Agent skill

Re Fp Runtime

by dslsdzc in dslsdzc/rev-skills

函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Fp Runtime

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-fp-runtime --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-fp-runtime .claude/skills/re-fp-runtime && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-fp-runtime
GitHub stars
117
Used in
1 other repo
Token cost
~1.4k tokens
SKILL.md length
394 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 运行时识别 → 闭包与堆对象 → 调用约定 → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, brew and winget

What it does

Re Fp Runtime is an agent skill from dslsdzc/rev-skills. 函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略。 触发词:Haskell逆向、OCaml逆向、GHC RTS、thunk、STG、OCaml runtime、闭包、函数式产物。

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).

It sits in Security, covering Reverse engineering and malware. It works with C++. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re-fp-runtime”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 运行时识别
  2. 闭包与堆对象
  3. 调用约定
  4. 分析策略(数据流优先)
  5. 字节码产物(OCaml 特有)

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • brew
    • winget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Fp Runtime loads about 1.4k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 394 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 394 words, ~1,430 tokens.

Download SKILL.mdSave it as .claude/skills/re-fp-runtime/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-fp-runtime
description
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略。 触发词:Haskell逆向、OCaml逆向、GHC RTS、thunk、STG、OCaml runtime、闭包、函数式产物。
type
atomic
capabilities
lang-runtime-analysis

函数式运行时逆向(Haskell / OCaml)

何时使用 / 何时不用

  • 用:Haskell/OCaml 产物(GHC RTS 符号、OCaml block 头特征),需要还原闭包/堆对象、求值顺序、模式匹配分支
  • 用:OCaml 原生/字节码产物判别与字节码分析(ocamlrun 脚本头特征)
  • 不用:命令式语言产物(各归各技能:C++ → [[re-cpp-abi]]、Go → [[re-go]]、Rust → [[re-rust]])
  • 不用:只需函数逻辑且控制流完整(函数式产物控制流打散,直接反编译收益低,见步骤 4)

工具准备

readelf / llvm-nm(符号分析)
  • 安装与验证见 [[re-cpp-abi]] 工具准备
ghc 工具链(Haskell 侧,可选)
  • Linux/macOS: GHC 安装包(apt install ghc / brew install ghc / ghcup);Windows: ghcup(winget install ghcup 或官网安装器);验证: ghc --version
  • 用途: 同版本编译对照产物,验证 closure/info table 形态(GHC 版本差异大)
ocamlobjinfo / ocamlopt(OCaml 侧,可选)
  • Linux/macOS: OCaml 工具链(apt install ocaml / brew install ocaml);Windows: opam(winget install OCaml.opam)或官网安装器;验证: ocamlobjinfo 处理任意 .cmx 输出 CRC 与导入表
  • 用途: 字节码产物/对象文件结构分析(ocamlobjinfo 可读 .cmo/.cmx/字节码可执行文件)
Ghidra / IDA(反编译底座)
  • 安装与验证见 [[re-ghidra]] / [[re-ida]]
file / xxd / Python struct(字节级核对)
  • 系统自带(file/xxd);Python 3 自带 struct
  • 用途: 字节码产物判别(ocamlrun 脚本头)、closure 首字段/block 头字节验证(示例见 [[examples]])

操作步骤

按顺序执行;逆向着重数据流而非控制流(函数式产物控制流被打散,见坑 4)。每步产物存档(路径 + sha256,见 [[re-triage]])。

  1. 运行时识别:

    sh
    readelf -s sample | grep -iE 'ghc|stg_|RTS|HsMain|_closure|_info' | head   # GHC 特征
    readelf -s sample | grep -iE 'caml_' | head                                # OCaml 特征
    file sample                                                              # 字节码产物判别(脚本头)
    • GHC:main(C RTS 入口)+ RTS 运行时符号(stg_*/hs_*)+ 业务符号 Main_main_closure/Main_main_info(模块_名字_closure/info 形态)
    • OCaml 原生:main → caml_main → caml_startup_common → caml_start_program → caml<模块>__entry;caml_startup/caml_startup_pooled 是供 C 嵌入调用的等价入口(签名同为 void (char_os **argv),区别在 pooling 标志与异常行为),勿误当主链;caml_* 运行时符号(caml_alloc/caml_apply2/3 等)
    • 字节码 vs 原生:caml_start_program 仅存在于 native 运行库(4.14.2 libasmrun.a 实测),是 native 特征;字节码判据用 caml_interprete(仅 libcamlrun.a 有);字节码产物判别用 file(ocamlrun script executable)/xxd 头(#!...ocamlrun\n 脚本头 + T/C 魔数 + 分节)
    • 入口链各版本一致:runtime/main.c 定义 main 并调用 caml_main(argv)(caml_main 定义于 startup_byt.c/startup_nat.c;原生链 main → caml_main → caml_startup_common → caml_start_program,4.14.2 实测地址见 [[examples]]);字节码运行库入口为 caml_main → caml_startup_aux → caml_interprete
    • 判别速查:GHC = stg_* 机械符号群 + 模块_名_closure/info 对;OCaml 原生 = caml_* 群 + caml<模块>__<名>_<id>;OCaml 字节码 = #!ocamlrun 脚本头
  2. 闭包与堆对象:

