Reverse-Skill Bootstrap Capabilities and Extension Guide
The reverse-skill repository provides platform-specific bootstrap scripts that prepare hosts by reading JSON manifests to download, verify, and install tools automatically.
The reverse-skill project implements a manifest-driven bootstrap system that prepares Windows, Linux/macOS, and Kali environments for its skill-routing engine. Understanding how to leverage and extend these bootstrap capabilities lets you add new tools without modifying shell or PowerShell logic.
Available Bootstrap Platforms and Entry Points
The repository ships with three platform-specific bootstrap implementations:
| Platform | Entry Point Script | Manifest Path |
|---|---|---|
| Linux / macOS | skills/scripts/bootstrap-reverse.sh |
skills/scripts/bootstrap-manifest.json |
| Windows | skills/scripts/bootstrap-reverse.ps1 |
skills/scripts/bootstrap-manifest.json |
| Kali Linux | kali/scripts/bootstrap-reverse.sh |
kali/scripts/bootstrap-manifest.json |
Each platform's bootstrap script follows the same execution pattern defined in the source code:
- Detect platform — the routing layer invokes the appropriate
*.shor*.ps1script - Load manifest — the JSON manifest specifies tools, download URLs, optional checksums, and post-install commands
- Download and verify — for each entry, the script checks for existing binaries, downloads using
curl/wgetorInvoke-WebRequest, and verifies checksums when provided - Execute install commands — runs any custom setup logic (archive extraction, package installation)
- Refresh tool index — triggers
skills/scripts/refresh-tool-index.*to rebuildskills/tool-index.mdfor runtime routing
Bootstrap Manifest Structure
The bootstrap manifest is a pure data file that decouples tool definitions from platform logic. A minimal entry follows this schema:
{
"name": "example-tool",
"url": "https://example.com/example-tool.tar.gz",
"checksum": "sha256:abcdef1234567890...",
"install": "tar -xzf example-tool.tar.gz -C $TOOLS_DIR",
"binary": "example-tool"
}
Field definitions as implemented in the bootstrap scripts:
name— human-readable identifier used for logging and index generationurl— direct download link; must be accessible without authenticationchecksum— optional but recommended; format isalgorithm:digest(typicallysha256)install— shell command executed after download; runs in subshell with$TOOLS_DIRavailablebinary— expected executable name for existence checks and routing lookups
How to Extend Bootstrap Capabilities
Extending the bootstrap process requires only manifest edits. Follow these steps to add new tools:
Step 1: Add Tool Definition to Manifest
Open the appropriate bootstrap-manifest.json for your target platform. For cross-platform tools, add to skills/scripts/bootstrap-manifest.json. Kali-specific tools belong in kali/scripts/bootstrap-manifest.json.
Step 2: Configure Download and Verification
Specify a direct url and checksum. The bootstrap scripts automatically detect and verify supported algorithms.
Step 3: Define Install Behavior
The install field accepts arbitrary shell commands. For simple archive extraction:
"install": "unzip -o tool.zip -d $TOOLS_DIR/bin"
For Python packages requiring pip:
"install": "pip3 install --target $TOOLS_DIR/lib some-package"
The $TOOLS_DIR variable defaults to ~/.local/reverse-skill/tools on Unix systems and a corresponding path on Windows.
Step 4: Specify Binary Location
The binary field enables the bootstrap script to skip redundant downloads and allows the routing engine to locate the tool. If your install command places the executable in a subdirectory, ensure the routing layer can resolve it via skills/tool-index.md.
Step 5: Execute Bootstrap and Verify
Run the platform-appropriate script:
# Linux / macOS
bash skills/scripts/bootstrap-reverse.sh
# Windows PowerShell
powershell -NoProfile -ExecutionPolicy Bypass -File skills/scripts/bootstrap-reverse.ps1
# Kali
bash kali/scripts/bootstrap-reverse.sh
Check skills/tool-index.md to confirm the new tool appears in the generated index.
Practical Extension Example
Adding pwntools to the Linux bootstrap demonstrates the complete workflow:
{
"name": "pwntools",
"url": "https://files.pythonhosted.org/packages/.../pwntools-4.9.0.tar.gz",
"checksum": "sha256:3d5f8c9e2f0b...",
"install": "pip3 install pwntools-4.9.0.tar.gz",
"binary": "pwn"
}
Save this entry to skills/scripts/bootstrap-manifest.json, then execute:
bash skills/scripts/bootstrap-reverse.sh
The script downloads the tarball, validates the SHA-256 digest, installs via pip3, and regenerates the tool index. The pwn command becomes available to any skill that depends on Python exploitation utilities.
Key Source Files for Bootstrap Extension
| File Path | Purpose |
|---|---|
skills/scripts/bootstrap-reverse.sh |
Linux/macOS bootstrap driver with curl/wget download logic |
skills/scripts/bootstrap-reverse.ps1 |
Windows bootstrap driver using Invoke-WebRequest |
skills/scripts/bootstrap-manifest.json |
Core cross-platform tool definitions |
kali/scripts/bootstrap-reverse.sh |
Kali-specific bootstrap with penetration testing defaults |
kali/scripts/bootstrap-manifest.json |
Kali-specific tool manifest (extends core manifest) |
skills/scripts/refresh-tool-index.sh / refresh-tool-index.ps1 |
Index regeneration scripts called post-bootstrap |
skills/tool-index.md |
Generated runtime index consumed by routing engine |
Summary
- Bootstrap capabilities in
reverse-skillare manifest-driven and platform-agnostic at the data layer - Three platform scripts (
bootstrap-reverse.sh,bootstrap-reverse.ps1,kali/scripts/bootstrap-reverse.sh) implement identical download-verify-install workflows - Extension requires only JSON edits to
bootstrap-manifest.jsonfiles—no shell script modifications needed - The
checksum,install, andbinaryfields provide security, flexibility, and routing integration - Post-bootstrap index regeneration ensures the routing engine discovers new tools automatically
Frequently Asked Questions
What checksum algorithms does the bootstrap system support?
The bootstrap scripts parse checksums in algorithm:digest format. Based on the implementation patterns in skills/scripts/bootstrap-reverse.sh and skills/scripts/bootstrap-reverse.ps1, SHA-256 is the primary algorithm used, though the verification logic typically delegates to platform tools (sha256sum on Linux, Get-FileHash on Windows) that may support additional algorithms.
Can I override the default tools directory?
Yes. The bootstrap scripts reference $TOOLS_DIR (Unix) or $env:TOOLS_DIR (Windows) to determine installation paths. Set this environment variable before running the bootstrap script to redirect tool installation. Ensure the routing engine's configuration points to the same location for tool discovery.
How do I add platform-specific install commands?
Use the platform-specific manifest files. Commands in kali/scripts/bootstrap-manifest.json execute only on Kali, while skills/scripts/bootstrap-manifest.json applies to all platforms. For conditional logic within a single entry, include platform-detection in the install string, though separating entries by manifest is the cleaner approach supported by the source architecture.
What happens if a download fails during bootstrap?
The bootstrap scripts perform existence checks before downloading. If a network request fails, the script logs the error and typically continues with remaining entries (behavior verified in skills/scripts/bootstrap-reverse.sh error handling). Checksums that fail verification halt installation for that specific tool to prevent corrupted or tampered binaries from entering the toolchain.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →