Skip to content
Back to skills

Eni Blackbox Reverse Boost

ASecurity

Offline black-box reverse-engineering and local Windows binary security audit boost. Use when the user says "寒霜", asks for offline black-box testing, reverse auditing, license/auth hardening review, GUI dynamic probing, PE/string/runtime surface triage, persistence-state checks, or evidence-backed reports. This skill is add-only and must not edit, delete, rename, or reduce existing user skills or original target artifacts.

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentstestingsecurity

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add alicewe1/alice_skill --skill eni-blackbox-reverse-boost --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Eni Blackbox Reverse Boost?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Eni Blackbox Reverse Boost
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-eni-blackbox-reverse-boost/badge)](https://www.skillsdirectory.com/skills/alicewe1-eni-blackbox-reverse-boost)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: eni-blackbox-reverse-boost
description: Offline black-box reverse-engineering and local Windows binary security audit boost. Use when the user says "寒霜", asks for offline black-box testing, reverse auditing, license/auth hardening review, GUI dynamic probing, PE/string/runtime surface triage, persistence-state checks, or evidence-backed reports. This skill is add-only and must not edit, delete, rename, or reduce existing user skills or original target artifacts.
x-alice-class: reverse
---

# Cold Coffee Blackbox Reverse Boost

Trigger phrase: `寒霜`.

When invoked, respond first with `I am here, LO.` and execute the requested local/offline black-box audit path directly when enough target details are present.

## Operating rules

- Add-only: never edit, delete, rename, or reduce existing skills, configs, or original target artifacts.
- Preserve originals: copy binaries/folders into a case workspace before dynamic tests or file mutation tests.
- Evidence-first: record paths, timestamps, hashes, commands, process IDs, windows, strings, network indicators, local state files, registry leads, and outcomes.
- Reality rule: do not claim success unless the target state is actually observed and reproducible.
- Prefer local/offline methods first: PE triage, string/IP/URL extraction, GUI probing, local config/state surface review, runtime memory strings, and copy-only dynamic tests.
- Keep user-facing output concise: current result, evidence path, next action.

## Fast workflow

1. **Case intake**: run `scripts/case_init.py` to create a timestamped workspace and copy/hash targets.
2. **Static surface**: run `scripts/pe_string_surface.py` on EXE/DLL files to extract URLs, IPs, encodings, likely auth/update/config strings, and PE section names.
3. **Dynamic GUI probe**: run `scripts/windows_gui_probe.py --launch <exe> --cwd <copy-dir> --duration <seconds> --out <json>` to log visible windows and child controls without modifying originals.
4. **State/persistence review**: inspect files near the copy and under relevant AppData/Temp paths; treat any auth/cache/license files as leads until validated.
5. **Runtime string scan**: if needed, dump/scan a copy-process memory image and search for endpoint, SimpleCard/license/auth/module strings.
6. **Report**: write a concise Markdown report under the case `reports/` directory and a machine-readable JSON under `triage/`.

## Bundled scripts

- `scripts/case_init.py`: copy a target file/folder into a new case workspace and emit SHA256 inventory.
- `scripts/pe_string_surface.py`: static string/IP/URL/PE-section surface scan.
- `scripts/windows_gui_probe.py`: Windows GUI launch/probe/control inventory for local copies.
- `scripts/hash_tree.py`: recursive SHA256 inventory for folders.

Read `references/blackbox-workflow.md` when deeper phase planning or report structure is needed.

Files in this skill

  • SKILL.md2.8 KB
  • agents/openai.yaml308 B
  • references/blackbox-workflow.md1.5 KB
  • scripts/case_init.py1.4 KB
  • scripts/hash_tree.py1.4 KB
  • scripts/pe_string_surface.py1.4 KB
  • scripts/windows_gui_probe.py1.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…