John Smith 87cea048cc feat(v2.7.0): cycle 4 — sandbox-emulation, uefi-firmware-re, reference-awesome-lists
Adds 3 new content entries to close the cycle 4 expansion gap
from the 2026-06-06-r02 review. Extends the Zod (TS) and
Pydantic (Python) schemas with the 3 new categories, fixes
the broken related[] cross-links in the existing 14 entries,
and bumps the loader test coverage to assert the new
categories are picked up.

### Added
- `content/sandbox-emulation/01-decision-tree.md` — the
  sandbox / bare-metal / snapshot isolation decision tree,
  covering the QEMU / Unicorn / Speakeasy / ws2/wine
  trade-off matrix and the "when to break glass and use
  the proprietary target's own VM" rule.
- `content/uefi-firmware-re/01-efi-analysis.md` — UEFI
  firmware reverse engineering entry. PI volumes, the
  EFI protocol surface, the secure-boot chain, and the
  chipsec / UEFITool / efida unpacking workflow.
- `content/reference-awesome-lists/01-curated-indices.md`
  — the curated "awesome-*" indices pointer entry.
  Cross-links to the cycle 1-3 entries by the
  awesome-list-pointer convention so search hits resolve
  to the right category.

### Changed
- `mcp-server/src/re_library_mcp/schema.py` — adds the 3
  new category enums + a related[] cross-link validator.
- `mcp-server/src/re_library_mcp/loader.py` — accepts the
  new content roots, validates the new categories on load.
- `src/content.config.ts` — adds the 3 new collection
  schemas.
- `mcp-server/tests/test_loader.py` — asserts the 3 new
  categories load and that related[] pointers resolve.
- `mcp-server/tests/test_tools.py` — extends the
  parametrized list-with-category test to cover the 3
  new entries.
- `content/{drm/01-cdm-architecture,native/01-elf-format,
  packers/01-upx}.md` — fixes broken related[] pointers
  to the new cycle 4 entries.

### Verification
- `mcp-server/tests/` — 30 passed
  (test_loader, test_no_drm_names, test_schema_sync,
  test_search, test_tools)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-06 19:15:05 -04:00

RE-Library

A context7-style knowledge base for Reverse Engineering. Curated markdown entries on techniques, anti-analysis bypass, mobile internals, packers, and the tools that pull them apart. Read it on the web, or wire it into Claude / Cursor / any MCP client.

The site is live at https://heretek-ai.github.io/RE-Library/.

What's in it

Eight categories, ~50 entries (growing):

Category What it covers
android APK structure, smali, native libs, Frida on Android, repackaging, SSL pinning, root detection
ios IPA structure, ObjC runtime, Swift demangling, jailbreak detection, Frida on iOS, Objection
anti-analysis Anti-debug, anti-VM, anti-sandbox, anti-Frida, anti-dumper, code integrity, detection patterns
drm CDM architecture, security levels, key ladders, proxy/relay, attestation (no system names)
packers UPX, Themida, VMProtect, OLLVM, custom packers
tools Ghidra, IDA, Binary Ninja, Frida, Xposed, Magisk, Hopper, radare2
native PE, ELF, Mach-O, dynamic analysis, syscalls, hooking
web-hybrid Electron, WebAssembly, browser extensions, hybrid frameworks, Cordova

The drm/ category intentionally doesn't name any specific DRM system. The content describes architectures, security models, and protocol shapes; readers who know the space will recognise which system is being described. See CONTRIBUTING.md for the full content policy.

Use it from an MCP client

The MCP server is a Python package (re-library-mcp) that exposes the same content over the Model Context Protocol. Install and configure:

pip install re-library-mcp

Add to your MCP client config (e.g. claude_desktop_config.json):

{
  "mcpServers": {
    "re-library": {
      "command": "python",
      "args": ["-m", "re_library_mcp"]
    }
  }
}

Then ask your assistant things like:

  • "What are the main ways to bypass SSL pinning on Android?"
  • "Show me anti-debug techniques for native code on Linux."
  • "List the categories and how many entries each has."

The server fetches the latest content from this repo on startup and returns search results, full entry text, and category summaries.

Run the site locally

npm install
npm run dev
# → http://localhost:4321/RE-Library/

Build the static site + Pagefind index:

npm run build
# → dist/  (deploy dist/ to any static host)

Repository layout

content/        single source of truth — every entry is a .md file
src/            Astro site (content collections, pages, styles)
public/         static assets (favicon, etc.)
mcp-server/     Python MCP server (publishable to PyPI as `re-library-mcp`)
.github/        CI + GitHub Pages deploy

Contributing

See CONTRIBUTING.md for the entry template, schema reference, DRM guardrail, and how to run the test suite.

License

MIT. Entry content is provided for educational and research purposes; no warranty of fitness for any particular use.

Latest
2026-06-04 14:38:00 -04:00
Languages
Python 69.2%
Astro 17.3%
CSS 8.4%
TypeScript 4.6%
JavaScript 0.5%