How Reverse‑Skill Handles Tool Installation from GitHub Releases: A Complete Guide
Reverse‑skill uses a manifest‑driven bootstrap system that automatically fetches, verifies, and installs missing tools from GitHub release assets across Windows PowerShell, generic Bash, and specialized Kali Linux scripts.
The zhaoxuya520/reverse-skill repository eliminates manual tool setup by declaratively specifying how each capability is obtained. Whether you're analyzing Android binaries with JADX or instrumenting apps with Frida, the bootstrap mechanism handles platform detection, asset selection, checksum verification, and installation without hard‑coded paths.
How the Bootstrap Manifest Defines GitHub Release Sources
At the heart of reverse‑skill's installation system is skills/scripts/bootstrap-manifest.json. This file maps each capability to its installation method.
Each manifest entry for GitHub releases includes:
name— the capability identifier (e.g.,jadx,ghidra,anything-analyzer)bootstrapKind— the fetch strategy:"github-release-zip","github-release-tar", or"github-release-jar-wrapper"repo— the GitHub repository providing the release (e.g.,skylot/jadx)assetRegex— a regular expression matching the desired asset (e.g.,.*\.zip)assetSha256orpreferApiDigest— optional checksum fields for verification
The manifest enforces the repository's "no‑guess‑path" policy defined in RULES.md, ensuring every tool acquisition is explicit and reproducible.
Detecting Missing Tools During Skill Execution
When a reverse‑skill runs, it validates required tools against skills/tool-index.md. If a capability is absent, the runner automatically invokes the appropriate bootstrap script:
- Windows:
skills/scripts/bootstrap-reverse.ps1 -Capability @('name') - Linux/macOS:
skills/scripts/bootstrap-reverse.sh name - Kali Linux:
kali/scripts/bootstrap-reverse.sh name
This detection happens transparently, allowing skills to declare dependencies without embedding installation logic.
Fetching Release Assets from the GitHub API
PowerShell Implementation
The bootstrap-reverse.ps1 script defines Get‑GitHubLatestReleaseAsset around line 375. This function:
- Constructs the API URL:
https://api.github.com/repos/$Repo/releases/tags/$ReleaseTagor/releases/latest - Issues a request via
Invoke‑RestMethodwith a customUser‑Agentheader - Selects the first asset whose name matches the
AssetRegexpattern
# Windows – install JADX and start its MCP service
powershell -NoProfile -ExecutionPolicy Bypass `
-File skills\scripts\bootstrap-reverse.ps1 `
-Capability @('jadx') -StartServices
Bash Implementation
The bootstrap-reverse.sh script performs equivalent operations using curl or wget, parsing the JSON response to extract the browser download URL. The Kali‑specific variant in kali/scripts/bootstrap-reverse.sh layers additional package‑manager integration (apt, pipx, npm) before falling back to GitHub releases.
# Linux/macOS – install Frida and Anything‑Analyzer, then register them
bash skills/scripts/bootstrap-reverse.sh frida anything-analyzer --start-services
# Kali – install pentesting tools in one shot
bash kali/scripts/bootstrap-reverse.sh metasploitmcp nmap burpsuite-mcp
Verifying Download Integrity
Before extraction, reverse‑skill validates the downloaded artifact:
- If
assetSha256is provided in the manifest, the script computes and compares the SHA256 hash - If
preferApiDigestis enabled, the script uses the digest provided by GitHub's API - Verification failures abort installation and surface actionable error messages
This safeguard appears in the verification logic of bootstrap-reverse.ps1 (lines 365–367 according to source analysis), preventing corrupted or tampered tools from entering the execution environment.
Installing and Registering Tools
After successful download and verification, the bootstrap script:
- Extracts the archive (zip or tar) to a temporary directory
- Moves contents to
$HOME/.reverse-skill/tools/<name>or equivalent platform path - For
github-release-jar-wrapperentries, places the JAR directly and generates a wrapper script - When
-StartServicesor--start-servicesis specified, registers the tool with the MCP (Modular Capability Platform)
MCP registration enables other skills to discover the tool automatically without path configuration.
Platform‑Specific Entry Points
| Platform | Script Path | Typical Invocation |
|---|---|---|
| Windows | skills/scripts/bootstrap-reverse.ps1 |
powershell -NoProfile -ExecutionPolicy Bypass -File skills\scripts\bootstrap-reverse.ps1 -Capability @('jadx','frida') -StartServices |
| Generic Linux / macOS | skills/scripts/bootstrap-reverse.sh |
bash skills/scripts/bootstrap-reverse.sh jadx frida --start-services |
| Kali Linux | kali/scripts/bootstrap-reverse.sh |
bash kali/scripts/bootstrap-reverse.sh jadx frida |
Platform documentation in docs/platforms/linux.md and docs/platforms/macos.md details prerequisite package managers and fallback behavior when native packages are preferred over GitHub releases.
Complete Installation Flow
Understanding how reverse‑skill handles GitHub release installation requires following the end‑to‑end sequence:
- Skill execution detects a missing capability via
skills/tool-index.md - Bootstrap script launches with the capability list as arguments
- Manifest lookup resolves
bootstrapKindto a GitHub release strategy - GitHub API request locates the matching release asset using
assetRegex - Download and checksum verification ensures integrity
- Extract and install places the tool in the managed directory
- Optional service start registers with MCP for downstream discovery
This pipeline makes tools self‑contained, reproducible, and immediately usable across all supported platforms.
Summary
- Reverse‑skill uses
bootstrap-manifest.jsonto declaratively map capabilities to GitHub release assets - Three platform‑specific scripts handle installation: PowerShell for Windows, Bash for Linux/macOS, and a specialized Kali variant
- The
Get‑GitHubLatestReleaseAssetfunction inbootstrap-reverse.ps1queries GitHub's API with regex‑based asset selection - Checksum verification via
assetSha256or API digests prevents compromised tool installation - MCP registration with
-StartServicesmakes tools discoverable to other skills without manual configuration
Frequently Asked Questions
How does reverse‑skill know which GitHub release asset to download?
The assetRegex field in bootstrap-manifest.json defines a regular expression that matches the desired filename in the release. The bootstrap script selects the first matching asset, allowing version‑independent patterns like .*-windows\.zip or jadx-.*\.zip.
What happens if GitHub's API rate limits the bootstrap request?
The PowerShell script uses a custom User-Agent header, and the Bash scripts support both curl and wget with appropriate flags. For environments with strict rate limits, pre‑placing tools in the expected directory bypasses automatic fetching entirely.
Can I install tools without starting MCP services?
Yes. Omit -StartServices on Windows or --start-services on Linux/macOS. The tool installs to the filesystem but skips MCP registration, making it available for manual use without exposing it to the capability platform.
How does the Kali bootstrap differ from the generic Linux version?
kali/scripts/bootstrap-reverse.sh prioritizes native package managers (apt, pipx, npm) before attempting GitHub releases. This aligns with Kali's security‑focused distribution model while maintaining the same manifest‑driven fallback behavior.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →