Agent skill

Re Lldb

by dslsdzc in dslsdzc/rev-skills

lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check: notesSecurity

Install Re Lldb

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-lldb -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-lldb --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-lldb .claude/skills/re-lldb && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-lldb
GitHub stars
125
Token cost
~1.3k tokens
SKILL.md length
300 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills.

  • Works in 8 steps: Developer Tools 权限确认 → attach/启动 → image lookup 符号 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, dnf and brew

What it does

Re Lldb is an agent skill from dslsdzc/rev-skills. lldb 调试(macOS/iOS):attach、expr、image。 触发词:lldb、macOS调试、iOS调试

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/commands.md` and `references/gotchas.md`).

It sits in Security. It works with iOS, macOS, Xcode and Linux. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-lldb”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Developer Tools 权限确认
  2. attach/启动
  3. image lookup 符号
  4. 内存表达式 expr
  5. 断点与脚本
  6. 单步/栈/线程
  7. 内存搜索与区域
  8. 证据核对(收尾):断点命中记录、frame variable/expr 输出、memory read 转储(memory read --force -o 文件 导出)对照 [[re-triage]] 初勘值入档,结论写…

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Lldb loads about 1.3k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 17 tokens; SKILL.md has 300 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:34
    - 旧系统: `sudo DevToolsSecurity -enable`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 300 words, ~1,258 tokens.

Download SKILL.mdSave it as .claude/skills/re-lldb/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-lldb
description
lldb 调试(macOS/iOS):attach、expr、image。 触发词:lldb、macOS调试、iOS调试
capabilities
debugging

lldb 动态调试(macOS/iOS)

何时使用 / 何时不用

  • 用:macOS/iOS 目标动态调试(attach/启动/断点/表达式求值/符号查找)
  • 用:Linux 上调试带 DWARF 的调试版程序(lldb 与 clang 工具链同源,DWARF 处理成熟)
  • 不用:Linux 目标([[re-gdb]])、Windows 目标([[re-x64dbg]])
  • 不用:iOS 越狱/证书环境问题(属 [[re-mobile]] 域);只读内存([[re-memdump]] 默认转储优先)
  • 不用:脚本化大批量内存转储/取证([[re-memdump]] / [[re-mem-forensics]] 更对口)

工具准备

参考 [[re-analyze/platform-tips]] macOS 分支——SIP 与 TCC 限制 attach,需 Developer Tools 授权。

lldb
  • macOS: 自带(Xcode Command Line Tools: xcode-select --install)
  • Linux: apt install lldb / dnf install lldb / pacman -S lldb
  • macOS 更全: brew install llvm(含新版 lldb)
  • 验证: lldb --version
  • 版本差异: Xcode 自带 lldb、llvm.org 的 lldb、Swift 工具链 lldb 功能近似但版本号不同(lldb --version 确认);脚本依赖 lldb.SBDebugger API 时跨版本兼容性需验证(见 [[gotchas]])
SIP 关闭或授权(attach 前置)
  • 系统设置 > 隐私与安全性 > 开发者工具 > 授权使用 lldb 的终端(TCC 授权)
  • 旧系统: sudo DevToolsSecurity -enable
  • 说明: 一般不要关 SIP(可只对调试需求临时处理);iOS 内核级调试需 KDK/开发内核,属 [[re-mobile]] 域

操作步骤

  1. Developer Tools 权限确认:

    sh
    lldb -p <测试进程pid>   # 若报 "please check the developer mode" / 权限拒绝 → 去系统设置授权终端

    授权后重启终端;仍失败再检查 SIP 状态: csrutil status。 注意: TCC 授权弹窗需在系统设置手动确认,无法命令行绕过。

  2. attach/启动:

    (lldb) process attach --pid <pid>     # 附加
    (lldb) process attach --name Safari   # 按名字附加(需唯一)
    (lldb) target create ./sample         # 或直接启动
    (lldb) run --args arg1
    (lldb) continue / c

    iOS 设备: platform select remote-ios + process connect connect://<device>(需配合调试服务,越狱/证书要求见 [[re-mobile]])

