Agent skill

Re Fw Emulate

by dslsdzc in dslsdzc/rev-skills

固件仿真:QEMU 用户态/全系统. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Fw Emulate

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-fw-emulate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-fw-emulate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-fw-emulate .claude/skills/re-fw-emulate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-fw-emulate
GitHub stars
130
Token cost
~1.3k tokens
SKILL.md length
352 words
Files
3 (incl. references)
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

固件仿真:QEMU 用户态/全系统. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 用户态仿真(最轻,优先) → 全系统仿真 → 外设缺失用 stub/回环 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, dnf and brew; reaches github.com

What it does

Re Fw Emulate is an agent skill from dslsdzc/rev-skills. 固件仿真:QEMU 用户态/全系统。 触发词:仿真、QEMU、firmadyne、跑固件

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/commands.md` and `references/gotchas.md`).

It sits in Security. It works with Linux, macOS and Homebrew. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-fw-emulate”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 用户态仿真(最轻,优先)
  2. 全系统仿真
  3. 外设缺失用 stub/回环
  4. 交叉调试(qemu -g + gdb-multiarch)
  5. 网络隔离下仿真

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • brew
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Fw Emulate loads about 1.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 15 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 352 words, ~1,310 tokens.

Download SKILL.mdSave it as .claude/skills/re-fw-emulate/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-fw-emulate
description
固件仿真:QEMU 用户态/全系统。 触发词:仿真、QEMU、firmadyne、跑固件
capabilities
emulation

固件仿真(QEMU)

何时使用 / 何时不用

  • 用:需要运行固件内程序观察行为/验证假设(固件 web 界面、服务端逻辑)
  • 用:rootfs 已解出、需要整体启动(全系统仿真)
  • 不用:只需静态分析([[re-fw-rootfs]] 已覆盖)
  • 不用:有实物板子且必须真实硬件交互(走 [[re-hardware-io]],硬件提取/接口调试)
  • 不用:目标只是解包看内容(走 [[re-fw-extract]])

工具准备

所有工具先验证再使用。仿真 = 动态执行,默认沙箱 + 网络隔离([[re-analyze/platform-tips]] 最高原则);用户态仿真优先(最轻可行方案)。

qemu-user —— 用户态仿真(最轻)
  • Linux: apt install qemu-user / dnf install qemu-user / pacman -S qemu-user
  • macOS: brew install qemu(含用户态与系统态)
  • Windows/WSL: WSL 内 Linux 版
  • 验证: qemu-arm --version、qemu-mips --version(大端)、qemu-mipsel --version(小端)
qemu-system —— 全系统仿真
  • Linux: apt install qemu-system-arm qemu-system-mips / dnf install qemu-system-arm qemu-system-mips / pacman -S qemu-system-arm qemu-system-mips
  • macOS: brew install qemu
  • Windows/WSL: WSL 内 Linux 版
  • 验证: qemu-system-arm --version
binfmt_misc —— 直接执行交叉程序
  • Linux: apt install binfmt-support qemu-user-static(Debian/Ubuntu 装 qemu-user-static 即自动注册各架构 binfmt 条目;Fedora 用 systemd binfmt 配置);手动注册: update-binfmts --enable qemu-arm(或 /etc/binfmt.d/ 配置文件)
  • macOS/Windows: 不支持,用 qemu-<arch> 显式调用
  • 验证: ls /proc/sys/fs/binfmt_misc/ 可见 qemu-arm 条目;之后可直接执行 ./rootfs_out/usr/sbin/httpd
gdb-multiarch + gdbserver —— 交叉调试
  • Linux: apt install gdb-multiarch / dnf install gdb-multiarch / pacman -S gdb-multiarch;gdbserver: apt install gdbserver(或随 gdb 包提供)
  • macOS: brew install gdb(需 Developer Tools 授权,见 [[re-analyze/platform-tips]] macOS 分支)或 WSL 内 Linux 版
  • Windows/WSL: WSL 内 Linux 版
  • 验证: gdb-multiarch --version
firmadyne —— 全系统自动仿真框架(思路参考,可选装)
  • 安装: git clone https://github.com/firmadyne/firmadyne,依赖 qemu-system-* 与预编译内核(scripts/ 下下载),首次搭建较重
  • 验证: ls sources/ 有 getArch.py 等脚本;which qemu-system-mips
  • 多数单程序分析不需要它——用户态优先([[re-analyze/platform-tips]] 先给最轻可行方案)

操作步骤

按顺序执行,每步记下结果。

  1. 用户态仿真(最轻,优先):

    sh
    file rootfs_out/usr/sbin/httpd                    # 确认架构:ARM 32/64、MIPS(BE/EL)、RISC-V
    qemu-arm -L rootfs_out rootfs_out/usr/sbin/httpd  # -L 把 rootfs 当 sysroot(动态库/链接器从 rootfs 加载)
    # 大端 MIPS: qemu-mips -L rootfs_out ...
    # 小端 MIPS: qemu-mipsel -L rootfs_out ...

