Ctf Crypto
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。
$ npx skills add dslsdzc/rev-skills --skill re-arm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-arm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-arm .claude/skills/re-arm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .claude/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-armType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-arm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-arm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-arm .agents/skills/re-arm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .agents/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-arm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-arm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-arm .cursor/skills/re-arm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .cursor/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-arm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-arm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-arm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-arm .gemini/skills/re-arm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .gemini/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-armInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-arm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-arm .github/skills/re-arm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .github/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-arm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-arm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-arm .opencode/skills/re-arm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-arm" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-arm into .opencode/skills/re-arm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-arm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-armARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。
Re Arm is an agent skill from dslsdzc/rev-skills. ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。 触发词:ARM、arm32、Cortex-M、Cortex-A、Thumb、AAPCS、嵌入式逆向、裸机固件、stm32、向量表。
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware. It works with Android, Ghidra, Linux and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptbrewdnfFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Arm loads about 2.2k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 789 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 789 words, ~2,202 tokens.
.claude/skills/re-arm/SKILL.md (or your agent's skills folder)..so(走 [[re-android-native]])所有工具先验证再使用。静态分析可免沙箱;qemu 动态执行默认沙箱 + 网络隔离([[re-analyze/platform-tips]] 最高原则)。
apt install ghidra / pacman -S ghidrabrew install --cask ghidra;Windows: 官方 zipanalyzeHeadless -help(headless 模式)或 GUI 导入 ARM ELFapt install binutils 等);macOS: brew install binutils 或 LLVM 系 readelf;Windows: WSL 内readelf --versionbinwalk --version、unblob --versionapt install qemu-user / dnf install qemu-user / pacman -S qemu-userbrew install qemu(含用户态);Windows/WSL: WSL 内 Linux 版qemu-arm、64 位为 qemu-aarch64;-L <rootfs> 指定动态库/链接器来源,-strace 跟踪系统调用qemu-arm --version、qemu-aarch64 --versionqemu-system-arm -machine mps2-an385(Cortex-M3)等板级模型(-s -S 接 gdb),或 [[re-emulation]] 用 Unicorn 逐指令apt install gdb-multiarch(该包在 Debian/Ubuntu 及其衍生的官方仓库有);Fedora dnf install gdb(官方 gdb 支持多目标、可调裸机 ARM;arm-none-eabi-gdb 不在 Fedora 官方仓库,如需嵌入式专用工具链用官方预编译 ARM 工具链);Arch pacman -S gdb(官方 gdb 已内置 multiarch)brew install gdb(需 Developer Tools 授权,见 [[re-analyze/platform-tips]] macOS 分支)或 WSL 内 Linux 版;Windows/WSL: WSL 内 Linux 版gdb-multiarch --version;Fedora/Arch gdb --version;载入裸机固件后 set architecture armv7-m 再 file 加载,info registers 确认qemu-system-arm -s -S 或 qemu-arm -g <port>按顺序执行,每步结果存档;动态执行默认沙箱。
架构与字节序确认:
file target.bin # "ARM"=32 位(含 Thumb)、"AArch64"=64 位;MSB/LSB 端序提示
file target.elf
readelf -h target.elf # Machine=ARM / AArch64;Data=little-endian / big-endian
