Agent skill

Yara Sigs

by dariushoule in dariushoule/x64dbg-skills

Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more

MITAuto-check: notes

Install Yara Sigs

skills CLI
$ npx skills add dariushoule/x64dbg-skills --skill yara-sigs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dariushoule/x64dbg-skills yara-sigs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/yara-sigs .claude/skills/yara-sigs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
yara-sigs
GitHub stars
209
Token cost
~1.1k tokens
SKILL.md length
484 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more

  • Works in 6 steps: Check prerequisites → Ensure the YARA signature database is… → Determine what to scan for → …
  • Runs Python scripts from its folder; calls git, pip and python; reaches github.com

What it does

Yara Sigs is an agent skill from dariushoule/x64dbg-skills. Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `yara_scan.py`).

The repository describes itself as: Claude Code plugin providing skills for x64dbg debugger automation. The licence is MIT.

Example prompts

  • “/yara-sigs”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): mcp__x64dbg__get_debugger_status, mcp__x64dbg__pause, mcp__x64dbg__disconnect, mcp__x64dbg__connect_to_session, Bash, Read, AskUserQuestion, Skill

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check prerequisites
  2. Ensure the YARA signature database is available
  3. Determine what to scan for
  4. Obtain a snapshot to scan
  5. Run the YARA scan
  6. Report results

What it can do on your machine

Read from SKILL.md and the folder at commit 0409f53. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • mcp__x64dbg__get_debugger_status
    • mcp__x64dbg__pause
    • mcp__x64dbg__disconnect
    • mcp__x64dbg__connect_to_session
    • Bash
    • Read
    • AskUserQuestion
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Yara Sigs loads about 1.1k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 484 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: mcp__x64dbg__get_debugger_status, mcp__x64dbg__pause, mcp__x64dbg__disconnect, mcp__x64dbg__connect_

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dariushoule/x64dbg-skills at commit 0409f53, republished under its MIT licence (© dariushoule). 484 words, ~1,085 tokens.

Download SKILL.mdSave it as .claude/skills/yara-sigs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
yara-sigs
description
Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more
allowed-tools
mcp__x64dbg__get_debugger_status, mcp__x64dbg__pause, mcp__x64dbg__disconnect, mcp__x64dbg__connect_to_session, Bash, Read, AskUserQuestion, Skill

yara-sigs

Scan debuggee memory (via a state snapshot) against a large YARA signature database to identify packers, crypto constants, anti-debug tricks, malware families, and more.

Instructions

Follow these steps exactly:

1. Check prerequisites

Run pip show yara-python via Bash. If not installed, tell the user to run pip install yara-python and stop. Run git --version via Bash. If not installed, tell the user to install Git and stop.

2. Ensure the YARA signature database is available

Check if the directory ${CLAUDE_PLUGIN_ROOT}\yarasigs exists (use dir). If it does not exist, clone it:

git clone --recurse-submodules https://github.com/x64dbg/yarasigs "${CLAUDE_PLUGIN_ROOT}\yarasigs"

If the directory exists but looks incomplete (missing Yara-Rules or citizenlab subdirectories), update submodules:

git -C "${CLAUDE_PLUGIN_ROOT}\yarasigs" submodule update --init --recursive
3. Determine what to scan for

The YARA database contains many rule categories. If the user specified what they want to scan for in their invocation, use that. Otherwise, ask the user what they want to scan for using AskUserQuestion with these options:

  • Packers & compilers — Detect packers (UPX, Themida, etc.) and compiler signatures
  • Crypto constants — Find cryptographic algorithm constants (AES S-boxes, RSA, MD5, etc.)
  • Anti-debug / anti-VM — Detect anti-debugging and anti-virtualization techniques
  • All signatures — Scan with every available rule (slower, more noise)

Map the selection to rule category paths:

SelectionRule paths (relative to yarasigs/)
Packers & compilerspacker.yara, packer_compiler_signatures.yara, Yara-Rules/packers/
Crypto constantscrypto_signatures.yara, Yara-Rules/crypto/
Anti-debug / anti-VMYara-Rules/antidebug_antivm/
All signaturesAll .yar and .yara files recursively
4. Obtain a snapshot to scan

Check if a recent snapshot exists in ${CLAUDE_PLUGIN_ROOT}\snapshots (use dir).

  • If snapshots exist, ask the user whether to use an existing snapshot or take a fresh one.
  • If no snapshots exist, tell the user you need to take a snapshot first.

To take a fresh snapshot, invoke the state-snapshot skill via Skill("state-snapshot"). After it completes, note the snapshot directory path.

Show full SKILL.md (199 more words)Show less
5. Run the YARA scan

Execute the scan script:

python "${CLAUDE_PLUGIN_ROOT}\skills\yara-sigs\yara_scan.py" --snapshot-dir <snapshot_path> --yarasigs-dir "${CLAUDE_PLUGIN_ROOT}\yarasigs" --categories <category> [--module-filter <module_name>]

Where <category> is one of: packers, crypto, antidebug, or all.

Module filtering: If the user asks to focus on a specific module (e.g. the main executable), pass --module-filter <name> where <name> is a substring of the module name as shown in the memory map (e.g. secret_encryptor). This merges all of the module's sections into a single buffer before scanning, which is critical for YARA rules whose patterns span multiple PE sections (e.g. MD5 init constants in .text + T-table in .rdata). Always prefer using --module-filter when scanning a specific module rather than relying on per-region scanning.