    缺库报错 → 交叉 ldd / readelf -d 看依赖,从 rootfs 补库;Web 服务类程序可加 -E 传环境变量。

    • -strace 记录客户程序系统调用(等效仿真内 strace——排查 mmap/ioctl 崩溃点直接用它)
    • -0 <argv0> 伪造 argv[0](程序按调用名分支时用);-cpu <型号> 指定 CPU(如 qemu-arm -cpu cortex-a9)
    • 跑不起来但静态可分析 → 回 [[re-fw-rootfs]] / [[re-binary-core]],不在仿真上死磕。
  2. 全系统仿真:

    sh
    # ARM(vexpress 平台)+ 内核与 initramfs:
    qemu-system-arm -M vexpress-a9 -kernel vmlinuz -initrd initramfs.img -nographic \
      -append "console=ttyAMA0 root=/dev/ram rdinit=/sbin/init"
    # MIPS(malta 平台,大端示例):
    qemu-system-mips -M malta -kernel vmlinuz -initrd initramfs.img -nographic \
      -append "console=ttyS0 rdinit=/sbin/init"

    把 rootfs 制作成磁盘镜像(ext2 挂 root)或 initramfs(cpio 打包 rootfs_out);firmadyne 的脚本就是自动化这套流程。 rootfs 已是磁盘镜像时直接挂盘:

    sh
    qemu-system-arm -M vexpress-a9 -kernel vmlinuz -drive file=rootfs.ext2,format=raw \
      -nographic -append "console=ttyAMA0 root=/dev/mmcblk0 rdinit=/sbin/init"

    root 设备名按平台磁盘控制器定(vexpress=mmcblk0、malta 的 IDE=/dev/sda 等,以 -M 平台文档为准)。

  3. 外设缺失用 stub/回环:

    • 用户态:程序 mmap 固定地址(GPIO/UART 寄存器)崩溃 → strace 定位访问点,LD_PRELOAD 提供 stub 库返回假寄存器值
    • 全系统:-device 挂虚拟外设(e1000 / virtio 等);真实芯片外设(wifi/基带)QEMU 无法模拟 → 打补丁跳过初始化或 stub 该 ioctl
    • 先确定程序初始化到哪一步崩(串口输出/日志),再决定 stub 哪部分
  4. 交叉调试(qemu -g + gdb-multiarch):

    sh
    qemu-arm -g 1234 -L rootfs_out rootfs_out/usr/sbin/httpd &   # -g 起 gdbstub
    gdb-multiarch rootfs_out/usr/sbin/httpd
    (gdb) target remote :1234

    全系统内:把 gdbserver 放进 rootfs,gdbserver :1234 /usr/sbin/httpd,宿主 target remote <qemu_ip>:1234;调试手法按 [[re-gdb]]。

  5. 网络隔离下仿真:

    • 用户态:不是网络沙箱(socket/connect 经 syscall 转发到宿主内核),需要受控网络时改用全系统方案
    • 全系统:QEMU 不加网络参数会默认建 NIC(e1000)+ user 后端——先显式 -nic none 确认行为,需要受控网络再加 -nic user,restrict=on(用户态 NAT,仅模拟出站)
    • 分析回连/协议前先隔离([[re-analyze/platform-tips]] 最高原则),流量抓包与协议重建转 [[re-protocol]];firmadyne 默认带网卡也需按此原则先行隔离
Show full SKILL.md (77 more words)Show less

跨域联合

  • [[re-firmware]]:工作流第 4 步固定调用本技能
  • 架构识别与指令级深挖:ARM(向量表/Thumb/MMIO 外设交叉)→ [[re-arm]];RISC-V(RV32/RV64/ecall)→ [[re-riscv]](选对 qemu-<arch> 前先对照)
  • 仿真内动态行为观察 → [[re-tracing]] + [[re-gdb]](默认沙箱内,[[re-analyze/platform-tips]] 最高原则)
  • 固件运行产生通信 → [[re-protocol]];仿真内 ELF 深挖 → [[re-binary-core]]
  • 仿真不成的程序回退静态 → [[re-fw-rootfs]]

常见坑与陷阱

  • 外设寄存器访问崩溃:现象——程序 mmap 固定地址后读 GPIO/UART 寄存器段错误;原因——QEMU 用户态不模拟外设,地址无映射;对策——strace 定位访问点,LD_PRELOAD stub 返回模拟值(步骤 3)
  • 架构选错直接 segfault:现象——qemu-arm 跑 MIPS 程序秒崩;原因——没先 file/readelf 确认架构与字节序(大端 mips ≠ mipsel);对策——步骤 1 先确认,选对 qemu-<arch>
  • 网卡型号不符 → 初始化卡死:现象——程序在网卡初始化处挂起不退出;原因——固件按特定芯片初始化,默认挂的 e1000 不匹配,ioctl 无返回;对策——按固件预期加 -device <型号> 等虚拟网卡,或先 -nic none 观察是否跳过(步骤 5)
  • 时间戳/时钟函数陷阱:现象——程序读时间怪异(1970/倒退),行为与真实设备不同;原因——QEMU 虚拟时钟与墙钟不同步;对策——-rtc base=utc 固定,或 stub 掉 clock_gettime 相关调用
  • 网络未隔离就仿真:现象——固件真实回连外网(C2/升级服务器);原因——QEMU 默认就建 NIC + user 后端(restrict=off),跳过显式隔离即联网;对策——全系统仿真显式 -nic none,用户态也非网络沙箱(步骤 5),回连分析前按 [[re-analyze/platform-tips]] 隔离
  • 命令族速查与操作序列见 [[commands]];工具特有坑与版本差异见 [[gotchas]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-fw-emulate of dslsdzc/rev-skills.