readelf -A target.elf | head # Tag_ABI_VFP_args: 1=硬浮点(HFABI)、0=软浮点;EABI 版本EF_ARM_ABI_FLOAT_HARD(0x400) 硬浮点 / EF_ARM_ABI_FLOAT_SOFT(0x200) 软浮点(对应坑 5)入口定位:
msr vbar_el1/el2/el3, Xt 及其地址构造序列;reset entry 本身由实现/SoC 启动配置决定(平台可提供 core reset vector base 配置),不能假定固定在 0AArch32 Thumb/T32 函数边界(Thumb/ARM 切换):
nm / readelf -s 中 Thumb 函数为奇地址)、BL 目标、向量表项、虚表函数指针项都带 Thumb 位bx rN / blx rN:按目标寄存器位 0 切换状态(1=Thumb);blx 立即数形式直接切到 ARM 态目标R_ARM_THM_CALL 判定,超距由链接器插 veneer);超限时链接器插入 veneer 跳板(形态如 ldr pc, =addr、movw+movt+bx),看到片状跳板序列不要当业务逻辑;veneer 也用于 ARM↔Thumb 状态切换$a/$t/$d 决定反汇编状态,映射符号丢失后会按错误状态反汇编——用 arm-none-eabi-objdump -d -M force-thumb 强制 Thumb,或交给 Ghidra 按 TMode 启发式切换基址 / 重定位(加载地址 vs 链接地址):
readelf -l):VMA 即链接地址;加载地址看 LMA / p_paddrAAPCS 调用约定识别:
push {r4-r11, lr},尾部 pop {..., pc}(借 LR 同时恢复 PC);叶子函数(无嵌套调用)常不 push LR,直接 bx lrreadelf -A 的 Tag_ABI_VFP_args 区分(混用时最易错,见坑 5)stp x29, x30, [sp, #-16]!外设寄存器交叉(MMIO xref):
ldr rN, [pc, #imm] 从函数尾部立即数池取地址 → str/ldr 访问外设;手工算池地址时注意 Thumb 态 PC=当前+4、ARM 态 +8,且按 4 字节对齐movw/movt + bx、ldr pc 跳板,被当成业务逻辑分析;原因——BL 立即数只能覆盖 ARM ±32MB / Thumb ±16MB,超限链接器插 veneer;对策——识别短跳板形态(结尾 bx/ldr pc 且目标为远地址)后跳过,继续跟踪最终目标;跨状态(Thumb↔ARM)调用同样经 veneerpush {..., lr} 与 bl 前后 LR 赋值点重建调用关系;异常入口现场恢复序列(入栈 8 字 r0-r3/r12/LR/PC/xPSR,PC 在 [sp,#0x18])用于确认异常处理函数readelf -A 的 Tag_ABI_VFP_args 与 e_flags 的 0x400/0x200 位定 ABI,再看参数实际落在哪组寄存器:首参从 s0-s15/d0-d7 收 = 硬浮点,从 r0-r3 收 = 软浮点。关键:-mfloat-abi=softfp 是"软浮点调用约定 + 允许 VFP 指令"——它照样发射 vmov/vadd/vcmp 等浮点指令,参数却仍走整数寄存器(实测:vmov s0, r1 把 r1 搬进 s0),所以浮点指令出现频率不能佐证 float ABI,只能佐证"代码用了 VFP"© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-arm of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Arm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Arm this skilldslsdzc/rev-skills | 125 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Audit Skillssickn33/agentic-awesome-skills | 47k | 2 repos | ~1.6k | Automated safety check: Warn | MIT | |
| Analyzing Linux Elf Malwaremukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | |
| Engine Whats Newflutter/flutter | 179k | — | ~978 | Automated safety check: Pass | BSD-3-Clause | |
| Updating Android SDKflutter/flutter | 179k | — | ~1.7k | Automated safety check: Pass | BSD-3-Clause |
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
sickn33/agentic-awesome-skills
Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.
mukul975/Anthropic-Cybersecurity-Skills
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…
flutter/flutter
Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).
flutter/flutter
Upgrades Flutter's Android SDK dependency to a new Android API version (or preview/canary release) in packages.txt, verifies CIPD tag uniqueness, and packages/uploads the binaries using…
darriousliu/PiPixiv
Jetpack Compose expert skill for Android UI development. An agent skill from darriousliu/PiPixiv.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。. Re Arm is an agent skill from dslsdzc/rev-skills.
Re Arm fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add dslsdzc/rev-skills --skill re-arm -a claude-code`. Or copy the skill folder (.claude/skills/re-arm in dslsdzc/rev-skills) into .claude/skills/re-arm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-arm -a codex`. Or copy the skill folder (.claude/skills/re-arm in dslsdzc/rev-skills) into .agents/skills/re-arm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-arm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-arm, .gemini/skills/re-arm, .github/skills/re-arm and .opencode/skills/re-arm in your project.
Going by SKILL.md and its folder, Re Arm needs the command-line tools its instructions call (apt, brew and dnf).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Arm is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Arm: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Audit Skills (sickn33/agentic-awesome-skills, 47k stars), Analyzing Linux Elf Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Engine Whats New (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.