The script writes results to <snapshot_path>/yara_results.json and prints a summary to stdout.

6. Report results

Read <snapshot_path>/yara_results.json if it exists and the stdout summary is not sufficient.

Present findings organized by:

  • Match summary — How many rules matched across how many memory regions
  • Matches by rule — Each matched rule name, its description/metadata, and which memory regions it hit (with base addresses and region info from memory_map.json)
  • Notable findings — Call out anything especially interesting (known packers, specific crypto algorithms, anti-debug patterns)

If no matches were found, tell the user and suggest trying a broader category (e.g., "all").

© dariushoule, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/yara-sigs of dariushoule/x64dbg-skills.

  • SKILL.md
  • yara_scan.py

Open the folder on GitHubat commit 0409f53

Compare with similar skills

Yara Sigs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Yara Sigs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Yara Sigs this skilldariushoule/x64dbg-skills209—~1.1kAutomated safety check: NotesMIT
Detecting Network Scanning With Ids Signaturesmukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.0
Scanwshobson/agents40k—~2.2kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.5kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.3kAutomated safety check: PassMIT
Vulnerability Scanningsickn33/agentic-awesome-skills47k1 repos~2.8kAutomated safety check: PassMIT

Similar skills

  • Detecting Network Scanning With Ids Signatures

    mukul975/Anthropic-Cybersecurity-Skills

    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning…

    34k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Scan

    wshobson/agents

    Scans the codebase to generate project-doc.md and AGENTS.md.

    40k GitHub stars~2.2k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Repo Scan

    affaan-m/ECC

    固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。

    276k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Repo Scan

    affaan-m/ECC

    用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。

    276k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Vulnerability Scanning

    sickn33/agentic-awesome-skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    47k GitHub starsUsed in 1 repo~2.8k tokens
    SecurityAuto-check passed
  • Repo Scan

    affaan-m/ECC

    Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit.

    276k GitHub starsUsed in 1 repo~1.8k tokens
    DevelopmentAuto-check passed

More from dariushoule/x64dbg-skills

  • Decompile

    dariushoule/x64dbg-skills

    Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills.

    209 GitHub stars~626 tokensUpdated 7 mo ago
    Auto-check: notes
  • State Diff

    dariushoule/x64dbg-skills

    Compare two state snapshots to identify register and memory changes between two points in time

    209 GitHub stars~594 tokensUpdated 7 mo ago
    Auto-check: notes
  • State Snapshot

    dariushoule/x64dbg-skills

    Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis

    209 GitHub stars~526 tokensUpdated 7 mo ago
    Auto-check: notes
  • Tracealyzer

    dariushoule/x64dbg-skills

    Trace execution (into or over calls) for N steps or until a condition, then analyze the recorded instruction log

    209 GitHub stars~1k tokensUpdated 7 mo ago
    Auto-check: notes
  • Vuln Hunter

    dariushoule/x64dbg-skills

    Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

    209 GitHub stars~3.9k tokensUpdated 7 mo ago
    Auto-check: notes
  • Find Oep

    dariushoule/x64dbg-skills

    Smart trace-based OEP finder for packed/protected PE executables.

    209 GitHub stars~2.5k tokensUpdated 7 mo ago
    Auto-check: notes

Questions about Yara Sigs

What does Yara Sigs do?

Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more. Yara Sigs is an agent skill from dariushoule/x64dbg-skills.

How do I install Yara Sigs in Claude Code?

Run `npx skills add dariushoule/x64dbg-skills --skill yara-sigs -a claude-code`. Or copy the skill folder (skills/yara-sigs in dariushoule/x64dbg-skills) into .claude/skills/yara-sigs in your project. Claude Code loads it when a task matches its description.

How do I install Yara Sigs in Codex?

Run `npx skills add dariushoule/x64dbg-skills --skill yara-sigs -a codex`. Or copy the skill folder (skills/yara-sigs in dariushoule/x64dbg-skills) into .agents/skills/yara-sigs in your project. Codex loads it when a task matches its description.

Can I use Yara Sigs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dariushoule/x64dbg-skills --skill yara-sigs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yara-sigs, .gemini/skills/yara-sigs, .github/skills/yara-sigs and .opencode/skills/yara-sigs in your project.

What does Yara Sigs need to run?

Going by SKILL.md and its folder, Yara Sigs needs Python for the scripts in its folder and the command-line tools its instructions call (git, pip and python). Our summary lists: Python 3. Its frontmatter pre-approves these tools: mcp__x64dbg__get_debugger_status, mcp__x64dbg__pause, mcp__x64dbg__disconnect, mcp__x64dbg__connect_to_session, Bash, Read, AskUserQuestion, Skill.

Does Yara Sigs access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Yara Sigs safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Yara Sigs use?

Yara Sigs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Yara Sigs use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Yara Sigs?

Skills that share tags, products or a category with Yara Sigs: Detecting Network Scanning With Ids Signatures (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Scan (wshobson/agents, 40k stars), Repo Scan (affaan-m/ECC, 276k stars) and Repo Scan (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Yara Sigs?

dariushoule (a GitHub user) maintains it in dariushoule/x64dbg-skills, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on March 13, 2026.

Source: dariushoule/x64dbg-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.