TH08 Semantic Reconstruction
N0zoM1z0/th08
Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-fp-runtime .claude/skills/re-fp-runtime && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .claude/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtimeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-fp-runtime .agents/skills/re-fp-runtime && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .agents/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-fp-runtime .cursor/skills/re-fp-runtime && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .cursor/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-fp-runtime--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-fp-runtime .gemini/skills/re-fp-runtime && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .gemini/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-fp-runtimeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-fp-runtime .github/skills/re-fp-runtime && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .github/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-fp-runtime .opencode/skills/re-fp-runtime && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-fp-runtime" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fp-runtime into .opencode/skills/re-fp-runtime/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-fp-runtime", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-fp-runtime函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
Re Fp Runtime is an agent skill from dslsdzc/rev-skills. 函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略。 触发词:Haskell逆向、OCaml逆向、GHC RTS、thunk、STG、OCaml runtime、闭包、函数式产物。
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).
It sits in Security, covering Reverse engineering and malware. It works with C++. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptbrewwingetFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Fp Runtime loads about 1.4k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 394 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 394 words, ~1,430 tokens.
.claude/skills/re-fp-runtime/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.apt install ghc / brew install ghc / ghcup);Windows: ghcup(winget install ghcup 或官网安装器);验证: ghc --versionapt install ocaml / brew install ocaml);Windows: opam(winget install OCaml.opam)或官网安装器;验证: ocamlobjinfo 处理任意 .cmx 输出 CRC 与导入表file/xxd);Python 3 自带 struct按顺序执行;逆向着重数据流而非控制流(函数式产物控制流被打散,见坑 4)。每步产物存档(路径 + sha256,见 [[re-triage]])。
运行时识别:
readelf -s sample | grep -iE 'ghc|stg_|RTS|HsMain|_closure|_info' | head # GHC 特征
readelf -s sample | grep -iE 'caml_' | head # OCaml 特征
file sample # 字节码产物判别(脚本头)main(C RTS 入口)+ RTS 运行时符号(stg_*/hs_*)+ 业务符号 Main_main_closure/Main_main_info(模块_名字_closure/info 形态)main → caml_main → caml_startup_common → caml_start_program → caml<模块>__entry;caml_startup/caml_startup_pooled 是供 C 嵌入调用的等价入口(签名同为 void (char_os **argv),区别在 pooling 标志与异常行为),勿误当主链;caml_* 运行时符号(caml_alloc/caml_apply2/3 等)caml_start_program 仅存在于 native 运行库(4.14.2 libasmrun.a 实测),是 native 特征;字节码判据用 caml_interprete(仅 libcamlrun.a 有);字节码产物判别用 file(ocamlrun script executable)/xxd 头(#!...ocamlrun\n 脚本头 + T/C 魔数 + 分节)main 并调用 caml_main(argv)(caml_main 定义于 startup_byt.c/startup_nat.c;原生链 main → caml_main → caml_startup_common → caml_start_program,4.14.2 实测地址见 [[examples]]);字节码运行库入口为 caml_main → caml_startup_aux → caml_interpretestg_* 机械符号群 + 模块_名_closure/info 对;OCaml 原生 = caml_* 群 + caml<模块>__<名>_<id>;OCaml 字节码 = #!ocamlrun 脚本头闭包与堆对象:
Main_main_closure 是 CAF,其 info 指向 thunk 求值代码调用约定:
_info 符号 = entry code)caml_applyN;原生代码调用闭包 = 寄存器装载 + caml_apply2/3 或直接跳 entrycaml_apply / stg 入口)再进用户逻辑;尾调用优化使递归变跳转(无增长栈帧),按循环读jmp 目标地址即函数入口,别按 call/ret 配对思维读分析策略(数据流优先):
构造器 C1 (tag 0, 2 字段) ← 分配点 A (caml_alloc2 / info 表)
字段0 ← 函数参数/常量(数据来源)
字段1 ← 字符串池引用
使用点: tag 比较 → 分支 B(业务逻辑)字节码产物(OCaml 特有):
head -c 64 sample | xxd # #!...ocamlrun 脚本头 + 魔数 T/C + 长度
ocamlobjinfo sample # 直接解析字节码可执行文件(导入单位/CRC)T + 代码区 + 各分节数据;分节名(CODE/PRIM/DATA/SYMB/CRCS 等 4 字符)与大端长度表在文件尾部 TOC,文件以 Caml1999X031 收尾(结构见 [[layout]],字节样例见 [[examples]])caml_start_program 仅 native 运行库有,是 native 特征;字节码判据用 caml_interprete)GHCziInternalziTopHandler_runMainIO1_info 难读;原因——z+小写转义特殊字符(GHC mangling:zi=. zu=下划线 zz=z zc=: zh=# 等);对策——按转义规则手工还原模块名(GHCziInternal → GHC.Internal),还原后与源码模块结构对应jmp 回函数自身地址 = 递归,按循环语义读,别找增长栈帧stg_ap_*/stg_upd_frame_info 等被当成业务逻辑分析;原因——STG 机械符号是求值机制;对策——先按 stg_/hs_ 前缀把 RTS 机械符号排除,业务代码集中在 模块_名_info 与调用 caml_applyN/caml_alloc* 的片段© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-fp-runtime of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dslsdzc/rev-skills, which our catalogue first saw on October 7, 2026.
Re Fp Runtime next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Fp Runtime this skilldslsdzc/rev-skills | 117 | 1 repos | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| TH08 Semantic ReconstructionN0zoM1z0/th08 | 100 | — | ~2.3k | Automated safety check: Pass | MIT | |
| ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime | 22k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 |
N0zoM1z0/th08
Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.
microsoft/onnxruntime
Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.
Works with
Categories
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills. Re Fp Runtime is an agent skill from dslsdzc/rev-skills.
Re Fp Runtime fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a claude-code`. Or copy the skill folder (.claude/skills/re-fp-runtime in dslsdzc/rev-skills) into .claude/skills/re-fp-runtime in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a codex`. Or copy the skill folder (.claude/skills/re-fp-runtime in dslsdzc/rev-skills) into .agents/skills/re-fp-runtime in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-fp-runtime, .gemini/skills/re-fp-runtime, .github/skills/re-fp-runtime and .opencode/skills/re-fp-runtime in your project.
Going by SKILL.md and its folder, Re Fp Runtime needs the command-line tools its instructions call (apt, brew and winget). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Fp Runtime is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Fp Runtime: TH08 Semantic Reconstruction (N0zoM1z0/th08, 100 stars), ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Code Audit (3stoneBrother/code-audit, 893 stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.