"
test ! -L "$output_dir/spec-cli-surface.md"
if [[ -e "$output_dir/spec-cli-surface.md" ]]; then
test -f "$output_dir/spec-cli-surface.md"
test -s "$output_dir/spec-cli-surface.md"
fi
python3 "$output_dir/validate-feature-registry.py"
if [[ "$upstream_ref_set" == 1 ]]; then
test -f "$output_dir/clone-metadata.json"
test ! -L "$output_dir/clone-metadata.json"
jq -e 'type == "object"' "$output_dir/clone-metadata.json" >/dev/null
else
[[ "$upstream_ref_set" == 0 ]]
fi
grep -Fqx '| Their capability | Our surface today | Verdict |' "$output_dir/steal-map.md"
if [[ "$security_audit" == 1 ]]; then
test -x "$output_dir/security/validate-security-audit.sh"
if [[ "$sbom" == 1 ]]; then
"$output_dir/security/validate-security-audit.sh" "$output_dir" --sbom
else
[[ "$sbom" == 0 ]]
"$output_dir/security/validate-security-audit.sh" "$output_dir" --no-sbom
fi
else
[[ "$security_audit" == 0 ]]
[[ "$sbom" == 0 ]]
fi
steal-map.md to Plan forone-way-door candidates; ordinary have, park, and
reject decisions remain evidence-backed terminal rows.
--upstream-ref pins the clone (fetch FETCH_HEAD, record SHA) so contracts can be committed as golden fixtures and diffed across runs. Regression test: bash skills/reverse-engineer/scripts/repo_fixture_test.sh. To update a fixture when contracts legitimately change, re-run with the new pinned ref, copy the contract files into fixtures/<product>/, and commit.
bash skills/reverse-engineer/scripts/self_test.sh
Must show: feature inventory generated, registry generated, registry validator exits 0; in security mode validate-security-audit.sh exits 0 and the secret scan passes.
Run the skill for cc-sdd with --mode=repo --upstream-repo="https://github.com/gotalab/cc-sdd.git" --upstream-ref=v1.0.0. It clones the pinned source, scans the surface, writes inventory/registry/specs, and maps each feature onto our surfaces (have, gap, steal, park, or reject) in steal-map.md. Supply selected steals to Plan.
Run the skill for ao with --authorized --mode=binary --binary-path="$(command -v ao)" --security-audit. It performs authorized static analysis plus the security suite under output_dir/security/; the secret-scan check must pass.
| Problem | Cause | Solution |
|---|---|---|
| Refuses binary analysis | Missing --authorized | Add --authorized (explicit written authorization required). |
| No clone-metadata.json | --upstream-repo not passed | Pass --upstream-repo (and optionally --upstream-ref). |
| Fixture diff fails | Upstream changed / stale golden | Re-run pinned, refresh fixtures/, commit. |
| spec-cli-surface.md missing | No Node/Python/Go CLI detected | Surface is documented in spec-code-map.md instead. |
| Steal-map is all "steal" | Skipped the park/reject rules | Substrate we delegate is park; doctrine conflicts are reject — not everything novel is worth adopting. |
have/gap/steal/park/reject — not everything marked "steal".A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).
Extracts and analyzes competitors' ads from ad libraries (Facebook, LinkedIn, etc.) to understand what messaging, problems, and creative approaches are working. Helps inspire and improve your own ad campaigns.
Identifies high-quality leads for your product or service by analyzing your business, searching for target companies, and providing actionable contact strategies. Perfect for sales, business development, and marketing professionals.
Analyzes your recent Claude Code chat history to identify coding patterns, development gaps, and areas for improvement, curates relevant learning resources from HackerNews, and automatically sends a personalized growth report to your Slack DMs.
Complete App Store Optimization (ASO) toolkit for researching, optimizing, and tracking mobile app performance on Apple App Store and Google Play Store
NGS analysis toolkit. BAM to bigWig conversion, QC (correlation, PCA, fingerprints), heatmaps/profiles (TSS, peaks), for ChIP-seq, RNA-seq, ATAC-seq visualization.
Materials science toolkit. Crystal structures (CIF, POSCAR), phase diagrams, band structure, DOS, Materials Project integration, format conversion, for computational materials science.
Transforms vague UI ideas into polished, Stitch-optimized prompts. Enhances specificity, adds UI/UX keywords, injects design system context, and structures output for better generation results.
Take boshu2/reverse-engineer from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.