MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
Smart trace-based OEP finder for packed/protected PE executables.
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dariushoule/x64dbg-skills find-oep --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/find-oep .claude/skills/find-oep && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .claude/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oepType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dariushoule/x64dbg-skills find-oep --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/find-oep .agents/skills/find-oep && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .agents/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dariushoule/x64dbg-skills find-oep --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/find-oep .cursor/skills/find-oep && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .cursor/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dariushoule/x64dbg-skills.git --path skills/find-oep--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dariushoule/x64dbg-skills find-oep --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/find-oep .gemini/skills/find-oep && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .gemini/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dariushoule/x64dbg-skills find-oepInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/find-oep .github/skills/find-oep && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .github/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dariushoule/x64dbg-skills find-oep --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/find-oep .opencode/skills/find-oep && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "find-oep" agent skill from https://github.com/dariushoule/x64dbg-skills/tree/main/skills/find-oep into .opencode/skills/find-oep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-oep", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
find-oepSmart trace-based OEP finder for packed/protected PE executables.
Find Oep is an agent skill from dariushoule/x64dbg-skills. Smart trace-based OEP finder for packed/protected PE executables. Traces through packer stubs using intelligent stepping, anti-debug evasion, and heuristic OEP detection, then captures a state snapshot at the original entry point.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with Model Context Protocol. The repository describes itself as: Claude Code plugin providing skills for x64dbg debugger automation. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0409f53. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
mcp__x64dbg__list_sessionsmcp__x64dbg__start_sessionmcp__x64dbg__connect_to_sessionmcp__x64dbg__get_debugger_statusmcp__x64dbg__disconnectmcp__x64dbg__allocate_memorymcp__x64dbg__write_memorymcp__x64dbg__read_memorymcp__x64dbg__set_registermcp__x64dbg__get_register…and 26 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Find Oep loads about 2.5k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 1,164 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbgAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dariushoule/x64dbg-skills at commit 0409f53, republished under its MIT licence (© dariushoule). 1,164 words, ~2,499 tokens.
.claude/skills/find-oep/SKILL.md (or your agent's skills folder).Smart trace-based OEP finder for packed/protected PE executables. Walks through unpacking stages using intelligent stepping, anti-debug evasion, and heuristic OEP detection. Once the OEP is found, captures a state snapshot for downstream use (PE reconstruction, analysis, etc.).
Ask the user (via AskUserQuestion) for any information not already provided:
Determine the CIP register name: rip for 64-bit, eip for 32-bit.
Determine the stack pointer register: rsp for 64-bit, esp for 32-bit.
Determine the debugger variant: x64dbg.exe for 64-bit, x32dbg.exe for 32-bit.
Use mcp__x64dbg__start_session with:
executable_path: the packed PE pathx64dbg_path: the appropriate debugger binaryAlways start a new session for a clean environment. Wait for the debugger to settle — call mcp__x64dbg__get_debugger_status and confirm the debuggee is paused at the entry point. If running, call mcp__x64dbg__pause.
Record the session PID and x64dbg path for later reconnection.
Gather information about the packed binary to inform the unpacking strategy:
mcp__x64dbg__get_all_registers to record the initial register state (especially the stack pointer — packers often restore it before jumping to OEP).mcp__x64dbg__get_memory_map to identify the module's sections, their protections, and any suspicious characteristics (e.g., sections with write+execute, sections with zero raw size but large virtual size, non-standard section names).mcp__x64dbg__disassemble to identify the packer stub pattern./yara-sigs via Skill("yara-sigs") to identify the packer and obvious crypto/anti-debug signatures.Summarize findings to the user:
This is the main unpacking loop. The goal is to trace through the packer stub and identify when execution transfers to the original, unpacked code.
The OEP is likely reached when several of these conditions align:
| Heuristic | Description |
|---|---|
| Section transition | CIP moves from a packer section (e.g., .rsrc, .aspack, last section) into the original code section (usually .text or the first section) |
| Stack restoration | ESP/RSP returns to (or near) its initial value from step 3 |
| Common OEP patterns | Disassembly shows typical compiler entry sequences: push ebp; mov ebp, esp, sub rsp, N, call __security_init_cookie, MSVC/GCC/Delphi/Borland CRT init patterns |
| Large code region | After writes settle, a large contiguous region of valid-looking code exists in the original code section |
| IAT populated | The import table region contains valid pointers to API functions |
Start at the packed entry point. Disassemble the current location.
Identify the current phase:
go. If you cannot determine the loop exit, use mcp__x64dbg__trace_over with a break_condition that detects leaving the loop (e.g., a CIP range check).GetProcAddress, LoadLibrary*, hash-based API resolution. Step over these — they are building the IAT.jmp or push+ret that lands in a different section — potential OEP. Verify with the heuristics above.When in a repetitive region (same addresses appearing repeatedly):
mcp__x64dbg__trace_over with a break_condition like cip < <loop_start> || cip > <loop_end> to escape the loop efficiently.mcp__x64dbg__set_breakpoint with an appropriate condition.At each significant transition, disassemble 20–30 instructions at the new location, check the memory section it belongs to, and evaluate the OEP heuristics.
Label and comment key addresses as you go: decode loop entries, API resolution routines, anti-debug checks, stage transitions, and the final OEP. Use mcp__x64dbg__set_comment and mcp__x64dbg__set_label.
