Ctf Crypto
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-format-elf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-format-elf .claude/skills/re-format-elf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .claude/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elfType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-format-elf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-format-elf .agents/skills/re-format-elf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .agents/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-format-elf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-format-elf .cursor/skills/re-format-elf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .cursor/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-format-elf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-format-elf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-format-elf .gemini/skills/re-format-elf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .gemini/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-format-elfInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-format-elf .github/skills/re-format-elf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .github/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-format-elf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-format-elf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-format-elf .opencode/skills/re-format-elf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-format-elf" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-format-elf into .opencode/skills/re-format-elf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-format-elf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-format-elfELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.
Re Format Elf is an agent skill from dslsdzc/rev-skills. ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复。 触发词:ELF、解析so、dynamic section
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).
It sits in Security. It works with Linux, macOS and Homebrew. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptdnfbrewFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Format Elf loads about 1.9k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 23 tokens; SKILL.md has 506 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 506 words, ~1,851 tokens.
.claude/skills/re-format-elf/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.参考 [[re-analyze/platform-tips]]——ELF 目标多为 Linux 本地分析;跨架构(ARM/MIPS 固件 ELF)可用 QEMU 用户态仿真,静态分析无需沙箱。
apt install binutils / dnf install binutils / pacman -S binutilsbrew install binutils(greadelf)readelf --versiongobjdump)objdump -Vapt install elfutils / dnf install elfutils / pacman -S elfutilsbrew install elfutils(eu-readelf 等)eu-readelf -h /bin/lsapt install patchelf / dnf install patchelf / pacman -S patchelfbrew install patchelfpatchelf --versionreadelf 三表(ehdr/phdr/shdr):
readelf -h sample # ELF 头: Class/Machine/Entry/Type
readelf -l sample # program headers(段→装载偏移,动态加载与 GNU_STACK 在这里)
readelf -S sample # section headers(节→地址/大小/标志)三表对照: -h 给入口点,-l 给运行时内存布局,-S 给静态节视图。
结构速览(ehdr/phdr/shdr 布局):ELF 文件 = 头 + 程序头表 + 节区 + 节头表;64 位下 ehdr 64 字节、phdr 56 字节/条、shdr 64 字节/条。ehdr 关键字段与偏移:
0x00 e_ident[16] magic(7F 45 4C 46)+class(0x04:1=32位/2=64位)+data(0x05)+OSABI(0x07)
0x10 e_type 1=REL 2=EXEC 3=DYN(PIE/so) 4=CORE
0x12 e_machine 62=x86-64 3=i386 183=AArch64 243=RISC-V 8=MIPS
0x18 e_entry 入口点
0x20 e_phoff 程序头表偏移
0x28 e_shoff 节头表偏移
0x34 e_ehsize 64(32 位为 52)
0x38 e_phnum | 0x3A e_shentsize | 0x3C e_shnum | 0x3E e_shstrndx三表关系: readelf -h 输出的每个字段都能在文件前 64 字节里手工核对(xxd -l 64);程序头描述"哪些文件区段按什么权限/对齐映射到内存",节头描述"文件里的符号/字符串/代码等命名区段"。字段全表与布局图见 [[layout]]。
