Ghidra Re
OrbitCurve/firmware-reverse-engineering
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-crypto-keys .claude/skills/re-crypto-keys && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .claude/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keysType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-crypto-keys .agents/skills/re-crypto-keys && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .agents/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-crypto-keys .cursor/skills/re-crypto-keys && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .cursor/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-crypto-keys--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-crypto-keys .gemini/skills/re-crypto-keys && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .gemini/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-crypto-keysInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-crypto-keys .github/skills/re-crypto-keys && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .github/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-crypto-keys .opencode/skills/re-crypto-keys && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-crypto-keys" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-crypto-keys into .opencode/skills/re-crypto-keys/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-crypto-keys", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-crypto-keys密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills.
Re Crypto Keys is an agent skill from dslsdzc/rev-skills. 密钥与口令提取:硬编码、内存搜索、资源。 触发词:找密钥、硬编码、key extraction、口令
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware. It works with Ghidra. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptdnfpipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Crypto Keys loads about 1.5k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 348 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 348 words, ~1,515 tokens.
.claude/skills/re-crypto-keys/SKILL.md (or your agent's skills folder).所有工具先验证再使用。静态搜索可免沙箱;内存转储/动态环节按 [[re-memdump]] 默认转储优先 + [[re-analyze/platform-tips]] 最高原则(运行样本进沙箱)。
apt install binutils / dnf install binutils / pacman -S binutils(多数自带)strings.exe(Sysinternals)strings --version(GNU 版有 --version)ghidra(GUI)或 rz-ghidra 插件可用;rizin -vgcore -o out <pid> 转储;转储时机按明文/代码 materialization 定(单层壳 OEP 附近通常合适,OEP 非通用判据,见 [[re-analyze/platform-tips]] 关键经验)file out 确认为 ELF core,eu-stack -e out 能跑按顺序执行,每步记下结果。策略顺序:先静态后动态(见坑 3),每步产物(密钥/口令 + 来源证据:偏移、函数名、转储路径)记录供 [[re-crypto-decrypt]] 使用。
静态:strings / 交叉引用找硬编码:
strings -n 6 sample.bin | grep -iE 'key|secret|pass|token|crypt|iv' | head -50
strings -el sample.bin | grep -iE 'key|secret|pass' | head -20 # UTF-16LE(Windows 常见)
strings -n 8 sample.bin | head -100 # 全量扫描人工过一遍Search > Memory / :> /v 0x...):32 字节十六进制串、重复的随机数据段内存:转储后搜密钥模式(16/32 字节熵块、口令可打印串):
gcore -o out <pid> # 默认转储([[re-memdump]]),按 materialization 定时机data = open('out','rb').read()
import collections, math
# 16/32 字节高熵块(AES-128/256 密钥候选)
def ent(blk):
c = collections.Counter(blk); n = len(blk)
return -sum((v/n)*math.log2(v/n) for v in c.values())
for base in range(0, len(data)-32, 32):
blk = data[base:base+32]
if ent(blk) > 7.0 and 16 <= len(set(blk)) <= 24:
print(f"0x{base:x}: 32B 高熵块")
# 口令/可打印串
import re
for m in re.finditer(rb'[ -~]{8,64}', data):
s = m.group()
if any(k in s.lower() for k in (b'key', b'pass', b'secret', b'pwd')):
print(f"0x{m.start():x}: {s}")资源文件(.rsrc / 嵌入 blob):
llvm-objdump -s -j .rsrc sample.exe 或 Ghidra 看资源段;7z x sample.exe 可解出嵌入的 icon/version/自定义资源.rodata 里的嵌入 blob(objdump -s -j .rodata);结合 [[re-firmware]] 经验——固件里密钥常在配置文件/默认证书里导入表线索(Crypt 函数附近)*:
objdump -p sample.exe | grep Crypt / Ghidra Imports 窗口找 CryptEncrypt/CryptDecrypt/BCrypt*/RSA*/EVP_*(OpenSSL)CryptSetKeyParam 的 pbKeyData 参数b CryptSetKeyParam 后看 pbKeyData 指向的内存——但注意 [[re-analyze/platform-tips]] 最高原则:运行进沙箱密钥派生函数(PBKDF)还原:
PBKDF2/scrypt/bcrypt/EVP_BytesToKey 调用 → 密钥 = KDF(口令, 盐, 迭代次数),逐参数提取:口令(硬编码串或用户输入)、盐(固定字节或上下文)、迭代次数(常量)pip install cryptography / hashlib 自带 PBKDF2):import hashlib
key = hashlib.pbkdf2_hmac('sha256', b'passphrase', b'<salt>', 100000, dklen=32)
print(key.hex())RAND_bytes 生成或服务器下发,根本不在样本里(白盒攻击之外无解);对策——诚实报告:本地无可提取密钥,改走密钥派生拦截(hook RAND_bytes/KDF 输入)、算法侧攻击(若解密结果可被已知明文验证)或回 [[re-malware]] 看密钥是否由 C2 下发© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-crypto-keys of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Crypto Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Crypto Keys this skilldslsdzc/rev-skills | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Ghidra ReOrbitCurve/firmware-reverse-engineering | 214 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Firmware Security ReportsOrbitCurve/firmware-reverse-engineering | 214 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Bench ExperimentDavidClawson/OpenScope-2C53T | 116 | — | ~1k | Automated safety check: Pass | GPL-3.0 | |
| Go Rust Reversezhaoxuya520/reverse-skill | 40k | 2 repos | ~339 | Automated safety check: Pass | MIT | |
| Reverse Engineering Signaturesvillith/relink-logs | 157 | — | ~7.5k | Automated safety check: Pass | MIT |
OrbitCurve/firmware-reverse-engineering
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
OrbitCurve/firmware-reverse-engineering
Evidence-based security report generation for firmware assessments.
DavidClawson/OpenScope-2C53T
Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.
zhaoxuya520/reverse-skill
A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
villith/relink-logs
A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…
mukul975/Anthropic-Cybersecurity-Skills
Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Works with
Categories
密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills. Re Crypto Keys is an agent skill from dslsdzc/rev-skills.
Re Crypto Keys fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a claude-code`. Or copy the skill folder (.claude/skills/re-crypto-keys in dslsdzc/rev-skills) into .claude/skills/re-crypto-keys in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a codex`. Or copy the skill folder (.claude/skills/re-crypto-keys in dslsdzc/rev-skills) into .agents/skills/re-crypto-keys in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-crypto-keys, .gemini/skills/re-crypto-keys, .github/skills/re-crypto-keys and .opencode/skills/re-crypto-keys in your project.
Going by SKILL.md and its folder, Re Crypto Keys needs the command-line tools its instructions call (apt, dnf and pip). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Crypto Keys is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Crypto Keys: Ghidra Re (OrbitCurve/firmware-reverse-engineering, 214 stars), Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 214 stars), Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars) and Go Rust Reverse (zhaoxuya520/reverse-skill, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.