C To Ast
Narwhal-Lab/MagicSkills
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
加密数据还原:定位解密函数、写解密脚本. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-decrypt --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .claude/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .claude/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decryptType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-decrypt --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .agents/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .agents/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-decrypt --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .cursor/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .cursor/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-crypto-decrypt--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-decrypt --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .gemini/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .gemini/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-crypto-decryptInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .github/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .github/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-decrypt --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-crypto-decrypt .opencode/skills/re-crypto-decrypt && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-crypto-decrypt" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-decrypt into .opencode/skills/re-crypto-decrypt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-decrypt", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-crypto-decrypt加密数据还原:定位解密函数、写解密脚本. An agent skill from dslsdzc/rev-skills.
Re Crypto Decrypt is an agent skill from dslsdzc/rev-skills. 加密数据还原:定位解密函数、写解密脚本。 触发词:解密、decrypt、还原数据、解密流量
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. It works with Python. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pippython3aptdnfbrewpythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Crypto Decrypt loads about 1.8k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 518 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 518 words, ~1,837 tokens.
.claude/skills/re-crypto-decrypt/SKILL.md (or your agent's skills folder).所有工具先验证再使用。本技能处理的是转储/反编译产物与密文数据,运行样本环节在 [[re-sandbox]] 内([[re-analyze/platform-tips]] 最高原则)。
apt install python3 python3-pip / dnf install python3 python3-pip / pacman -S python python-pipbrew install pythonpip install pycryptodome(AES/DES/RSA/ChaCha 等标准算法)python3 -c "from Crypto.Cipher import AES; print('ok')";python3 --versionfile out 是 ELF core;反编译器里能找到目标函数(ghidra / rizin 可启动)pip install angr——Python 版本兼容性以 [[re-angr]] 的「工具准备」为准(版本矩阵只在该处维护一份,避免多处漂移);依赖多,建议 venv: python3 -m venv venv && venv/bin/pip install angrvenv/bin/python -c "import angr; print(angr.__version__)"按顺序执行,每步记下结果。前提:算法([[re-crypto-id]])与密钥([[re-crypto-keys]])已确认或至少有一方候选;脚本与验证结果(明文样本 + sha256)存档供报告引用。
证伪"密文":先定位真实密文边界(跳过此步是加密分析最常见的失败方式):
cd_offset/cd_size 反推数据起点,EOCD 签名是已知明文)IEND 字样可落在 tEXt chunk 数据内、JPEG 的 FF D9 可落在 APP1 等 length-delimited 段内(拿首个命中当结尾会截掉合法数据)。正确做法是按格式规范解析:PNG 从 8 字节签名起按 Length/Type/Data/CRC 逐 chunk 遍历,直到结构合法且长度为 0 的 IEND(必要时逐块验 CRC);JPEG 从 SOI 起按 marker/segment 解析,进入 SOS 后按 FF00 stuffing 与 RSTn 规则处理,语法位置成立的 EOI 才是结尾。裸字节搜索只能用来产生候选位置,候选要经结构校验后才能定边界定位解密函数(交叉引用密文输入点):
Crypt*/EVP_* 调用点就是候选;观察入参的密文指针是否指向步骤 2 的偏移反编译还原算法:
重写为独立脚本(python):
# decrypt.py —— 按反编译还原的算法重写
from Crypto.Cipher import AES
import sys
key = bytes.fromhex("...") # 来自 [[re-crypto-keys]] 步骤 1/2/5
iv = key[:16] # 样本实现: IV = key 前 16 字节
data = open(sys.argv[1], 'rb').read()
pt = AES.new(key, AES.MODE_CBC, iv).decrypt(data)
print(pt) # 或写文件 + 后续校验用已知明文验证:
\xAA\x55)、文件头(PK zip / \x89PNG)、报文字段([[re-proto-rev]] 步骤 2 的固定头)、或 [[re-behavior]] 行为里观察到的明文串file - 识别出格式(PDF/zip/文本)→ 视为成功候选流量场景:解出明文流量流:
tshark -r c2.pcap -Y 'tcp.payload' -T fields -e data.data | sed 's/://g' | xxd -r -p > payloads.bin\n + = = 66 符号、Ascii85 85、hex 16 等;命中后 XOR 还原 → 解码;交叉验证:填充符(如 = 加密后仅出现 1 次在文件尾)、换行符频率、解码后魔数ImageChops.logical_xor 或 numpy a^b 逐像素 XOR 两图(RGB 三通道);结果常是"99.5% 纯白背景 + 极浅灰文字"(文字 254 vs 背景 255)——直接看/反色都不可见,用阈值增强:==255 → 黑、其余 → 白,文字立现;位图小字再按字符网格(5x7)切分逐字读,重复字符用两两位图相似度矩阵验证(如 d562333d 的重复模式)clip(a+b) 饱和加法与 a-b 减法,多运算组合对比r_1_0 类字段);对策——按"每层单独验证"纪律分层剥(熵降/可读即前进一层,见多轮解密链坑);注意同源 SDK 的"整体加密"可能再套 VM 化算法(约 70 个 handle 模拟基本指令、handle 未混淆时可逐个识别指令语义);key 来源分随机(抓包不可复现)与固定(可静态找)两类,先固定后随机03000001)再进同一函数;且加解密可能是同一函数(标志位控制方向);对策——hook 解密函数返回点批量导出全部解密字符串(JNI_OnLoad 前 memcpy 的加密串 → 全局变量 → 解密函数),key/iv 直接在其中搜索;找加密点用 findcrypt 扫特征常量(AES S-box 等)→ xref 定位校验 key/iv 长度(16)的函数;动态 hook 打印两次调用前后数据对照验证© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-crypto-decrypt of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Crypto Decrypt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Crypto Decrypt this skilldslsdzc/rev-skills | 125 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| C To AstNarwhal-Lab/MagicSkills | 316 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Vpn Security CheckSergei-thinker/vpn-setup | 189 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Banditalpha-omega-security/scrutineer | 231 | — | ~615 | Automated safety check: Notes | MIT | |
| Python Reviewliuyanghejerry/Clausura | 204 | — | ~164 | Automated safety check: Pass | MIT |
Narwhal-Lab/MagicSkills
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Sergei-thinker/vpn-setup
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
alpha-omega-security/scrutineer
Run bandit against the Python source in the repository and map its hits into the findings shape.
liuyanghejerry/Clausura
Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Works with
Categories
加密数据还原:定位解密函数、写解密脚本. An agent skill from dslsdzc/rev-skills. Re Crypto Decrypt is an agent skill from dslsdzc/rev-skills.
Re Crypto Decrypt fits situations like: security work in your project.
Run `npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a claude-code`. Or copy the skill folder (.claude/skills/re-crypto-decrypt in dslsdzc/rev-skills) into .claude/skills/re-crypto-decrypt in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a codex`. Or copy the skill folder (.claude/skills/re-crypto-decrypt in dslsdzc/rev-skills) into .agents/skills/re-crypto-decrypt in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-crypto-decrypt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-crypto-decrypt, .gemini/skills/re-crypto-decrypt, .github/skills/re-crypto-decrypt and .opencode/skills/re-crypto-decrypt in your project.
Going by SKILL.md and its folder, Re Crypto Decrypt needs the command-line tools its instructions call (pip, python3, apt, dnf, brew and python). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Crypto Decrypt is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Crypto Decrypt: C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars) and Bandit (alpha-omega-security/scrutineer, 231 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.