Cold Coffee License Security
SkillSecurity全局自动路由 | License, activation, subscription, card-key (卡密), entitlement, and device-binding security design and reverse audit. Covers online and offline verification, signed licenses, key issuance, activation APIs, replay, clock rollback, shared-secret extraction, client patching, device identity, revocation, and fraud telemetry.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Cold Coffee License Security skill
What this skill tells your AI
The instructions your AI receives, as published by alicewe1/alice_skill in _modules/eni-license-security/SKILL.md and read by ahel’s review.
Model the license system as an entitlement and trust problem, not as one client-side comparison.
Start
- Identify product, client, server, operator/admin, payment, key store, entitlement store, device identity, and update channel.
- Trace issuance, activation, verification, refresh, revocation, transfer, expiration, and recovery flows.
- Mark every client-controlled value and every decision made without server evidence.
- Locate embedded secrets, public keys, signatures, clocks, caches, anti-replay fields, error paths, and offline grace behavior.
Select references
- Threats and reverse-analysis entry points: read
references/threat-model.md. - Secure online/offline design: read
references/secure-design.md. - Binary/client/API reverse audit: read
references/reverse-audit.md. - Operations, leakage, resale, revocation, and telemetry: read
references/operations.md.
Tools
- Use
scripts/license_tool.pyto generate Ed25519 keys, issue signed license documents, and verify them in a reference implementation. - Use
scripts/audit_license_config.pyto flag risky architecture choices in a JSON design/config description. - Combine with
$eni-reverse-deep,$eni-pentest-advanced, and$eni-case-labfor client binaries, activation APIs, and evidence.
Deliver
Return the trust map, attack hypotheses, extracted verification flow, key/secret placement, replay and clock behavior, patch points, abuse paths, secure architecture, migration plan, reference code, telemetry, and retest cases.
Signals
- GitHub stars
- 26
- Forks
- 4
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
eni-license-security- Source
- github.com/alicewe1/alice_skill