Packers frequently employ anti-debug techniques. When you encounter them, work around them to simulate non-debugged execution:
| Technique | Detection | Evasion |
|---|---|---|
| IsDebuggerPresent | Call to kernel32.IsDebuggerPresent or direct PEB.BeingDebugged read | Step to the call, then set eax/rax to 0 after it returns (mcp__x64dbg__set_register) |
| NtQueryInformationProcess (DebugPort) | Call with class 0x7 | Step over the call, then zero the output buffer (mcp__x64dbg__write_memory) |
| PEB.BeingDebugged | Direct memory read of fs:[30]+2 (x86) or gs:[60]+2 (x64) | Write 0x00 to the BeingDebugged byte in the PEB (mcp__x64dbg__write_memory). Find PEB address via mcp__x64dbg__eval_expression with peb(). |
| PEB.NtGlobalFlag | Read of PEB+0x68 (x86) or PEB+0xBC (x64) | Write 0x00000000 to clear debug flags |
| Heap flags | PEB.ProcessHeap flags check | Patch the heap flags to remove debug indicators |
| Timing checks | rdtsc, GetTickCount, QueryPerformanceCounter | Step over the first call, note the result, step over the second, then patch the result to show minimal elapsed time |
| Hardware breakpoint detection | GetThreadContext / direct DR register reads | Clear debug registers before the check or patch the return values |
| INT 2D / INT 3 tricks | Exception-based anti-debug | Set the appropriate exception handler breakpoint and ensure execution continues as if no debugger is present |
| Self-checksum | CRC/hash of code regions (detects software breakpoints) | Use hardware breakpoints instead of software breakpoints in checksummed regions |
This list is not exhaustive. Always analyze the disassembly to understand the anti-debug technique being used and apply the appropriate evasion.
When you detect anti-debug behavior:
Proactive anti-debug setup: At the start of unpacking, consider preemptively patching common PEB fields:
0x00 to PEB.BeingDebugged0x00000000 to PEB.NtGlobalFlag
This can be done via mcp__x64dbg__eval_expression to find peb(), then mcp__x64dbg__write_memory.When you believe you've reached the OEP:
.text or first section).mcp__x64dbg__get_symbol to verify.Ask the user via AskUserQuestion: "OEP found at <address>. Take a state snapshot?"
If the user says no or wants to adjust, continue stepping as directed.
Invoke /state-snapshot via Skill("state-snapshot") to dump the full debuggee memory state at the OEP. Note the snapshot output directory.
Report the final results to the user:
Always call mcp__x64dbg__refresh_gui as the final step.
© dariushoule, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/find-oep of dariushoule/x64dbg-skills.
Open the folder on GitHubat commit 0409f53
Find Oep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Find Oep this skilldariushoule/x64dbg-skills | 209 | — | ~2.5k | Automated safety check: Notes | MIT | |
| MCP Server Builderanthropics/skills | 180k | 63 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 4 repos | ~1.2k | Automated safety check: Pass | MIT | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills | 8.5k | 6 repos | ~3.2k | Automated safety check: Notes | Apache-2.0 |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
google-labs-code/stitch-skills
Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.
coollabsio/coolify
A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.
dariushoule/x64dbg-skills
Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills.
dariushoule/x64dbg-skills
Compare two state snapshots to identify register and memory changes between two points in time
dariushoule/x64dbg-skills
Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis
dariushoule/x64dbg-skills
Trace execution (into or over calls) for N steps or until a condition, then analyze the recorded instruction log
dariushoule/x64dbg-skills
Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.
dariushoule/x64dbg-skills
Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more
Works with
Smart trace-based OEP finder for packed/protected PE executables. Find Oep is an agent skill from dariushoule/x64dbg-skills. Smart trace-based OEP finder for packed/protected PE executables.
Run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a claude-code`. Or copy the skill folder (skills/find-oep in dariushoule/x64dbg-skills) into .claude/skills/find-oep in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a codex`. Or copy the skill folder (skills/find-oep in dariushoule/x64dbg-skills) into .agents/skills/find-oep in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-oep, .gemini/skills/find-oep, .github/skills/find-oep and .opencode/skills/find-oep in your project.
SKILL.md names no scripts, command-line tools or credentials: Find Oep is instructions for the agent only. Its frontmatter pre-approves these tools: mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbg__get_debugger_status, mcp__x64dbg__disconnect, mcp__x64dbg__allocate_memory, mcp__x64dbg__write_memory, mcp__x64dbg__read_memory, mcp__x64dbg__set_register, mcp__x64dbg__get_register, mcp__x64dbg__get_all_registers, mcp__x64dbg__disassemble, mcp__x64dbg__assemble, mcp__x64dbg__set_breakpoint, mcp__x64dbg__clear_breakpoint, mcp__x64dbg__list_breakpoints, mcp__x64dbg__step_over, mcp__x64dbg__step_into, mcp__x64dbg__go, mcp__x64dbg__pause, mcp__x64dbg__run_to_return, mcp__x64dbg__set_comment, mcp__x64dbg__set_label, mcp__x64dbg__get_symbol, mcp__x64dbg__eval_expression, mcp__x64dbg__execute_command, mcp__x64dbg__refresh_gui, mcp__x64dbg__get_memory_map, mcp__x64dbg__trace_over, mcp__x64dbg__trace_into, mcp__x64dbg__wait_for_event, AskUserQuestion, Bash, Read, Write, Skill.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Find Oep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Find Oep: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dariushoule (a GitHub user) maintains it in dariushoule/x64dbg-skills, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on March 13, 2026.
Source: dariushoule/x64dbg-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.