    • GHC:thunk(未求值闭包)与已求值值的堆对象布局——closure 首字段即 info table 指针(实测字节验证见 [[examples]]);CAF 以 thunk 形式静态分配,首次引用才求值(惰性);Main_main_closure 是 CAF,其 info 指向 thunk 求值代码
    • GHC 值形态:未求值(thunk,info 指向求值代码)vs 已求值 WHNF(info 指向构造器头/函数头)——同地址空间的两种状态,求值后 closure 内容被覆写
    • OCaml:block 头(tag + 大小,64 位下 header = (size<<10)|(color<<8)|tag);tagged int 判定用值的最低位(bit 0,奇数=整数,偶数=指针/block)
    • 分析:字段与构造器是主要线索(数据流优先)
  3. 调用约定:

    • GHC:参数经栈传递;返回值在寄存器 R1-R3(盒值在 R1);entry 代码以 info table 为枢纽(_info 符号 = entry code)
    • OCaml:参数经寄存器(前 N 个)传递,闭包调用经 caml_applyN;原生代码调用闭包 = 寄存器装载 + caml_apply2/3 或直接跳 entry
    • 分析:先识别运行时包装(caml_apply / stg 入口)再进用户逻辑;尾调用优化使递归变跳转(无增长栈帧),按循环读
    • GHC 与 OCaml 共点:函数不是"被 call",而是"跳到 entry"——反编译里的 jmp 目标地址即函数入口,别按 call/ret 配对思维读
  4. 分析策略(数据流优先):

    • 控制流打散:惰性求值导致求值顺序不可预测——静态控制流分析价值低
    • 数据流线索:闭包字段初始化点(构造器参数)、模式匹配分支(构造器标签分发)、字符串/常量引用
    • 产出:数据流图(构造器 → 字段 → 使用点)替代控制流图(与 [[re-analyze/analysis-contract]] 数据契约衔接)
    • 模式匹配还原:分支按构造器 tag 分发(OCaml)或 info 表指针比较(GHC)——tag/指针值 → 构造器序号;还原出构造器集合即还原出数据类型
    • 产出格式(供分析报告与下一环节消费):
      构造器 C1 (tag 0, 2 字段) ← 分配点 A (caml_alloc2 / info 表)
        字段0 ← 函数参数/常量(数据来源)
        字段1 ← 字符串池引用
      使用点: tag 比较 → 分支 B(业务逻辑)
  5. 字节码产物(OCaml 特有):

    sh
    head -c 64 sample | xxd          # #!...ocamlrun 脚本头 + 魔数 T/C + 长度
    ocamlobjinfo sample              # 直接解析字节码可执行文件(导入单位/CRC)
    • 字节码 exe = 脚本头 + 魔数 T + 代码区 + 各分节数据;分节名(CODE/PRIM/DATA/SYMB/CRCS 等 4 字符)与大端长度表在文件尾部 TOC,文件以 Caml1999X031 收尾(结构见 [[layout]],字节样例见 [[examples]])
    • 字节码反汇编不是常规反编译(指令集为 OCaml bytecode 自定),分析入口用 ocamlobjinfo 的结构视图
Show full SKILL.md (94 more words)Show less

跨域联合

  • [[re-binary-core]] 网关:本技能归属(选择树「Haskell/OCaml 产物」分支)
  • [[re-analyze/analysis-contract]]:数据流图按数据契约传递
  • [[re-cpp-abi]]:vtable/info table 对照思路(表指针分派同构)

