Agent skill

Nuitka Nbc Rebuilder

by DimaReverse in DimaReverse/nuitka-static-unpacker

Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.

MITAuto-check passedSecurity

Install Nuitka Nbc Rebuilder

skills CLI
$ npx skills add DimaReverse/nuitka-static-unpacker --skill nuitka-nbc-rebuilder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DimaReverse/nuitka-static-unpacker nuitka-nbc-rebuilder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DimaReverse/nuitka-static-unpacker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/nuitka-nbc-rebuilder-skill .claude/skills/nuitka-nbc-rebuilder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nuitka-nbc-rebuilder
GitHub stars
132
Token cost
~2k tokens
SKILL.md length
941 words
Files
5
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.

  • Works in 7 steps: Do not invent logic. Every emitted… → Preserve every literal exactly as shown… → Preserve imported names exactly when… → …
  • The user pastes
  • SKILL.md covers Output Contract, Non-Negotiable Rules, NBC/2 Sections and Translation Workflow, plus 6 more sections
  • Calls python

What it does

Nuitka Nbc Rebuilder is an agent skill from DimaReverse/nuitka-static-unpacker. Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py. Use when the user pastes or references a .nbc file, an AIREADYNBC bundle, sections such as @MOD, @CONSTS, @RAWCHUNK, @OPS, @ASM, @FORENSICS, modulecode, modconsts[N], or asks to rebuild Python source from a Nuitka C-compiled module. The goal is evidence-backed reconstruction, not guaranteed perfect 1:1 recovery; uncertain spans must be marked.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `EXAMPLES.md`, `INSTALL.md` and `OPCODES.md`).

It sits in Security, covering Reverse engineering and malware. It works with Python. The repository describes itself as: Nuitka Static Unpacker — a static-first research tool for analyzing Nuitka-compiled binaries (constants/module extraction, .pyc recovery, reports). The licence is MIT.

When your agent uses it

  • The user pastes
  • References a .nbc file
  • An AIREADYNBC bundle
  • Sections such as @MOD

Example prompts

  • “/nuitka-nbc-rebuilder”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Do not invent logic. Every emitted statement must be supported by @OPS,
  2. Preserve every literal exactly as shown in @CONSTS: strings, URLs,
  3. Preserve imported names exactly when they are evidenced. Do not add imports
  4. Mark uncertain code with # UNCERTAIN: .
  5. Prefer a short uncertain body over a plausible but unsupported body.
  6. Do not add comments, docstrings, logging, exception handling, async, crypto
  7. Do not collapse an evidenced sequence into .... If @OPS and @ASM

What it can do on your machine

Read from SKILL.md and the folder at commit 433eac3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nuitka Nbc Rebuilder loads about 2k tokens when it runs. Until then it costs about 128 tokens; SKILL.md has 941 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DimaReverse/nuitka-static-unpacker at commit 433eac3, republished under its MIT licence (© DimaReverse). 941 words, ~2,018 tokens.

Download SKILL.mdSave it as .claude/skills/nuitka-nbc-rebuilder/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
nuitka-nbc-rebuilder
description
Maximum-fidelity Python source reconstruction from Nuitka `.nbc` / `NBC/2` files produced by `nuitka_decompiler.py`. Use when the user pastes or references a `.nbc` file, an `AI_READY_NBC` bundle, sections such as `@MOD`, `@CONSTS`, `@RAW_CHUNK`, `@OPS`, `@ASM`, `@FORENSICS`, `module_code_*`, `mod_consts[N]`, or asks to rebuild Python source from a Nuitka C-compiled module. The goal is evidence-backed reconstruction, not guaranteed perfect 1:1 recovery; uncertain spans must be marked.

Nuitka NBC -> Python Source

Rebuild Python source from a Nuitka .nbc file with maximum fidelity to the original module. Treat the .nbc as forensic evidence, not as a normal Python bytecode listing. Nuitka may have removed comments, formatting, some local names, and may have inlined or optimized logic; never promise exact 1:1 output when the evidence is incomplete.

If the user needs to generate inputs first, prefer:

bash
python nuitka_decompiler.py --source target.exe --output OUT --only app,app.* --nbc-only

Output Contract

Emit one Python code block per module:

python
# MODULE: <module.dotted.name>
# CONFIDENCE: <percent>% evidence-backed reconstruction
# UNCERTAIN SPANS: <count>

<imports>
<globals>
<classes>
<functions>

No prose outside the code block unless the user explicitly asks for explanation. If a required .nbc section is missing, ask for the missing data instead of fabricating code.

Non-Negotiable Rules

  1. Do not invent logic. Every emitted statement must be supported by @OPS, @ASM, @CONSTS, @IMPORTS, @CODE_OBJECTS, or @FORENSICS.
  2. Preserve every literal exactly as shown in @CONSTS: strings, URLs, numbers, dict keys, format strings, escapes, and casing.
  3. Preserve imported names exactly when they are evidenced. Do not add imports for convenience.
  4. Mark uncertain code with # UNCERTAIN: <specific reason>.
  5. Prefer a short uncertain body over a plausible but unsupported body.
  6. Do not add comments, docstrings, logging, exception handling, async, crypto primitives, decorators, or helper functions unless the .nbc supports them.
  7. Do not collapse an evidenced sequence into .... If @OPS and @ASM show imports, attribute chains, calls, branches, or returns, reconstruct the smallest Python statement sequence that matches that evidence and mark only the missing operand or receiver as uncertain.

