/SKILL.md
Execute advanced JavaScript reverse-engineering workflows for modern web applications, including signature recovery, runtime instrumentation, deobfuscation, bundle analysis, anti-debug bypass, environment rebuild, and replay validation.
npx skillsauth add dqmyth/js-reverse-ops js-reverse-opsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill as a structured reverse-engineering workflow, not an ad hoc debugging session.
This public release keeps:
Locate, Runtime, Recover, and ReplayThis public release intentionally excludes:
Start from the smallest reliable context:
scripts/triage_js.sh <path> and then the smallest extractor that matches the target familyplaybooks/accepted-response-hidden-dom.mdplaybooks/embedded-runtime-font-mapping.mdplaybooks/bootstrap-digest-ladder.mdplaybooks/iterative-script-warmup-same-endpoint.mdplaybooks/server-time-gated-wasm-signer.mdplaybooks/patched-runtime-digest-branch.mdplaybooks/runtime-bundle-signer-extraction.mdXMLHttpRequest.open rewrites the protected URL with the signer field: treat the rewritten URL as the signer output, preserve script order and runtime state, and use playbooks/xhr-open-url-rewrite-runtime-replay.mdplaybooks/transport-profile-ladder.mdplaybooks/lenient-verify-data-gate.mdplaybooks/decoy-page-request-hidden-token-gate.mdplaybooks/grid-challenge-template-matching.mdplaybooks/fresh-reload-seeded-signer-step-key-ladder.mdplaybooks/same-page-prior-round-signer-replay.mdplaybooks/mobile-shell-api-pivot.mdreferences/task-types.mdreferences/stages/locate.mdreferences/stages/runtime.mdreferences/stages/recover.mdreferences/stages/replay.mdreferences/rules/evidence-rules.mdreferences/rules/runtime-first.mdreferences/rules/routing-rules.mdreferences/rules/replay-rules.mdThis public variant is intended for sharing as a reusable skill package. Keep private fixtures, live captures, and customer- or site-specific notes in a separate private workspace or repository.
development
Maintainer-only workflow for handling GitHub Secret Scanning alerts on OpenClaw. Use when Codex needs to triage, redact, clean up, and resolve secret leakage found in issue comments, issue bodies, PR comments, or other GitHub content.
development
Maintainer workflow for OpenClaw releases, prereleases, changelog release notes, and publish validation. Use when Codex needs to prepare or verify stable or beta release steps, align version naming, assemble release notes, check release auth requirements, or validate publish-time commands and artifacts.
development
Run, watch, debug, and extend OpenClaw QA testing with qa-lab and qa-channel. Use when Codex needs to execute the repo-backed QA suite, inspect live QA artifacts, debug failing scenarios, add new QA scenarios, or explain the OpenClaw QA workflow. Prefer the live OpenAI lane with regular openai/gpt-5.4 in fast mode; do not use gpt-5.4-pro or gpt-5.4-mini unless the user explicitly overrides that policy.
development
End-to-end Parallels smoke, upgrade, and rerun workflow for OpenClaw across macOS, Windows, and Linux guests. Use when Codex needs to run, rerun, debug, or interpret VM-based install, onboarding, gateway smoke tests, latest-release-to-main upgrade checks, fresh snapshot retests, or optional Discord roundtrip verification under Parallels.