# How the zhaoxuya520/reverse-skill Skill Router Chooses Reverse Engineering Modules

> Discover how the zhaoxuya520/reverse-skill router selects reverse engineering modules by matching task hints against regex patterns, scoring matches, and using tie-breaking priority.

- Repository: [ZhaoXu/reverse-skill](https://github.com/zhaoxuya520/reverse-skill)
- Tags: how-to-guide
- Published: 2026-08-14

---

**The skill router selects reverse engineering modules by matching user task hints against curated regex patterns in [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json), scoring matches, and applying a deterministic priority order to break ties.**

The `zhaoxuya520/reverse-skill` repository implements a **declarative routing system** that eliminates guesswork when dispatching reverse engineering tasks. Instead of hard-coded logic, the skill router uses a JSON-driven classification engine that maps natural language hints to specialized modules like APK reverse engineering, kernel exploitation, or WiFi penetration testing.

## How the Routing Decision Works

The skill router follows a five-step evaluation pipeline defined in [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json). Each route (`R0` through `R40`) represents a distinct reverse engineering domain with its own keyword signatures and module path.

### Step 1: Keyword Matching with Regex Rules

Every route contains a **`keywords`** array defining *must* regex patterns (plus optional *exclude* or *mustAll* expressions). When a user provides a hint, the router scans against all 40+ rule sets simultaneously.

- `R1` (APK reverse): `\bapk\b|smali|jadx|apktool|…`
- `R6` (IDA reverse): `ida|idapro|hexrays|…`
- `R28` (Kernel exploit): `kernel|rootkit|lkernel|…`

A hint containing "apk reverse and root detection" matches `R1` because `\bapk\b` satisfies its *must* condition.

### Step 2: Scoring Matched Candidates

Each route that matches at least one keyword set receives a **score** equal to its number of matched keyword objects. Multiple matches are common—hints like "analyze APK with IDA" may trigger both `R1` and `R6`.

### Step 3: Priority Resolution

The router consults the ordered **`priority`** array (lines 310–314 of [`routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.json)) to break ties. The highest-priority candidate with the maximal score wins. If `R1` appears before `R6` in priority and both score equally, `R1` becomes the **PRIMARY** route.

### Step 4: Fallback to Generic Skill

When no keywords match, the router uses `fallbackId: "R0"` (lines 5–6), directing to [`reverse-engineering/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/reverse-engineering/SKILL.md)—the generic reverse engineering module.

### Step 5: Module Activation

The selected route's **`skill`** field provides the relative path to its [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) file (e.g., [`apk-reverse/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/apk-reverse/SKILL.md)). This markdown file contains the actual instructions, tools, and workflows for that domain.

## Running the Router: PowerShell Implementation

The routing algorithm is implemented in `skills/scripts/master-route.ps1`, which reads [`routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.json) and executes the exact matching and scoring logic described above.

```powershell

# Execute routing with a specific task hint

powershell -NoProfile -ExecutionPolicy Bypass `
  -File skills\scripts\master-route.ps1 -Hint "apk reverse and root detection"

# Expected output:

#   PRIMARY = R1 – apk-reverse/SKILL.md

#   Reason  = "matched keyword set {must: '\bapk\b|smali|jadx|apktool'} with score 2"

```

The script loads the JSON configuration, applies regex evaluation, tallies scores, applies priority ordering, and emits the selected route with diagnostic reasoning.

## Fallback Behavior Demonstrated

```powershell

# Generic hints trigger the fallback route

powershell -File skills\scripts\master-route.ps1 -Hint "general reverse engineering"

# Output:

#   PRIMARY = R0 – reverse-engineering/SKILL.md

#   Reason  = "no keyword matched → fallbackId"

```

This ensures the system always produces actionable output even for ambiguous or novel task descriptions.

## Key Configuration Files

Understanding these files is essential for customizing or debugging the skill router:

| File | Purpose |
|------|---------|
| [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json) | Central routing definition containing all routes, keyword regexes, priority array, and fallback configuration |
| `skills/scripts/master-route.ps1` | PowerShell implementation of the matching, scoring, and selection algorithm |
| [`skills/MASTER-ROUTING.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/MASTER-ROUTING.md) | Human-readable documentation of routing contracts and priority tables |
| [`apk-reverse/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/apk-reverse/SKILL.md) | Example specialized module for Android APK analysis |
| [`reverse-engineering/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/reverse-engineering/SKILL.md) | Generic fallback module for unspecified reverse engineering tasks |

## Customizing Route Priority

To change how the skill router chooses reverse engineering modules, modify the `priority` array in [`routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.json). Earlier entries win ties. To add new domains, define a route with:

- Unique `id` (e.g., `R41`)
- `keywords` array with targeted regex patterns
- `skill` path pointing to your module's [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md)
- Insertion into the `priority` list at your preferred rank

The regex-based approach allows precise vocabulary control without code changes—domain expertise is encoded declaratively in JSON.

## Summary

- **Single source of truth**: [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json) drives all routing decisions
- **Regex keyword matching**: Routes define vocabulary signatures with *must*, *exclude*, and *mustAll* conditions
- **Score-based selection**: More matched keywords increase candidacy strength
- **Deterministic priority tie-breaking**: Ordered priority array guarantees reproducible outcomes
- **Guaranteed fallback**: `R0` generic skill handles unmatched hints
- **PowerShell automation**: `master-route.ps1` implements the complete algorithm for scripting integration

## Frequently Asked Questions

### How do I add support for a new reverse engineering domain?

Create a new route entry in [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json) with a unique ID, define targeted regex patterns in the `keywords` array, set the `skill` path to your module's [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md), and insert the ID into the `priority` array at your desired rank. No PowerShell code changes are required.

### What happens when multiple routes match with identical scores?

The router consults the `priority` array in order. The candidate appearing earlier in this list wins. This deterministic rule prevents random selection and ensures consistent, auditable behavior across identical hints.

### Can I use negative keywords to exclude certain matches?

Yes. Routes support *exclude* regex patterns in their keyword definitions. If a hint matches an exclusion pattern, that route is disqualified regardless of other matches. This enables precise boundary drawing between overlapping domains like mobile and binary analysis.

### Where is the fallback route configured?

The fallback is defined at lines 5–6 of [`skills/config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/config/routing.json) via the `fallbackId` field, which defaults to `R0`. This points to [`reverse-engineering/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/reverse-engineering/SKILL.md), ensuring every hint receives a actionable response even when no specialized keywords trigger.