Agent skill

Unpack Investigate Artifacts

by AetherKiri in AetherKiri/Aether

Safely unpack and investigate existing archives through evidence-first static analysis.

GPL-3.0Auto-check passedSecurity

Install Unpack Investigate Artifacts

skills CLI
$ npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AetherKiri/Aether unpack-investigate-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AetherKiri/Aether.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/unpack-investigate-artifacts .claude/skills/unpack-investigate-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unpack-investigate-artifacts
GitHub stars
154
Token cost
~1.6k tokens
SKILL.md length
761 words
Files
3 (incl. scripts)
Skills in repo
3
Repo updated
First seen
Licence
GPL-3.0

At a glance

Safely unpack and investigate existing archives through evidence-first static analysis.

  • Works in 4 steps: Record the source path, byte size,… → Identify the format from magic and… → List archive members before extracting.… → …
  • Codex is given a diagnostic ZIP
  • SKILL.md covers Recognize an AetherKiri…, Preserve provenance, Build an inventory and Route the investigation, plus 2 more sections
  • Runs Python scripts from its folder; calls python3 and rg

What it does

Unpack Investigate Artifacts is an agent skill from AetherKiri/Aether. Safely unpack and investigate existing archives through evidence-first static analysis. Use when Codex is given a diagnostic ZIP or directory produced by a collection tool such as AetherKiri tools/diagnose.py, or a TAR, APK, IPA, .app bundle, crash archive, or opaque package, and needs to validate integrity, align events and markers, compare layers, or identify the first unsupported boundary without building, installing, launching, reproducing, or collecting from a device.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/safe_unpack.py`).

It sits in Security, covering Static analysis and SAST. It works with iOS and macOS. The repository describes itself as: A cross-platform, multi-runtime visual novel emulator using Godot 4 as the rendering layer. The licence is GPL-3.0.

When your agent uses it

  • Codex is given a diagnostic ZIP
  • Directory produced by a collection tool such as AetherKiri tools/diagnose.py
  • Needs to validate integrity
  • Align events and markers

Example prompts

  • “/unpack-investigate-artifacts”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Record the source path, byte size, modification time, and SHA-256 before extraction.
  2. Identify the format from magic and structure, not only the extension.
  3. List archive members before extracting. Flag encrypted entries, absolute paths, traversal components, links, devices, surprising…
  4. Extract into a new disposable directory. Never overwrite the source or extract over a working tree.

What it can do on your machine

Read from SKILL.md and the folder at commit d4e017a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unpack Investigate Artifacts loads about 1.6k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 761 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from AetherKiri/Aether at commit d4e017a, republished under its GPL-3.0 licence (© AetherKiri). 761 words, ~1,648 tokens.

Download SKILL.mdSave it as .claude/skills/unpack-investigate-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
unpack-investigate-artifacts
description
Safely unpack and investigate existing archives through evidence-first static analysis. Use when Codex is given a diagnostic ZIP or directory produced by a collection tool such as AetherKiri tools/diagnose.py, or a TAR, APK, IPA, .app bundle, crash archive, or opaque package, and needs to validate integrity, align events and markers, compare layers, or identify the first unsupported boundary without building, installing, launching, reproducing, or collecting from a device.

Unpack and Investigate Artifacts

Begin with the artifact the user supplied. Do not build, install, launch, reproduce, or run any collection command. In particular, never invoke tools/diagnose.py from this skill; it consumes the package that script already produced.

Recognize an AetherKiri diagnostic bundle

Treat an existing out/diagnostics/<timestamp>-<platform>-<session>.zip or its matching directory as the primary input for this workflow. If the user says “the diagnostic package” without a path, locate the newest completed ZIP under out/diagnostics/; do not run tools/diagnose.py to create one.