NBC/2 Sections

  • @NBC 2: format marker.
  • @MOD: module name.
  • @VER: CPython target version.
  • @ENTRY: native VA of the module entry function.
  • @MODULE_TABLE: loader-table metadata; func_ptr confirms the module entry.
  • @RAW_CHUNK: base64 of the original Nuitka constants chunk. Use it only to verify or re-parse evidence; do not decode it by hand unless necessary.
  • @CONSTS <count> mode=full_repr: authoritative mod_consts table.
  • @IMPORTS: analyzer-suggested import statements.
  • @FUNCS_DETECTED: inferred function signatures.
  • @CODE_OBJECTS: code-object metadata where Nuitka preserved it.
  • @BLOCKS: summary of disassembled native blocks.
  • @OPS <va> # <qualname>: virtual operations derived from native code.
  • @ASM <va>: source-relevant annotated native assembly. Low-signal native moves may be omitted by the emitter; use this to resolve ambiguous @OPS, arithmetic, comparisons, attribute names, and C-API calls.
  • @FORENSICS and @NO_OPS <qualname>: evidence for functions without a reachable @OPS body.
  • Bare @NO_OPS: the whole module lacks disassembly; emit only signatures and constants-backed globals with uncertainty markers.

Translation Workflow

  1. Parse @MOD, @VER, @ENTRY, @MODULE_TABLE, and @CONSTS.
  2. Build a literal map from every @CONSTS row: c[N] -> exact repr.
  3. Build function declarations from @FUNCS_DETECTED and @CODE_OBJECTS.
  4. Build a block map from every @OPS <va> and matching @ASM <va>.
  5. Map @OPS blocks to functions using the # qualname annotation first. If no annotation exists, use nearby string constants that look like qualnames. If still ambiguous, mark the body uncertain.
  6. Resolve C fn@0xVA by looking up the matching @OPS 0xVA block before deciding whether it is a helper call, nested function, or local method.
  7. Translate the @ENTRY block into imports, global assignments, class/function registration, and top-level calls only when the sequence is clear.
  8. Translate each function block. Use @ASM comments to confirm attribute names, C-API calls, call targets, and constants.
  9. Treat C helper_* as a known runtime-helper call with weaker semantics than C r#N; consult AI_READY_NBC/context/NUITKA_RUNTIME_HELPERS.txt when available before assigning Python meaning.
  10. For functions listed in @FUNCS_DETECTED but missing @OPS, inspect the matching @FORENSICS block. Emit logic only when adjacent constants or mentions plainly support it; otherwise emit ... with an uncertainty reason.
  11. Run the anti-hallucination checklist before final output.
Show full SKILL.md (357 more words)Show less

Virtual Ops

  • L c[N]: load mod_consts[N].
  • C r#N: call a ranked Nuitka runtime helper.
  • C helper_*: call a less common runtime helper.
  • C fn@0xVA: call another native block in this same module; resolve to @OPS 0xVA when present.
  • C module_code_<name>: call another module entry. Usually import/init logic.
  • C capi:<name>: call a Python C-API function.
  • J_EQ c[N] Lx / J_NE c[N] Lx: conditional branch against a constant.
  • J_EQ ? Lx: conditional branch with unresolved comparator.
  • J Lx: unconditional branch.
  • :Lx: label.
  • RET: return.

Runtime Helper Hints

Treat ranks as build-local hints, not universal truth. Use AI_READY_NBC/context/NUITKA_RUNTIME_HELPERS.txt when available.

Common rank meanings:

  • r#0: attribute lookup (obj.attr)
  • r#1: no-arg call (f())
  • r#2: one-arg call (f(a))
  • r#3: two-arg call (f(a, b))
  • r#4: three-arg call (f(a, b, c))
  • r#5: positional/variadic call
  • r#6 to r#8: globals or string-dict lookup/update
  • r#9 to r#13: imports or method calls
  • r#14 and above: function creation, class creation, globals update, or helper-specific operations depending on the build

C-API Hints

  • PyImport_ImportModule: import X
  • PyImport_ImportModuleLevel*: relative/from import logic
  • PyObject_GetAttrString: obj.name
  • PyObject_SetAttrString: obj.name = value
  • PyObject_Call*: obj(...)
  • PyObject_IsTrue: truthiness check
  • PyDict_GetItem, PyDict_SetItem, PyDict_DelItem: dict access/update
  • PyUnicode_GetLength, PyUnicode_Find, PyUnicode_Substring: string ops
  • PyErr_*: exception path evidence
  • PyGen_*, PyCoro_*: generator/coroutine evidence

Anti-Hallucination Checklist

Before emitting code, verify:

  • Every string literal appears verbatim in @CONSTS.
  • Every numeric literal above 10 appears in @CONSTS.
  • Every import is supported by @IMPORTS, @OPS, or @ASM.
  • Every call target is supported by @OPS, @ASM, or a known C-API pattern.
  • No exception handling appears without PyErr_* or branch evidence.
  • No crypto logic appears without visible crypto imports, attributes, constants, or C-API evidence.
  • No async/generator syntax appears without coroutine/generator evidence.