常见坑与陷阱

  • RTS 版本差异:现象——closure 布局解读失败;原因——GHC/OCaml 版本演进;对策——按目标版本确认布局(本技能字段表基于 9.14/4.14 实测,见 [[layout]])
  • thunk 惰性求值误导:现象——未求值闭包被当已求值数据;原因——惰性求值;对策——区分 thunk 头(info 指向求值代码)与已求值值(info 指向 WHNF 头);CAF 首引用前都是 thunk
  • OCaml 字节码非 native:现象——反编译全是运行时包装;原因——字节码产物;对策——识别 ocamlrun 脚本头/字节码段特征后按字节码结构分析(非常规反编译;caml_start_program 仅 native 运行库有,是 native 特征;字节码判据用 caml_interprete)
  • 控制流打散导致静态分析失效:现象——函数体无连续逻辑;原因——函数式编译产物;对策——转数据流分析(步骤 4),不硬追控制流
  • tagged int 误读:现象——整数被当指针/指针被当整数;原因——OCaml 值标记位;对策——按最低位区分(1=整数,0=指针),访问前先解标记(int >> 1 取真值)
  • GHC 模块名带 z 编码:现象——符号 GHCziInternalziTopHandler_runMainIO1_info 难读;原因——z+小写转义特殊字符(GHC mangling:zi=. zu=下划线 zz=z zc=: zh=# 等);对策——按转义规则手工还原模块名(GHCziInternal → GHC.Internal),还原后与源码模块结构对应
  • info table 与 entry code 是同一指针的两个视图:现象——info 指针处反汇编出的是字段表数据而非代码;原因——info table 指针指向 entry code,表字段在 entry code 之前;对策——反汇编从 info 指针处开始(即 entry),字段表按负偏移读
  • 尾调用优化把递归变跳转:现象——按 call 树分析递归逻辑断裂;原因——函数式编译器的尾调用优化(TCO);对策——jmp 回函数自身地址 = 递归,按循环语义读,别找增长栈帧
  • 惰性求值顺序不可预测:现象——按源码顺序单步动态分析对不上;原因——thunk 首次引用才求值,求值触发点在"需要值的地方"而非"产生值的地方";对策——动态分析聚焦数据依赖(哪个闭包被强制求值),静态聚焦字段初始化点,别假设执行顺序
  • 跨运行时误判(GHC 机械符号当业务代码):现象——stg_ap_*/stg_upd_frame_info 等被当成业务逻辑分析;原因——STG 机械符号是求值机制;对策——先按 stg_/hs_ 前缀把 RTS 机械符号排除,业务代码集中在 模块_名_info 与调用 caml_applyN/caml_alloc* 的片段

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-fp-runtime of dslsdzc/rev-skills.

  • SKILL.md
  • references/examples.md
  • references/layout.md

Open the folder on GitHubat commit bd21db8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dslsdzc/rev-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Re Fp Runtime next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Fp Runtime compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Fp Runtime this skilldslsdzc/rev-skills1171 repos~1.4kAutomated safety check: PassApache-2.0
TH08 Semantic ReconstructionN0zoM1z0/th08100—~2.3kAutomated safety check: PassMIT
ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime22k—~3.3kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.

    100 GitHub stars~2.3k tokensUpdated 18 days ago
    DevelopmentAuto-check passed
  • Official

    Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

    22k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    935 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Re Cpp Abi

    dslsdzc/rev-skills

    现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~996 tokens
    Auto-check passed

Works with

Categories

Questions about Re Fp Runtime

What does Re Fp Runtime do?

函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills. Re Fp Runtime is an agent skill from dslsdzc/rev-skills.

When should I use Re Fp Runtime?

Re Fp Runtime fits situations like: tasks that involve Reverse engineering and malware.

How do I install Re Fp Runtime in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a claude-code`. Or copy the skill folder (.claude/skills/re-fp-runtime in dslsdzc/rev-skills) into .claude/skills/re-fp-runtime in your project. Claude Code loads it when a task matches its description.

How do I install Re Fp Runtime in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a codex`. Or copy the skill folder (.claude/skills/re-fp-runtime in dslsdzc/rev-skills) into .agents/skills/re-fp-runtime in your project. Codex loads it when a task matches its description.

Can I use Re Fp Runtime in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-fp-runtime -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-fp-runtime, .gemini/skills/re-fp-runtime, .github/skills/re-fp-runtime and .opencode/skills/re-fp-runtime in your project.

What does Re Fp Runtime need to run?

Going by SKILL.md and its folder, Re Fp Runtime needs the command-line tools its instructions call (apt, brew and winget). Our summary lists: Python 3.

Does Re Fp Runtime access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Fp Runtime safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Fp Runtime use?

Re Fp Runtime is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Fp Runtime use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Re Fp Runtime?

Skills that share tags, products or a category with Re Fp Runtime: TH08 Semantic Reconstruction (N0zoM1z0/th08, 100 stars), ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Code Audit (3stoneBrother/code-audit, 893 stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Fp Runtime?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.