初始化与终止回调(.init_array / .fini_array):
readelf -S sample | grep -iE 'init_array|fini_array'
readelf -a sample | grep -A5 -i 'init_array'
objdump -s -j .init_array sample # .init_array 是函数指针数组(数据节),用 -s 打印内容;-d 只反汇编代码节,实际不输出
# 取到指针后逐个 `objdump -d --start-address=<ptr> --stop-address=<ptr+len> sample` 看回调函数两者的执行时机不同,别混为一谈:.init_array 中的函数指针在启动初始化阶段(main 之前)按数组正序执行——初始化/反调试/解密常藏在这里,必须最先查;.fini_array 中的指针在退出/dlclose 清理阶段执行、按数组逆序,不紧跟 main(详见坑项)。
GOT/PLT 与动态符号:
objdump -d -j .plt sample # PLT 桩(外部函数调用入口)
readelf -r sample | head -40 # 重定位表(含 GOT 条目)
readelf -s sample | grep FUNC # 符号表(动态符号在 .dynsym)
objdump -T sample | grep UND # 未定义符号 = 导入动态链接结构解析要点(.so 与动态可执行文件必查):
readelf -d sample # dynamic section: DT_* 标签
readelf -s sample | head -20 # .dynsym 动态符号(导入/导出)
readelf -r sample | grep -E 'JUMP_SLOT|GLOB_DAT|RELATIVE'关联链: DT_STRTAB/DT_SYMTAB 标签指向 dynstr/dynsym,符号表按 DT_SYMENT 给出的 entry size 定长遍历(标准 ELF32 的 Elf32_Sym 为 16 字节、ELF64 为 24 字节;读 DT_SYMENT 并按该步长走,勿硬编码 24);DT_GNU_HASH(新)替代 DT_HASH(旧)做符号查找;重定位类型决定 GOT 槽行为——R_X86_64_JUMP_SLOT(PLT 跳转)、GLOB_DAT(全局变量)、RELATIVE(基址相对)。DT_BIND_NOW(或 FLAGS 的 DF_BIND_NOW)出现 = 启动时完成全部绑定、无惰性绑定(现代发行版默认);但 RELRO 是独立条件——全 RELRO = PT_GNU_RELRO 段 + BIND_NOW 同时成立(GOT 转只读);只有 PT_GNU_RELRO 是 Partial RELRO,只有 BIND_NOW 推不出 RELRO。动态区解析细节见 [[layout]]。
stripped 二进制符号恢复思路:
readelf -s sample | wc -l # 如果只剩 .dynsym(几十个),说明被 strip
strings -n 6 sample | grep -iE 'error|usage|\.so' # 错误消息泄露内部函数名恢复流程: 字符串交叉引用(strings -t x 取偏移 → 在 Ghidra/radare2 中定位引用)→ 对常见库函数做签名匹配(Ghidra FLIRT / rizin z 签名)→ 从 main 入口逆推调用关系。
安全属性检查:
readelf -l sample | grep -E 'GNU_STACK|GNU_RELRO'
# GNU_STACK 无 E 标志 = 不可执行栈(NX)
# GNU_RELRO 存在 + BIND_NOW = 全 RELRO;GOT 只读
readelf -s sample | grep -c __stack_chk_fail # >0 仅为 SSP 线索(静态链接会因 libc 自带 SSP 误报;SSP 按函数施加,不代表全部函数受保护)RELRO/Canary/NX 情况决定后续动态分析(如 GOT 是否可写)与 [[re-imports]] 的劫持面判断。
手工解析与验证:readelf 输出异常/头字段被伪造时,用 xxd + Python struct 按偏移直接解析 ehdr/phdr/shdr(最小可运行示例与字节样例见 [[examples]]),别把解析失败当"损坏文件"丢弃。
init_array 藏初始化/反调试:比 main 更早执行,只看 main 会漏掉预置逻辑
stripped 后符号只剩 dynsym:readelf -s 列表骤减,恢复靠字符串交叉引用 + 签名匹配,别期待完整符号
GOT 覆盖是常见攻击点:非全 RELRO 时 GOT 可写——逆向/利用分析都要确认 GNU_RELRO 与 BIND_NOW
检查跨架构 ELF(ARM/MIPS)时本机 objdump 报 "unknown format" → 用对应交叉工具或 QEMU 仿真(见 [[re-analyze/platform-tips]] Linux 分支)
早期初始化链不止 init_array:现象——查过 .init_array 却仍漏掉更早执行的逻辑(如 strcmp@GOT 被 hook 但 main 断点处未复现);原因——动态链接器初始化早期会先跑 .preinit_array(比 .init_array 更早),恶意构造器可在 main 之前覆写 GOT/装钩子;对策——.preinit_array 与 .init_array 都反汇编,在 __libc_start_main 调用 init 处断点,核对 GOT 条目在 main 前是否已被改写
伪造节头使 readelf 报错:现象——readelf -S/-l 报错或输出中断(e_shentsize 异常、程序头计数离谱、dynamic section 缺失);原因——混淆/对抗样本伪造头字段使工具解析失败;对策——xxd 手工核对 ehdr 关键字段(e_shoff/e_shnum/e_shentsize/e_phnum),按真实值修正后重解析,别当"损坏文件"丢弃
fini 不在 main 后立即执行:现象——在 main 返回处断点找不到"收尾"逻辑;原因——fini/.fini_array 在退出清理阶段执行(与 rtld_fini、atexit、析构函数一起),不紧跟 main;对策——收尾逻辑在 exit 路径(exit_group / rtld_fini)上断点,别在 main 尾部找
R_X86_64_RELATIVE addend 必须与 vaddr 体系自洽:*slot = B + addend(B=加载 bias)。若产物 vaddr = ImageBase + RVA(PE 转换场景),文件槽内存储值即目标 vaddr → addend = 存储值;只有"vaddr = 纯 RVA"体系才用 存储值 − ImageBase——混用两套公式是终审级 bug(偏差恒定一个 base,且"能 dlopen"不暴露)
SHF_ALLOC 节必须被 PT_LOAD 覆盖:动态区(.dynsym/.dynstr/.hash)标记 SHF_ALLOC 但不在任何段内 → 加载器不映射,符号解析失败——手写 ELF 生成器时给动态区单独 PT_LOAD(p_offset 与 p_vaddr 可解耦)
DSO 要求可执行栈而进程未启用 → dlopen 失败:现象——dlopen 报 cannot enable executable stack as shared object requires: Invalid argument(glibc 对 dlopen 路径直接拒绝,非内核行为);原因——该 DSO 要求可执行栈而进程启动时未启用可执行栈,而"缺 PT_GNU_STACK 是否算要求"取决于目标 ABI 默认栈权限(x86/x86-64/arm32 等默认可执行、aarch64/riscv 等默认不可执行);对策——正解是给目标补非 X 的 PT_GNU_STACK(PF_R|PF_W、无 X、align 16);仅在确需兼容时可临时设 glibc.rtld.execstack=2(=1 实测无效;该值放宽限制、降低安全性)
重定位目标段必须可写:GLOB_DAT/RELATIVE 的 r_offset 所在段若只读(PF_R),ld.so 写入即 SIGSEGV——含重定位目标的节强制 PF_W(v1 可放弃 RELRO,后续再上 PT_GNU_RELRO)
shstrtab 别用 strlen 取长:字符串表以 \0 开头,strlen 在首字节截断为 1——用显式长度/sizeof;同理会坑 .dynstr 索引
filesz > memsz 是 readelf 报错:p_memsz = max(vsize, raw_size) 保证 filesz≤memsz,BSS 清零区语义由 loader 处理
gzexe 包裹的 ELF(伪装 .sh):现象——目标文件拖进 IDA 报"不是 ELF 格式",但文件确实是可执行程序;原因——gzexe 把 ELF gzip 压缩后包在 shell 脚本里(Linux 常见压缩方式);对策——hexdump 看头确认(脚本头 + 尾部压缩数据),gzexe -d 解压还原真正的 ELF 再分析
OLLVM 混淆 + 字符串加密的 ELF:GOT 出口拦截:现象——静态补丁不可行(51642 类关键串运行时才解密,二进制里找不到);原因——OLLVM 字符串加密使字符串仅运行时出现在内存;对策——不在数据源头动手,在数据出口拦截:程序最终发送必然经 GOT 调 sendto/send/write/SSL_write → hook GOT 槽位,在 buf 中搜索 needle 替换后原样调用真函数;先用 debug 模式确认目标串确实出现在发送缓冲区再 patch;OLLVM 可能混淆 GOT 值本身(MOVZ+MOVK×3 拼出的 64 位常量 got_addend)——hook 安装时保持与混淆方式一致(改 MOVZ+MOVK 立即数而非直接写地址)
code cave 注入 + 哨兵占位(免重编译):现象——要注入的 shellcode 地址依赖目标具体布局,每目标重写一次;原因——直接硬编码地址不可复用;对策——shellcode 内所有地址用哨兵值(如 0xCAFEBABE 开头)占位,patcher 注入时扫描哨兵替换为实际地址(cave 地址/偏移/原 init 指针均可自动检测);注入点用 .init_array(程序启动自动调用,比 main 早)
© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-format-elf of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Format Elf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Format Elf this skilldslsdzc/rev-skills | 125 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Gearcoleco Debuggingdrhelius/Gearcoleco | 141 | — | ~3.5k | Automated safety check: Pass | GPL-3.0 | |
| Ccapwysaid/CameraCapture | 191 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Install Mimi Remotegaixianggeng/mimi-remote | 104 | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Env Doctorcat-xierluo/legal-skills | 713 | — | ~756 | Automated safety check: Pass | MIT |
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
wysaid/CameraCapture
Install or use the ccap CLI for camera capture, webcam inspection, device listing, frame capture, and video metadata.
gaixianggeng/mimi-remote
安装、配置、配对、迁移、升级、诊断、回滚或卸载 Mimi Remote;在 macOS 上安装和维护 Mimi Remote Mac 菜单栏 App / DMG,或通过 Homebrew、Linux user-systemd 部署 agentd;从源码构建 iPhone/iPad App;配置 Codex 主通道和可选 Claude Code 实验 Runtime。用户提出“安装 Mimi…
cat-xierluo/legal-skills
本机开发环境与全局包的体检、账本与安装纪律,覆盖所有包管理器(npm/npx、nvm、pip/pipx、uv、brew、bun)与运行时环境面(~/.local/bin 垫片、PATH、python 解释器版图、LaunchAgents、cron、shell rc 漂移对照)。当用户问「node/python 为什么是这个版本」「npm/pip…
Peiiii/nextclaw
当用户希望把本机 Codex、ChatGPT Codex 或 Claude Code 订阅通过 localhost 暴露为 OpenAI 兼容端点,或希望在代理验证成功后把它添加成 NextClaw 自定义 provider 时使用。负责 CLIProxyAPI 安装检查、安全配置、OAuth 登录、Homebrew/systemd 持久托管、重启存活验收、NextClaw provider…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills. Re Format Elf is an agent skill from dslsdzc/rev-skills.
Re Format Elf fits situations like: security work in your project.
Run `npx skills add dslsdzc/rev-skills --skill re-format-elf -a claude-code`. Or copy the skill folder (.claude/skills/re-format-elf in dslsdzc/rev-skills) into .claude/skills/re-format-elf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-format-elf -a codex`. Or copy the skill folder (.claude/skills/re-format-elf in dslsdzc/rev-skills) into .agents/skills/re-format-elf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-format-elf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-format-elf, .gemini/skills/re-format-elf, .github/skills/re-format-elf and .opencode/skills/re-format-elf in your project.
Going by SKILL.md and its folder, Re Format Elf needs the command-line tools its instructions call (apt, dnf and brew). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Format Elf is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Format Elf: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars), Ccap (wysaid/CameraCapture, 191 stars) and Install Mimi Remote (gaixianggeng/mimi-remote, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.