If a line fails, replace that line with # UNCERTAIN: <failed check>.

Reconstruction Bias

Be evidence-maximal, not stub-maximal. A body with five supported operations and one unknown receiver should become four or five Python lines plus one # UNCERTAIN marker, not a full ... body. Preserve uncertainty locally.

Confidence

Compute confidence qualitatively:

  • 90-100%: almost every nontrivial line comes from @OPS/@ASM.
  • 70-89%: core control flow is evidenced, with small uncertain spans.
  • 40-69%: signatures and literals are strong, bodies partly inferred.
  • Below 40%: emit mostly signatures/globals with uncertainty markers.

Use the header value to communicate evidence quality, not optimism.

© DimaReverse, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in nuitka-nbc-rebuilder-skill of DimaReverse/nuitka-static-unpacker.

  • SKILL.md
  • EXAMPLES.md
  • INSTALL.md
  • OPCODES.md
  • PROMPT.md

Open the folder on GitHubat commit 433eac3

Compare with similar skills

Nuitka Nbc Rebuilder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nuitka Nbc Rebuilder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nuitka Nbc Rebuilder this skillDimaReverse/nuitka-static-unpacker132—~2kAutomated safety check: PassMIT
Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills185—~826Automated safety check: PassMIT
Ghidra ReOrbitCurve/firmware-reverse-engineering216—~4.2kAutomated safety check: PassApache-2.0
Electron App Security Analyzerptn1411/skill219—~830Automated safety check: NotesNone
Rev Unicorn Debugindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Binary Reaiskillstore/marketplace4331 repos~2.6kAutomated safety check: PassNone

Similar skills

  • Combine Dbc

    CSS-Electronics/can-bus-reverse-engineering-skills

    Combine multiple individual single-signal DBC files into one combined DBC at the application level.

    185 GitHub stars~826 tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    216 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 19 days ago
    SecurityAuto-check: notes
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Binary Re

    aiskillstore/marketplace

    This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

    433 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence.

    105 GitHub stars~877 tokensUpdated today
    DevelopmentAuto-check passed

Works with

Categories

Questions about Nuitka Nbc Rebuilder

What does Nuitka Nbc Rebuilder do?

Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py. Nuitka Nbc Rebuilder is an agent skill from DimaReverse/nuitka-static-unpacker.py.

When should I use Nuitka Nbc Rebuilder?

Nuitka Nbc Rebuilder fits situations like: the user pastes; references a .nbc file; an AIREADYNBC bundle; sections such as @MOD.

How do I install Nuitka Nbc Rebuilder in Claude Code?

Run `npx skills add DimaReverse/nuitka-static-unpacker --skill nuitka-nbc-rebuilder -a claude-code`. Or copy the skill folder (nuitka-nbc-rebuilder-skill in DimaReverse/nuitka-static-unpacker) into .claude/skills/nuitka-nbc-rebuilder in your project. Claude Code loads it when a task matches its description.

How do I install Nuitka Nbc Rebuilder in Codex?

Run `npx skills add DimaReverse/nuitka-static-unpacker --skill nuitka-nbc-rebuilder -a codex`. Or copy the skill folder (nuitka-nbc-rebuilder-skill in DimaReverse/nuitka-static-unpacker) into .agents/skills/nuitka-nbc-rebuilder in your project. Codex loads it when a task matches its description.

Can I use Nuitka Nbc Rebuilder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DimaReverse/nuitka-static-unpacker --skill nuitka-nbc-rebuilder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuitka-nbc-rebuilder, .gemini/skills/nuitka-nbc-rebuilder, .github/skills/nuitka-nbc-rebuilder and .opencode/skills/nuitka-nbc-rebuilder in your project.

What does Nuitka Nbc Rebuilder need to run?

Going by SKILL.md and its folder, Nuitka Nbc Rebuilder needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Nuitka Nbc Rebuilder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nuitka Nbc Rebuilder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nuitka Nbc Rebuilder use?

Nuitka Nbc Rebuilder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nuitka Nbc Rebuilder use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nuitka Nbc Rebuilder?

Skills that share tags, products or a category with Nuitka Nbc Rebuilder: Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 185 stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Electron App Security Analyzer (ptn1411/skill, 219 stars) and Rev Unicorn Debug (index-login/MobileRE-Skill, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nuitka Nbc Rebuilder?

DimaReverse (a GitHub user) maintains it in DimaReverse/nuitka-static-unpacker, which has 132 GitHub stars. The repository was last updated on August 22, 2026.

Source: DimaReverse/nuitka-static-unpacker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.