  • SKILL.md
  • references/commands.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Fw Emulate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Fw Emulate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Fw Emulate this skilldslsdzc/rev-skills130—~1.3kAutomated safety check: PassApache-2.0
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Gearcoleco Debuggingdrhelius/Gearcoleco142—~3.5kAutomated safety check: PassGPL-3.0
Ccapwysaid/CameraCapture191—~1.4kAutomated safety check: PassMIT
Install Mimi Remotegaixianggeng/mimi-remote104—~2.8kAutomated safety check: PassGPL-3.0
Env Doctorcat-xierluo/legal-skills717—~756Automated safety check: PassMIT

Similar skills

  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Gearcoleco Debugging

    drhelius/Gearcoleco

    Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.

    142 GitHub stars~3.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Ccap

    wysaid/CameraCapture

    Install or use the ccap CLI for camera capture, webcam inspection, device listing, frame capture, and video metadata.

    191 GitHub stars~1.4k tokensUpdated 3 mo ago
    MobileAuto-check passed
  • Install Mimi Remote

    gaixianggeng/mimi-remote

    安装、配置、配对、迁移、升级、诊断、回滚或卸载 Mimi Remote;在 macOS 上安装和维护 Mimi Remote Mac 菜单栏 App / DMG,或通过 Homebrew、Linux user-systemd 部署 agentd;从源码构建 iPhone/iPad App;配置 Codex 主通道和可选 Claude Code 实验 Runtime。用户提出“安装 Mimi…

    104 GitHub stars~2.8k tokensUpdated yesterday
    MobileAuto-check passed
  • Env Doctor

    cat-xierluo/legal-skills

    本机开发环境与全局包的体检、账本与安装纪律,覆盖所有包管理器(npm/npx、nvm、pip/pipx、uv、brew、bun)与运行时环境面(~/.local/bin 垫片、PATH、python 解释器版图、LaunchAgents、cron、shell rc 漂移对照)。当用户问「node/python 为什么是这个版本」「npm/pip…

    717 GitHub stars~756 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • 当用户希望把本机 Codex、ChatGPT Codex 或 Claude Code 订阅通过 localhost 暴露为 OpenAI 兼容端点,或希望在代理验证成功后把它添加成 NextClaw 自定义 provider 时使用。负责 CLIProxyAPI 安装检查、安全配置、OAuth 登录、Homebrew/systemd 持久托管、重启存活验收、NextClaw provider…

    260 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check: notes

More from dslsdzc/rev-skills

All 40 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Re Format Elf

    dslsdzc/rev-skills

    ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Re Fw Emulate

What does Re Fw Emulate do?

固件仿真:QEMU 用户态/全系统. An agent skill from dslsdzc/rev-skills. Re Fw Emulate is an agent skill from dslsdzc/rev-skills.

When should I use Re Fw Emulate?

Re Fw Emulate fits situations like: security work in your project.

How do I install Re Fw Emulate in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-fw-emulate -a claude-code`. Or copy the skill folder (.claude/skills/re-fw-emulate in dslsdzc/rev-skills) into .claude/skills/re-fw-emulate in your project. Claude Code loads it when a task matches its description.

How do I install Re Fw Emulate in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-fw-emulate -a codex`. Or copy the skill folder (.claude/skills/re-fw-emulate in dslsdzc/rev-skills) into .agents/skills/re-fw-emulate in your project. Codex loads it when a task matches its description.

Can I use Re Fw Emulate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-fw-emulate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-fw-emulate, .gemini/skills/re-fw-emulate, .github/skills/re-fw-emulate and .opencode/skills/re-fw-emulate in your project.

What does Re Fw Emulate need to run?

Going by SKILL.md and its folder, Re Fw Emulate needs the command-line tools its instructions call (apt, dnf, brew and git).

Does Re Fw Emulate access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Re Fw Emulate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Fw Emulate use?

Re Fw Emulate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Fw Emulate use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Re Fw Emulate?

Skills that share tags, products or a category with Re Fw Emulate: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Gearcoleco Debugging (drhelius/Gearcoleco, 142 stars), Ccap (wysaid/CameraCapture, 191 stars) and Install Mimi Remote (gaixianggeng/mimi-remote, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Fw Emulate?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.