After safe extraction, verify the bundle contract before interpreting it:

  • root metadata.json identifies the requested session, platform, profile, Git revision, and capture mode;
  • app metadata may have been merged into root metadata, while raw app files can remain under app-data/;
  • root events.jsonl is the normalized cross-layer stream; check JSON validity, session IDs, sequence continuity, clock basis, and queue_dropped before sorting or filtering it;
  • incidents/marker-*-pre.jsonl and marker-*-post.jsonl preserve the marker windows when the UI marker was accepted;
  • incidents/marker-*-state.json captures the bounded performance, input, memory, and plugin context sampled by that one-click marker;
  • attachments/state-snapshot-*.json contains explicit in-app state snapshots and attachments/screenshot-*.png contains only user-requested screenshots;
  • diagnostic_self_check events report which app-side facilities were reachable, but do not prove that unrelated runtime paths were healthy;
  • platform/ contains raw host/platform evidence and collection errors or omissions;
  • summary.md is a generated lead, not source evidence. Re-check every material statement against the structured events and raw platform files.

An absent UI marker is not automatically a failed bundle. Check for a host marker with ui_marker_missing=true, then state which app-side boundary is unavailable. Treat a typed marker label, state snapshot, screenshot, and self-check as separate evidence with independent timestamps.

Preserve provenance

  1. Record the source path, byte size, modification time, and SHA-256 before extraction.
  2. Identify the format from magic and structure, not only the extension.
  3. List archive members before extracting. Flag encrypted entries, absolute paths, traversal components, links, devices, surprising compression ratios, and duplicate names.
  4. Extract into a new disposable directory. Never overwrite the source or extract over a working tree.

For ZIP-compatible packages and TAR archives, prefer:

bash
python3 scripts/safe_unpack.py ARTIFACT OUTPUT_DIR --manifest OUTPUT_DIR.manifest.json

The script rejects traversal, links, special files, excessive member counts, and expanded-size limits. For unsupported formats, list with the narrowest available format-aware tool before choosing an extractor with equivalent protections.

Build an inventory

Use rg --files first, then group files by role rather than dumping every path:

  • metadata and manifests;
  • structured events, markers, and incident windows;
  • explicit state snapshots, screenshots, self-checks, and in-app export artifacts;
  • platform logs, crash reports, traces, and thread dumps;
  • binaries, architectures, symbols, libraries, plugins, and signatures;
  • assets, scripts, configuration, databases, and caches;
  • missing, truncated, duplicated, or unexpectedly empty evidence.

Keep secrets out of output. Report the presence and location of credentials, tokens, provisioning data, or personal content without printing their values.

Show full SKILL.md (301 more words)Show less

Route the investigation

  • Diagnostic bundle: validate metadata, session identity, sequence continuity, clock basis, queue drops, marker pairing, and pre/post windows before interpreting symptoms.
  • Android package or evidence: inspect manifest, ABI libraries, resources/assets, mapping or symbols, PID-scoped logcat, crash buffers, ANR/thread evidence, and device/build identity.
  • Apple package or evidence: inspect Info.plist, architectures, frameworks, entitlements, dSYM/UUID matches, crash logs, device/build identity, and app Documents evidence.
  • Web package or evidence: inspect build metadata, source maps, browser console/network evidence, workers, storage, and deployment headers.
  • Generic resource or game archive: inspect indexes, nested containers, encodings, scripts, plugin boundaries, and ownership/lifetime transitions.

Read only the relevant variant. Do not infer runtime behavior solely from package layout.

Establish the evidence chain

  1. Translate the reported symptom or typed marker label into one or more falsifiable boundaries.
  2. Anchor the timeline on explicit UI/host markers, snapshot timestamps, crash timestamps, sequence numbers, or monotonic clocks. State when clocks cannot be aligned.
  3. Find the deepest confirmed successful boundary and the first missing, failed, or contradictory boundary.
  4. Compare both sides of asynchronous or ownership transitions: queued/completed, created/destroyed, written/flushed, encoded/decoded, loaded/presented.
  5. Separate facts, inferences, and unknowns. Temporal proximity is not causation.
  6. Prefer a narrow next-evidence request over a broad request for every log.

For performance evidence, distinguish total duration from self-time and note whether tracing or logging could perturb timing. For rendering or missing UI, separate creation, enqueue, execution, upload, presentation, and input hit-testing.

Report findings

Return a compact investigation report containing:

  1. artifact identity and extraction integrity;
  2. relevant inventory and exact evidence locations;
  3. confirmed timeline and boundaries;
  4. strongest supported finding;
  5. competing explanations that remain possible;
  6. missing evidence and the smallest useful next step.

Do not claim a root cause when the artifact only establishes correlation or the failure lies beyond the captured boundary.

© AetherKiri, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/unpack-investigate-artifacts of AetherKiri/Aether.

  • SKILL.md
  • agents/openai.yaml
  • scripts/safe_unpack.py

Open the folder on GitHubat commit d4e017a

Compare with similar skills

Unpack Investigate Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unpack Investigate Artifacts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unpack Investigate Artifacts this skillAetherKiri/Aether154—~1.6kAutomated safety check: PassGPL-3.0
Audit Skillssickn33/agentic-awesome-skills47k2 repos~1.6kAutomated safety check: WarnMIT
macOS Reversezhaoxuya520/reverse-skill41k2 repos~366Automated safety check: PassMIT
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Conducting Mobile App Penetration Testmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Offensive MobileSnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Audit Skills

    sickn33/agentic-awesome-skills

    Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~1.6k tokens
    SecurityAuto-check: warnings
  • macOS Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

    41k GitHub starsUsed in 2 repos~366 tokens
    SecurityAuto-check passed
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conducting Mobile App Penetration Test

    mukul975/Anthropic-Cybersecurity-Skills

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Re Lldb

    dslsdzc/rev-skills

    lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills.

    135 GitHub stars~1.3k tokensUpdated 6 days ago
    SecurityAuto-check: notes

More from AetherKiri/Aether

  • Prepare, validate, push, open, monitor, and merge paired pull requests across the public AetherKiri repository and private AetherInternal package without publishing private source or unrelated…

    154 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Diagnose, implement, validate, commit, and document end-to-end compatibility fixes for KiriKiri games running in AetherKiri.

    154 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Unpack Investigate Artifacts

What does Unpack Investigate Artifacts do?

Safely unpack and investigate existing archives through evidence-first static analysis. Unpack Investigate Artifacts is an agent skill from AetherKiri/Aether. Safely unpack and investigate existing archives through evidence-first static analysis.

When should I use Unpack Investigate Artifacts?

Unpack Investigate Artifacts fits situations like: Codex is given a diagnostic ZIP; directory produced by a collection tool such as AetherKiri tools/diagnose.py; needs to validate integrity; align events and markers.

How do I install Unpack Investigate Artifacts in Claude Code?

Run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a claude-code`. Or copy the skill folder (.agents/skills/unpack-investigate-artifacts in AetherKiri/Aether) into .claude/skills/unpack-investigate-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install Unpack Investigate Artifacts in Codex?

Run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a codex`. Or copy the skill folder (.agents/skills/unpack-investigate-artifacts in AetherKiri/Aether) into .agents/skills/unpack-investigate-artifacts in your project. Codex loads it when a task matches its description.

Can I use Unpack Investigate Artifacts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AetherKiri/Aether --skill unpack-investigate-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unpack-investigate-artifacts, .gemini/skills/unpack-investigate-artifacts, .github/skills/unpack-investigate-artifacts and .opencode/skills/unpack-investigate-artifacts in your project.

What does Unpack Investigate Artifacts need to run?

Going by SKILL.md and its folder, Unpack Investigate Artifacts needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and rg). Our summary lists: Python 3.

Does Unpack Investigate Artifacts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Unpack Investigate Artifacts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Unpack Investigate Artifacts use?

Unpack Investigate Artifacts is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unpack Investigate Artifacts use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Unpack Investigate Artifacts?

Skills that share tags, products or a category with Unpack Investigate Artifacts: Audit Skills (sickn33/agentic-awesome-skills, 47k stars), macOS Reverse (zhaoxuya520/reverse-skill, 41k stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Conducting Mobile App Penetration Test (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unpack Investigate Artifacts?

AetherKiri (a GitHub organization) maintains it in AetherKiri/Aether, which has 154 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.

Source: AetherKiri/Aether on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.