Agent skill

Re Cpp Abi

by dslsdzc in dslsdzc/rev-skills

现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Cpp Abi

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-cpp-abi -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-cpp-abi --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-cpp-abi .claude/skills/re-cpp-abi && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-cpp-abi
GitHub stars
117
Used in
1 other repo
Token cost
~996 tokens
SKILL.md length
247 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.

  • Works in 6 steps: ABI 识别 → RTTI 重建(Itanium) → 虚表恢复 → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, dnf and brew

What it does

Re Cpp Abi is an agent skill from dslsdzc/rev-skills. 现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码。 触发词:C++逆向、RTTI、虚表恢复、异常处理、C++ ABI、mangling、C++反编译。

Its SKILL.md is about 1000 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. It works with C++, Ghidra and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re-cpp-abi”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. ABI 识别
  2. RTTI 重建(Itanium)
  3. 虚表恢复
  4. 异常处理表
  5. 模板/lambda 识别
  6. mangling 解码(批量)

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Cpp Abi loads about 996 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 247 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~996

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 247 words, ~996 tokens.

Download SKILL.mdSave it as .claude/skills/re-cpp-abi/SKILL.md (or your agent's skills folder).
name
re-cpp-abi
description
现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码。 触发词:C++逆向、RTTI、虚表恢复、异常处理、C++ ABI、mangling、C++反编译。
type
atomic
capabilities
decompilation

现代 C++ 逆向(RTTI / 异常 / 虚表)

何时使用 / 何时不用

  • 用:RTTI/异常表密集的二进制、反编译结果混乱的 C++ 目标(类层次/虚调用/异常流无法直接读出)
  • 不用:C 代码或纯汇编(走 [[re-binary-core]] 通用路径);混淆主导的目标(先 [[re-deobfuscate]])

工具准备

readelf / llvm-objdump(节表与异常表)
  • Linux: apt install binutils llvm / dnf install binutils llvm / pacman -S binutils llvm
  • macOS: brew install llvm(binutils 部分 macOS 自带)
  • Windows: WSL 或 llvm 预编译
  • 验证: readelf --version、llvm-objdump --version
c++filt / undname(mangling 解码)
  • Linux/macOS: c++filt(binutils 自带);Windows: undname(VS 工具链)
  • 验证: echo '_ZN3foo3barEv' | c++filt(输出 foo::bar())
Ghidra / IDA(反编译底座,脚本化 RTTI 遍历)
  • 安装与验证见 [[re-ghidra]] / [[re-ida]] 工具准备
gdb(异常断点,可选)
  • 安装与验证见 [[re-gdb]]

操作步骤

按顺序执行,每步产物存档(路径 + sha256,见 [[re-triage]])。

  1. ABI 识别:

    sh
    readelf -s sample | grep -E '_ZN|_ZTV|_ZTI' | head    # Itanium(GCC/Clang)
    strings sample | grep -E '^\?\?_' | head              # MSVC
    • Itanium 特征:_ZN(函数)、_ZTV(虚表)、_ZTI(RTTI 类型信息)
    • MSVC 特征:??_7(vftable)、??_R(RTTI)(strip 后 ??_ 在符号表而非字符串区——补查导入表 __CxxFrameHandler / msvcp 特征辅助判断)
    • 识别错则后续全部偏——先确认再继续
  2. RTTI 重建(Itanium):

    sh
    readelf -s sample | grep _ZTI | head
    # _ZTI<类名> 指向 typeinfo:起始为 vptr(指向 _ZTVN10__cxxabiv1... 类型信息虚表),
    # 下一 pointer-sized 槽为 __type_name;64 位通常 +0/+8、32 位 +0/+4
    # 解析前先定 ELF class / 指针宽度;__si_class_type_info / __vmi_class_type_info 同样按目标 ABI 对齐与字段宽度解析
    • 结构:typeinfo → __class_type_info 派生链 → 每个类的完整继承路径
    • 脚本化:Ghidra/IDA 遍历 _ZTI 引用,重建类继承图(父子关系表)
    • 产出:类名 → 继承链映射(写入会话 symbols_known,见 [[re-analyze/analysis-contract]])
    • MSVC:??_R0<类名> TypeDescriptor 符号 + _RTTICompleteObjectLocator(COL)遍历重建继承图
  3. 虚表恢复:

    sh
    readelf -s sample | grep _ZTV | head
    • _ZTV<类名> 指向 vtable 起点(虚函数指针数组);vtable 前缀两槽位(32 位 8 字节 / 64 位 16 字节):offset to top + typeinfo 指针(Itanium ABI)
    • 定位 vtable 后:每个槽位的函数地址 → 调用点反推虚方法名(结合步骤 2 的继承图)
    • 虚调用(call *reg)无法静态定名 → 用调用点上下文(参数/返回值使用)缩小候选
  4. 异常处理表:

    sh
    readelf -S sample | grep -E 'eh_frame|gcc_except'   # ELF:.eh_frame(readelf 不解析 PE,PE 走下方命令)
    llvm-readobj --coff-unwind-info sample.exe            # PE:.pdata/.xdata(或 objdump -h / pefile)
    • PE:.pdata 的 RUNTIME_FUNCTION(Begin/End/UnwindInfo)→ .xdata 展开数据 → 异常处理器(__CxxFrameHandler3)
    • ELF:.eh_frame 的 FDE/CIE → 展开规则与 LSDA(.gcc_except_table)→ 异常处理函数
    • 用途:恢复被异常路径打断的控制流、定位析构/清理逻辑(catch 块)
  5. 模板/lambda 识别:

    • 模板:符号含 <...> 参数(Itanium mangling 中展开为长串);实例化爆炸时按调用模式聚类
    • lambda:closure type 是真实的匿名 class type;普通调用场景常不发射独立 RTTI,缺 _ZTI 既不能排除也不能反推 lambda(typeid 等 ODR-use 时可有对应 RTTI)。识别优先用 Itanium 的 _ZZ<作用域>ENK... / operator() mangling、捕获成员布局与调用点,MSVC 的 <lambda_...>
    • 输出:疑似模板实例化/lambda 的函数清单 + 调用点
  6. mangling 解码(批量):

    sh
    readelf -s sample | grep -E '_ZN|_ZTV|_ZTI' | awk '{print $8}' | c++filt | head -20
    • MSVC: undname 或在线等价工具
    • 解码结果写入符号表(供 [[re-ghidra]] / [[re-ida]] 重命名)

跨域联合

  • [[re-binary-core]] 网关:本技能归属(re-binary-core 选择树已挂载)
  • [[re-ghidra]] / [[re-ida]]:反编译底座与脚本化
  • [[re-deobfuscate]]:混淆与 ABI 分析衔接
  • [[re-analyze/analysis-contract]]:类继承图/符号表按数据契约传递
  • [[re-analyze/rerouting]]:RTTI/异常表特征触发本技能(A 表已挂)

常见坑与陷阱

  • ABI 误判导致全部解析失败:现象——用 Itanium 结构解析 MSVC 目标(或反之)全盘错位;原因——识别步骤跳过;对策——先做步骤 1,mangling 特征双查
  • 模板展开导致符号爆炸:现象——readelf 输出几万行 _Z...;原因——模板实例化;对策——按调用模式聚类、过滤标准库符号(libstdc++/STL 前缀)
  • lambda 缺 RTTI 被当成无类型:现象——类继承图缺节点,误以为 lambda 不是真实类型;原因——closure type 是真实的匿名 class type,只是普通调用场景常不发射独立 typeinfo,缺 _ZTI 既不能排除也不能反推;对策——按 _ZZ<作用域>ENK... / operator() mangling、捕获成员布局与调用点识别,不硬找 RTTI(typeid 等 ODR-use 时可另有 RTTI)
  • 异常表版本差异:现象——.xdata 解析错位;原因——MSVC 异常处理版本(__CxxFrameHandler3 等)不同;对策——按导入函数(__CxxFrameHandler)确认版本再解析
  • 虚调用无法静态定名:现象——call *reg 全是间接调用;原因——虚分派;对策——结合 vtable 槽位与调用点证据缩小候选,不猜

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-cpp-abi of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dslsdzc/rev-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Re Cpp Abi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Cpp Abi compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Cpp Abi this skilldslsdzc/rev-skills1171 repos~996Automated safety check: PassApache-2.0
Ghidra ReOrbitCurve/firmware-reverse-engineering213—~4.2kAutomated safety check: PassApache-2.0
Firmware Security ReportsOrbitCurve/firmware-reverse-engineering213—~4.1kAutomated safety check: PassApache-2.0
Bench ExperimentDavidClawson/OpenScope-2C53T116—~1kAutomated safety check: PassGPL-3.0
Go Rust Reversezhaoxuya520/reverse-skill40k2 repos~339Automated safety check: PassMIT
macOS Reversezhaoxuya520/reverse-skill40k2 repos~366Automated safety check: PassMIT

Similar skills

  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    213 GitHub stars~4.2k tokensUpdated 29 days ago
    SecurityAuto-check passed
  • Firmware Security Reports

    OrbitCurve/firmware-reverse-engineering

    Evidence-based security report generation for firmware assessments.

    213 GitHub stars~4.1k tokensUpdated 29 days ago
    SecurityAuto-check passed
  • Bench Experiment

    DavidClawson/OpenScope-2C53T

    Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.

    116 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    40k GitHub starsUsed in 2 repos~339 tokens
    SecurityAuto-check passed
  • macOS Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

    40k GitHub starsUsed in 2 repos~366 tokens
    SecurityAuto-check passed
  • A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…

    158 GitHub stars~7.5k tokensUpdated 11 days ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Works with

Categories

Questions about Re Cpp Abi

What does Re Cpp Abi do?

现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills. Re Cpp Abi is an agent skill from dslsdzc/rev-skills.

When should I use Re Cpp Abi?

Re Cpp Abi fits situations like: tasks that involve Reverse engineering and malware.

How do I install Re Cpp Abi in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-cpp-abi -a claude-code`. Or copy the skill folder (.claude/skills/re-cpp-abi in dslsdzc/rev-skills) into .claude/skills/re-cpp-abi in your project. Claude Code loads it when a task matches its description.

How do I install Re Cpp Abi in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-cpp-abi -a codex`. Or copy the skill folder (.claude/skills/re-cpp-abi in dslsdzc/rev-skills) into .agents/skills/re-cpp-abi in your project. Codex loads it when a task matches its description.

Can I use Re Cpp Abi in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-cpp-abi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-cpp-abi, .gemini/skills/re-cpp-abi, .github/skills/re-cpp-abi and .opencode/skills/re-cpp-abi in your project.

What does Re Cpp Abi need to run?

Going by SKILL.md and its folder, Re Cpp Abi needs the command-line tools its instructions call (apt, dnf and brew).

Does Re Cpp Abi access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Cpp Abi safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Cpp Abi use?

Re Cpp Abi is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Cpp Abi use?

About 996 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Cpp Abi?

Skills that share tags, products or a category with Re Cpp Abi: Ghidra Re (OrbitCurve/firmware-reverse-engineering, 213 stars), Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 213 stars), Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars) and Go Rust Reverse (zhaoxuya520/reverse-skill, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Cpp Abi?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.