Windows, Linux, and Kali Bootstrap Scripts for reverse-skill: Complete Setup Guide
reverse-skill provides three platform-specific bootstrap scripts—PowerShell for Windows, Bash for generic Linux/macOS, and a specialized Kali wrapper—that automatically install reverse engineering tools based on a shared JSON manifest.
The zhaoxuya520/reverse-skill repository ships automated setup scripts that eliminate manual dependency management across Windows, Linux, and Kali Linux environments. Each script parses a capability manifest, resolves tool dependencies, and installs them through native package managers or direct downloads. This guide covers all three platform implementations, their differences, and how to use them effectively.
Windows Bootstrap Script (PowerShell)
The Windows bootstrap is implemented in skills/scripts/bootstrap-reverse.ps1. It handles PowerShell-only tooling, winget packages, and Windows-specific installation paths.
How to Run the Windows Script
powershell -NoProfile -ExecutionPolicy Bypass `
-File skills/scripts/bootstrap-reverse.ps1 `
-Capability apktool,adb,anything-analyzer
Key Windows-Specific Behavior
- OS detection: Uses
Test-ReverseIsWindowsinternal function to confirm platform - Package management: Preferred order is
winget→ manual download → build from source - Path injection: Updates
$env:PATHpersistently via registry modifications - Wrapper creation: Generates
.cmdfiles for Java-based tools likeapktool
The Windows script reads skills/scripts/bootstrap-manifest.json to determine download URLs, checksums, and installation methods. For capabilities marked with bootstrapKind: "winget", it executes winget install directly.
Linux and macOS Bootstrap Script (Bash)
The generic Unix bootstrap lives in skills/scripts/bootstrap-reverse.sh. It uses POSIX-compatible commands for maximum portability across distributions.
Running the Linux/macOS Script
# Install specific capabilities
bash skills/scripts/bootstrap-reverse.sh radare2,go-tools
# Single capability
bash skills/scripts/bootstrap-reverse.sh adb
Platform Resolution Logic
The script detects the host distribution and selects the appropriate package manager:
- Debian/Ubuntu:
apt-get - RHEL/CentOS/Fedora:
dnforyum - macOS:
brew(if available) or manual installation - Fallback: Direct download and extraction
For GitHub-hosted releases, the script calls functions from skills/scripts/lib/bootstrap-supply-chain.sh to verify SHA-256 checksums before extraction.
Kali Linux Bootstrap Script
Kali Linux receives specialized treatment via kali/scripts/bootstrap-reverse.sh, which extends the generic Linux logic with penetration-testing-specific packages.
Kali-Specific Features
- Dual manifest loading: Reads
kali/scripts/bootstrap-manifest.jsonfirst, then falls back to the generic manifest - Debian package handling: Direct
apt-get install -yfor Kali metapackages (e.g.,kali-tools-top10) - MCP server shortcuts: Auto-generates systemd user service files for
anything-analyzer
Running the Kali Bootstrap
bash kali/scripts/bootstrap-reverse.sh \
nmap,sqlmap,metasploit-framework
Kali Manifest Overrides
The Kali manifest (kali/scripts/bootstrap-manifest.json) can:
- Override download URLs for Kali-packaged versions
- Add
aptPackageentries not present in the generic manifest - Specify
kaliCategorytags for tool organization
Shared Bootstrap Flow (All Platforms)
All three scripts follow an identical five-phase process:
- Manifest loading: Parse JSON capability definitions
- Dependency resolution: Check existing tools via
Get-Command(PowerShell) orwhich(Bash) - Tool installation: Execute platform-specific
bootstrapKindhandlers:packageManager: winget, apt, dnf, brewgithubRelease: Download, verify, extractbuildFromSource: go install, pip, npm
- MCP registration: Configure server endpoints if the capability exposes one
- Index refresh: Run
refresh-tool-indexto updateskills/tool-index.md
Scripts are idempotent—re-running skips already-installed tools and only adds missing capabilities.
Verifying Installation Results
Each script outputs JSON for programmatic inspection:
Windows Verification
powershell -NoProfile -ExecutionPolicy Bypass `
-File skills/scripts/bootstrap-reverse.ps1 -Capability adb `
| ConvertFrom-Json | Format-Table name,status,ready
Linux/Kali Verification
bash skills/scripts/bootstrap-reverse.sh adb \
| jq '.[] | {name, status, ready}'
A successful installation returns "status": "ready" and "ready": true. Failed installations include an error field with diagnostic details.
Core Library Files
| File | Purpose |
|---|---|
skills/scripts/lib/ToolDiscovery.ps1 / tool-discovery.sh |
Locate existing system tools |
skills/scripts/lib/BootstrapSupplyChain.ps1 / bootstrap-supply-chain.sh |
Download, verify, and extract remote assets |
skills/scripts/refresh-tool-index.ps1 / kali/scripts/refresh-tool-index.sh |
Regenerate tool documentation |
Summary
skills/scripts/bootstrap-reverse.ps1: Windows PowerShell bootstrap with winget integrationskills/scripts/bootstrap-reverse.sh: Generic Linux and macOS Bash bootstrapkali/scripts/bootstrap-reverse.sh: Kali-specific wrapper with pentesting package support- All scripts share
bootstrap-manifest.jsonformat and produce structured JSON output - Idempotent design allows safe repeated execution
Frequently Asked Questions
What distinguishes the Kali bootstrap from the generic Linux script?
The Kali bootstrap loads a secondary manifest at kali/scripts/bootstrap-manifest.json that contains Kali-specific package names and Debian repositories. It also applies automatic apt-get install logic for tools already packaged in Kali's repositories, avoiding redundant compilation.
Can I run these scripts on already-configured systems without breaking anything?
Yes. All bootstrap scripts implement idempotent installation: they check for existing tools via Get-Command (Windows) or which (Linux) before attempting installation. Already-present tools are skipped with "status": "present" in the JSON output.
What PowerShell execution policy is required for the Windows script?
The script requires Bypass execution policy for the current process only. The documented invocation (-NoProfile -ExecutionPolicy Bypass) does not change system-wide policy and avoids persistent security modifications.
How do I add a custom capability to the bootstrap process?
Add an entry to skills/scripts/bootstrap-manifest.json (or kali/scripts/bootstrap-manifest.json for Kali-specific tools) with fields for name, bootstrapKind, sourceUrl, and verificationHash. The scripts will automatically pick up new capabilities on next run.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →