Agent skill

Decompile

by dariushoule in dariushoule/x64dbg-skills

Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills.

MITAuto-check: notes

Install Decompile

skills CLI
$ npx skills add dariushoule/x64dbg-skills --skill decompile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dariushoule/x64dbg-skills decompile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/decompile .claude/skills/decompile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
decompile
GitHub stars
209
Token cost
~626 tokens
SKILL.md length
318 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills.

  • Works in 6 steps: Check prerequisites → Verify debugger connection → Determine target function address → …
  • Runs Python scripts from its folder; calls pip and python

What it does

Decompile is an agent skill from dariushoule/x64dbg-skills. Decompile a function to C-like pseudocode using angr

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `decompile.py`).

It works with Model Context Protocol. The repository describes itself as: Claude Code plugin providing skills for x64dbg debugger automation. The licence is MIT.

Example prompts

  • “/decompile”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): mcp__x64dbg__get_debugger_status, mcp__x64dbg__get_register, mcp__x64dbg__eval_expression, mcp__x64dbg__get_symbol, Bash, Read

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check prerequisites
  2. Verify debugger connection
  3. Determine target function address
  4. Resolve module path and compute RVA
  5. Run the decompile script
  6. Present results

What it can do on your machine

Read from SKILL.md and the folder at commit 0409f53. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • mcp__x64dbg__get_debugger_status
    • mcp__x64dbg__get_register
    • mcp__x64dbg__eval_expression
    • mcp__x64dbg__get_symbol
    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Decompile loads about 626 tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 318 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~626

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: mcp__x64dbg__get_debugger_status, mcp__x64dbg__get_register, mcp__x64dbg__eval_expression, mcp__x64d

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dariushoule/x64dbg-skills at commit 0409f53, republished under its MIT licence (© dariushoule). 318 words, ~626 tokens.

Download SKILL.mdSave it as .claude/skills/decompile/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
decompile
description
Decompile a function to C-like pseudocode using angr
allowed-tools
mcp__x64dbg__get_debugger_status, mcp__x64dbg__get_register, mcp__x64dbg__eval_expression, mcp__x64dbg__get_symbol, Bash, Read

decompile

Decompile a function from the debugged binary into C-like pseudocode using angr.

If no address is specified, decompiles the function containing the current instruction pointer. Accepts an address or symbol name as an argument.

Instructions

Follow these steps exactly:

1. Check prerequisites

Run pip show angr via Bash. If angr is not installed, tell the user:

angr is not installed. Install it with pip install angr (requires Python >= 3.10). Note: angr is a large package (~500MB+).

Then stop.

2. Verify debugger connection

Call mcp__x64dbg__get_debugger_status to confirm the debugger is connected and paused. If not debugging, tell the user and stop.

3. Determine target function address

If the user provided an address or symbol as an argument:

  • If it looks like a hex address, use it directly
  • If it looks like a symbol name, resolve it via mcp__x64dbg__eval_expression

If no argument was provided:

  • Get the current instruction pointer via mcp__x64dbg__get_register (register rip for 64-bit, eip for 32-bit)
  • Use the current RIP/EIP value as the target address

Call this resolved value target_addr.

4. Resolve module path and compute RVA

Use mcp__x64dbg__eval_expression to evaluate:

  • mod.path(target_addr) — to get the on-disk path of the module containing the address
  • mod.base(target_addr) — to get the module's base address

Compute the RVA: target_addr - module_base

If mod.path fails, the address may not belong to a loaded module. Tell the user and stop.

5. Run the decompile script

Execute:

python "${CLAUDE_PLUGIN_ROOT}\skills\decompile\decompile.py" --binary "<module_path>" --address <rva_hex>

Where:

  • <module_path> is the on-disk path from step 4
  • <rva_hex> is the RVA in hex (e.g. 0x1060)

The script may take 10-30 seconds for large binaries (CFG generation is the bottleneck). Use a timeout of at least 120 seconds.

6. Present results

The script outputs decompiled C pseudocode to stdout and status messages to stderr.

Present the decompiled code to the user in a ```c code block. If the script failed, relay the error message from stderr (e.g., function not found, decompilation failed) and suggest nearby functions if listed.

© dariushoule, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/decompile of dariushoule/x64dbg-skills.

  • SKILL.md
  • decompile.py

Open the folder on GitHubat commit 0409f53

Compare with similar skills

Decompile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Decompile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Decompile this skilldariushoule/x64dbg-skills209—~626Automated safety check: NotesMIT
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.4k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.4k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from dariushoule/x64dbg-skills

  • State Diff

    dariushoule/x64dbg-skills

    Compare two state snapshots to identify register and memory changes between two points in time

    209 GitHub stars~594 tokensUpdated 6 mo ago
    Auto-check: notes
  • State Snapshot

    dariushoule/x64dbg-skills

    Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis

    209 GitHub stars~526 tokensUpdated 6 mo ago
    Auto-check: notes
  • Tracealyzer

    dariushoule/x64dbg-skills

    Trace execution (into or over calls) for N steps or until a condition, then analyze the recorded instruction log

    209 GitHub stars~1k tokensUpdated 6 mo ago
    Auto-check: notes
  • Vuln Hunter

    dariushoule/x64dbg-skills

    Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

    209 GitHub stars~3.9k tokensUpdated 6 mo ago
    Auto-check: notes
  • Yara Sigs

    dariushoule/x64dbg-skills

    Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more

    209 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check: notes
  • Find Oep

    dariushoule/x64dbg-skills

    Smart trace-based OEP finder for packed/protected PE executables.

    209 GitHub stars~2.5k tokensUpdated 6 mo ago
    Auto-check: notes

Questions about Decompile

What does Decompile do?

Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills. Decompile is an agent skill from dariushoule/x64dbg-skills.

How do I install Decompile in Claude Code?

Run `npx skills add dariushoule/x64dbg-skills --skill decompile -a claude-code`. Or copy the skill folder (skills/decompile in dariushoule/x64dbg-skills) into .claude/skills/decompile in your project. Claude Code loads it when a task matches its description.

How do I install Decompile in Codex?

Run `npx skills add dariushoule/x64dbg-skills --skill decompile -a codex`. Or copy the skill folder (skills/decompile in dariushoule/x64dbg-skills) into .agents/skills/decompile in your project. Codex loads it when a task matches its description.

Can I use Decompile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dariushoule/x64dbg-skills --skill decompile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/decompile, .gemini/skills/decompile, .github/skills/decompile and .opencode/skills/decompile in your project.

What does Decompile need to run?

Going by SKILL.md and its folder, Decompile needs Python for the scripts in its folder and the command-line tools its instructions call (pip and python). Our summary lists: Python 3. Its frontmatter pre-approves these tools: mcp__x64dbg__get_debugger_status, mcp__x64dbg__get_register, mcp__x64dbg__eval_expression, mcp__x64dbg__get_symbol, Bash, Read.

Does Decompile access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Decompile safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Decompile use?

Decompile is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Decompile use?

About 626 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Decompile?

Skills that share tags, products or a category with Decompile: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Decompile?

dariushoule (a GitHub user) maintains it in dariushoule/x64dbg-skills, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on March 13, 2026.

Source: dariushoule/x64dbg-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.