    • attach 时机注意: 目标已运行过初始化逻辑,入口前行为看不到——需要从入口看就 target create + run 启动模式
    • 启动停在入口: process launch --stop-at-entry(等价 -s)
  3. image lookup 符号:

    (lldb) image lookup -n main            # 按名字查符号
    (lldb) image lookup -a $pc             # 按地址查当前所在函数/源行
    (lldb) image list                      # 已加载镜像(dylib 基址表)
    (lldb) image lookup -rn dispatch       # 正则匹配符号

    stripped 二进制用 image lookup -a 反查地址归属模块,配合 image dump symtab

    • 模块基址: image list -o 加偏移列——ASLR 下每次运行基址不同,脚本里先拿基址再算绝对地址(见 [[gotchas]])
  4. 内存表达式 expr:

    (lldb) expr $rax
    (lldb) expr $rax = 0                   # 写寄存器
    (lldb) expr (char*)0x100000000         # 类型化读地址
    (lldb) expr -O -- @"hello"             # Objective-C 求值(objc 运行时)
    (lldb) memory read -c 20 -s 4 -f x $rsp     # 读内存(缺 -f x 会报格式冲突错误)
    (lldb) memory write -s 1 0x100000000 0x90  # 写字节(绕过校验)
    • 表达式求值有副作用(会执行代码)——别在敏感路径上乱求值,见 [[gotchas]]
  5. 断点与脚本:

    (lldb) breakpoint set -n main
    (lldb) breakpoint set -a 0x100004000 -c '*(int*)($rsp) == 0x1234'   # 条件断点
    (lldb) breakpoint command add 1
    > frame variable
    > expr $rax
    > continue
    > DONE

    Python 自动化: lldb 内置 Python——script import lldb,或用 lldb -s script.lldb 批处理。

    • 符号断点: breakpoint set -n objc_msgSend(按符号名,模块加载后自动生效);正则: -r '^check_'
    • 断点管理: breakpoint list / breakpoint delete / breakpoint disable 1
  6. 单步/栈/线程:

    (lldb) thread step-over / step-into / step-out   # 步过/步入/出函数(别名 next/step/finish)
    (lldb) thread backtrace                          # 当前线程栈(别名 bt)
    (lldb) thread list                               # 全部线程
    (lldb) frame select 1                            # 切栈帧
    (lldb) frame variable                            # 当前帧局部变量
    (lldb) register read                             # 全部寄存器
    • 单步跳过 call 后的 step-out 配合返回寄存器看结果,是「验证函数返回」最快路径
  7. 内存搜索与区域:

    (lldb) memory find 0x100000000 0x101000000 -e 0xdeadbeef   # 区间内搜值/字节串
    (lldb) memory find -s "password" 0x100000000 0x101000000   # 搜字符串
    (lldb) memory region 0x100004000                           # 该地址所属区域权限/边界
    • 找密钥/常量: 先 memory find 定位,再断写入点;区域权限(RWX)异常段先看(壳/解密段)
  8. 证据核对(收尾):断点命中记录、frame variable/expr 输出、memory read 转储(memory read --force -o 文件 导出)对照 [[re-triage]] 初勘值入档,结论写 [[re-analyze/analysis-contract]]

Show full SKILL.md (83 more words)Show less

跨域联合

  • [[re-binary-core]]:工作流第 6 步(macOS/iOS 调试器)
  • [[re-mobile]]:iOS App/越狱动态调试的底层工具
  • [[re-format-macho]]:先解析结构再调试(入口/LC_MAIN 与签名状态)
  • attach 失败时按 [[re-analyze/platform-tips]] 转 [[re-memdump]]

常见坑与陷阱

  • SIP/TCC 拦截 attach:非授权终端 attach 被拒(permission denied 或静默失败)——去系统设置开发者工具授权;关闭 SIP 只在极端情况
  • 权限弹窗需手动确认:TCC 每次对新的调试目标弹窗,脚本化 attach 会被卡住——预先授权目标程序
  • 内核调试需额外配置:macOS 内核调试要 KDK 匹配版本 + 开发内核启动,普通逆向用不上,别在用户态调试上浪费时间
  • 签名状态: 修改过的 Mach-O 未重签无法运行(见 [[re-format-macho]])——先 codesign -f -s - 重签再调试
  • task_for_pid entitlement/SIP/Hardened Runtime 三层限制:现象——Developer Tools 已授权仍 attach 失败或目标启动即崩溃;原因——除 TCC 外还有三层:调试器需 task_for_pid entitlement,目标启用 Hardened Runtime 时调试 API 受限,SIP 限制系统进程 attach;对策——逐层排查(csrutil status、检查目标签名与 entitlement),测试目标可先去签名/重签([[re-format-macho]])再调试,参考 [[re-analyze/platform-tips]] macOS 分支
  • ASLR 基址漂移:每次启动 dylib 基址不同——脚本里硬编码地址会失效;用 image list -o 拿基址换算,断点尽量下符号名(-n/-s)
  • 表达式求值有副作用:expr 会真实执行代码(调用函数/改内存)——在 hook 点求值可能改变目标行为,验证场景用 frame variable 只读优先
  • 版本差异、调试服务器与边界见 [[gotchas]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-lldb of dslsdzc/rev-skills.

  • SKILL.md
  • references/commands.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Lldb next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Lldb compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Lldb this skilldslsdzc/rev-skills125—~1.3kAutomated safety check: NotesApache-2.0
OdevioOdevio/Odevio-CLI423—~7.6kAutomated safety check: PassMIT
Limrun Xcodesuperset-sh/superset15k—~6.5kAutomated safety check: NotesCustom licence
Eas Simulatorexpo/skills2.7k—~6.6kAutomated safety check: NotesMIT
Audit Skillssickn33/agentic-awesome-skills47k2 repos~1.6kAutomated safety check: WarnMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause

Similar skills

  • Odevio

    Odevio/Odevio-CLI

    Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.

    423 GitHub stars~7.6k tokensUpdated 14 days ago
    MobileAuto-check passed
  • Limrun Xcode

    superset-sh/superset

    Build an iOS / Apple app on remote Xcode with lim xcode build instead of local xcodebuild, run project commands with lim xcode run, or run its XCTest suites with lim xcode test, from any environment…

    15k GitHub stars~6.5k tokensUpdated today
    MobileAuto-check: notes
  • Eas Simulator

    expo/skills

    Official

    Run and control a user's app on a remote iOS/Android simulator hosted on EAS cloud.

    2.7k GitHub stars~6.6k tokensUpdated yesterday
    MobileAuto-check: notes
  • Audit Skills

    sickn33/agentic-awesome-skills

    Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~1.6k tokens
    SecurityAuto-check: warnings
  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…

    87k GitHub starsUsed in 1 repo~584 tokens
    MobileAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    125 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Re Lldb

What does Re Lldb do?

lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills. Re Lldb is an agent skill from dslsdzc/rev-skills.

When should I use Re Lldb?

Re Lldb fits situations like: security work in your project.

How do I install Re Lldb in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-lldb -a claude-code`. Or copy the skill folder (.claude/skills/re-lldb in dslsdzc/rev-skills) into .claude/skills/re-lldb in your project. Claude Code loads it when a task matches its description.

How do I install Re Lldb in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-lldb -a codex`. Or copy the skill folder (.claude/skills/re-lldb in dslsdzc/rev-skills) into .agents/skills/re-lldb in your project. Codex loads it when a task matches its description.

Can I use Re Lldb in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-lldb -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-lldb, .gemini/skills/re-lldb, .github/skills/re-lldb and .opencode/skills/re-lldb in your project.

What does Re Lldb need to run?

Going by SKILL.md and its folder, Re Lldb needs the command-line tools its instructions call (apt, dnf and brew). Our summary lists: Python 3.

Does Re Lldb access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Lldb safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Re Lldb use?

Re Lldb is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Lldb use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Re Lldb?

Skills that share tags, products or a category with Re Lldb: Odevio (Odevio/Odevio-CLI, 423 stars), Limrun Xcode (superset-sh/superset, 15k stars), Eas Simulator (expo/skills, 2.7k stars) and Audit Skills (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Lldb?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.