How reverse-skill Classifies and Routes Security Tasks: A Complete Guide
The reverse-skill framework uses a deterministic, data-driven pipeline with a three-axis routing matrix (Target Type × User Intent × Toolchain) to classify security tasks and dispatch them to the appropriate skill script.
The reverse-skill repository implements a declarative routing system for security workflows. When you submit a query containing keywords like "recon", "exploit", or "reverse", the framework translates your intent into structured commands without hard-coded logic in the dispatchers. This article examines the complete classification and routing pipeline as implemented in zhaoxuya520/reverse-skill.
The Four-Stage Routing Pipeline
Security task routing in reverse-skill follows a strict four-stage pipeline. Each stage is isolated, testable, and governed by explicit configuration files.
Stage 1: Detection and Hint Extraction
The entry point skills/MASTER-ROUTING.md receives all security-oriented queries. This component performs keyword-based classification to generate a hint string that represents the intended task category.
The hint extraction looks for security-specific vocabulary:
- "recon" → reconnaissance tasks
- "exploit" → vulnerability exploitation
- "reverse" → reverse engineering
- "binary diff" → comparison analysis
Once classified, the hint is passed to platform-specific dispatchers.
Stage 2: Platform-Specific Dispatcher Selection
MASTER-ROUTING selects the dispatcher based on the host operating system:
| Platform | Dispatcher Script | Language |
|---|---|---|
| Windows | skills/scripts/master-route.ps1 |
PowerShell |
| Linux / macOS / Kali | skills/scripts/master-route.sh |
Bash |
Both dispatchers share identical logic: receive the hint, invoke the routing engine, and handle execution. The platform abstraction ensures consistent behavior across environments without code duplication.
Stage 3: Data-Driven Routing Engine
The routing engine consults skills/config/routing.json — the single source of truth for all routing decisions. This JSON encodes a three-axis matrix:
- Target Type — what asset is being analyzed (Windows AD, binary, API)
- User Intent — what operation is requested (enumeration, compare, reverse)
- Toolchain — preferred execution environment (PowerShell, bash)
The engine matches the hint against this matrix and resolves the concrete skill script path.
Example routing.json structure:
{
"windows-ad": {
"enumeration": {
"powershell": "skills/windows-ad/SKILL.md"
}
},
"binary-diff": {
"compare": {
"bash": "skills/binary-diff/SKILL.md"
}
},
"ida-reverse": {
"analyze": {
"bash": "skills/ida-reverse/SKILL.md"
}
}
}
Adding new security capabilities requires only updating this JSON and providing the corresponding skill documentation — no dispatcher modifications needed.
Stage 4: Guard and Evidence Generation
Before any skill executes, the case-initialization guard runs. Located in skills/scripts/case-init.sh, this component enforces:
- Authentication check — verifies
auth.statusis valid - Scope validation — confirms
work/<case>/scope.mdexists - Environment preparation — sets up isolated working directories
Only when all guards pass does the target skill launch. This hard-coded policy, defined in RULES.md, ensures every security task respects access controls and generates auditable evidence.
Command-Line Routing Examples
The routing system is designed for scripting and automation. Below are practical invocations for common security tasks.
Linux/macOS: Route a Binary Diff Task
bash skills/scripts/master-route.sh --hint "binary diff"
The bash dispatcher:
- Parses the hint "binary diff"
- Queries
routing.jsonfor target type "binary-diff", intent "compare" - Runs
case-init.shto validate auth and scope - Launches
skills/binary-diff/SKILL.md
Windows: Route an IDA Reverse Engineering Task
powershell -NoProfile -ExecutionPolicy Bypass `
-File skills/scripts/master-route.ps1 -Hint "ida reverse"
The PowerShell dispatcher performs identical matrix lookup and launches skills/ida-reverse/SKILL.md after guard validation.
Direct Routing.json Query Pattern
For custom integrations, you can trace the routing decision manually:
# Extract routing for a specific hint using jq
cat skills/config/routing.json | jq '."ida-reverse"."analyze"'
# Output: {"bash": "skills/ida-reverse/SKILL.md"}
Key Configuration and Source Files
| File | Purpose | Routing Role |
|---|---|---|
skills/MASTER-ROUTING.md |
High-level entry point | Classifies queries, selects dispatcher |
skills/scripts/master-route.ps1 |
Windows dispatcher | Executes PowerShell-based skills |
skills/scripts/master-route.sh |
Unix dispatcher | Executes bash-based skills |
skills/config/routing.json |
Routing matrix | Maps hints to skill scripts declaratively |
skills/scripts/case-init.sh |
Security guard | Enforces authentication and scope before execution |
RULES.md |
Policy contract | Defines mandatory routing constraints |
How reverse-skill Classification Compares to Alternatives
Traditional security frameworks often embed routing logic directly in dispatcher code. The reverse-skill approach offers distinct advantages:
- Configuration over code — New skills require JSON edits, not script changes
- Cross-platform consistency — Same routing matrix, different dispatchers
- Mandatory guard integration — No bypass path around
case-initvalidation - Explicit toolchain selection — Matrix axis prevents environment mismatches
Summary
- reverse-skill classifies security tasks through keyword-based hint extraction at
MASTER-ROUTING.md - Platform dispatchers (
master-route.ps1,master-route.sh) handle OS-specific execution - The routing matrix in
routing.jsonprovides declarative mapping of Target Type × User Intent × Toolchain - Case initialization guards enforce authentication and scope requirements before any skill runs
- Adding new capabilities requires only JSON configuration and skill documentation
Frequently Asked Questions
How does reverse-skill handle ambiguous security queries?
When a hint matches multiple routing.json entries, the framework uses exact matching first, then falls back to prefix matching. If ambiguity persists, the dispatcher logs the conflict and exits without execution, forcing explicit query refinement.
Can the routing matrix be extended without modifying core scripts?
Yes. Adding a new security skill requires only: (1) creating the skill directory with SKILL.md, (2) adding the corresponding entry to skills/config/routing.json, and (3) ensuring the toolchain script exists. Neither master-route.ps1 nor master-route.sh need changes.
What happens if case initialization fails?
The case-init.sh guard terminates the routing pipeline immediately. According to RULES.md, no skill may execute without valid auth.status and work/<case>/scope.md. Failed initiations are logged for audit purposes but do not delegate to fallback skills.
Is there API access to the routing engine?
The routing engine is currently command-line only through the platform dispatchers. The routing.json structure is stable and documented, enabling external tools to replicate classification logic by parsing the same matrix the dispatchers use.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →