Agent skill

Re Nim

by dslsdzc in dslsdzc/rev-skills

Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Nim

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-nim -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-nim --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-nim .claude/skills/re-nim && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-nim
GitHub stars
130
Token cost
~1.3k tokens
SKILL.md length
400 words
Files
3 (incl. references)
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径. An agent skill from dslsdzc/rev-skills.

  • Works in 7 steps: 产物识别 → 字符串与序列结构(先判 GC 模式) → 内存中定位字符串(动态/转储场景) → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, dnf and brew

What it does

Re Nim is an agent skill from dslsdzc/rev-skills. Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径。 触发词:Nim逆向、nim、NimString、NimMain、nim 产物。

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).

It sits in Security, covering Reverse engineering and malware. It works with C++ and Linux. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re-nim”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. 产物识别
  2. 字符串与序列结构(先判 GC 模式)
  3. 内存中定位字符串(动态/转储场景)
  4. 异常与 raises 路径
  5. GC 与引用计数(按 GC 模式分叉)
  6. C 混合编译边界
  7. stripped 产物兜底

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Nim loads about 1.3k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 22 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 400 words, ~1,289 tokens.

Download SKILL.mdSave it as .claude/skills/re-nim/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-nim
description
Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径。 触发词:Nim逆向、nim、NimString、NimMain、nim 产物。
type
atomic
capabilities
lang-runtime-analysis

Nim 逆向

何时使用 / 何时不用

  • 用:Nim 产物(NimMain / GC 符号、NimString 结构特征),需要还原字符串逻辑、异常路径、GC/所有权关系
  • 用:Nim/C 混合产物中区分 Nim 侧代码(按符号来源分组后 Nim 侧进本技能路径)
  • 不用:纯 C/C++ 产物(走 [[re-cpp-abi]] / [[re-binary-core]] 通用路径)
  • 不用:只需函数逻辑(直接反编译技能)

工具准备

readelf / llvm-nm(符号与节分析)
  • 安装与验证见 [[re-cpp-abi]] 工具准备
  • Nim 产物以 ELF 为主(Linux 默认 C 后端);macOS 用 llvm-nm
Ghidra / IDA(反编译底座)
  • 安装与验证见 [[re-ghidra]] / [[re-ida]];Nim 符号(NimMain/NimStringV2 等)导入后直接可读
nim 编译器(可选,对照编译)
  • Linux: apt install nim / dnf install nim / pacman -S nim;macOS: brew install nim;Windows: choosenim/官方安装器
  • 验证: nim -v;用途: 同版本编译对照产物,验证字符串布局/GC 符号形态(版本差异见 [[layout]])
xxd + Python struct(字节级核对)
  • 系统自带(xxd);Python 3 自带 struct
  • 用途: 符号/布局输出异常时按偏移直接解析 NimString 与对象结构(示例见 [[examples]])

操作步骤

按顺序执行,每步产物存档(路径 + sha256,见 [[re-triage]])。

  1. 产物识别:

    sh
    readelf -s sample | grep -iE 'NimMain|nimGC|NimString' | head   # ELF;Mach-O 用 llvm-nm
    readelf -s sample | grep -iE 'nimIncRef|nimDecRef|rawNewString|eqStrings' | head
    • Nim 特征:NimMain(入口链)、GC 符号(refc 的 nimGC_* / orc 的 nimIncRefCyclic 等)、NimStringV2/NimStringDesc 结构类型
    • 注意:release 构建下 GC 符号常被内联/消除(见坑 1),靠 NimMain 与字符串函数兜底
    • 入口链:C main → NimMain → NimMainInner → NimMainModule(模块初始化)→ 业务 main
    • 模块初始化顺序按依赖拓扑(import 关系):NimMainModule 内的初始化段先跑被依赖模块——在初始化段断点/下钻时按调用序对照 import 链
  2. 字符串与序列结构(先判 GC 模式):

    • orc/arc(2.x 默认 orc):NimStringV2 = {len: int, p: ptr NimStrPayload};NimStrPayload = {cap: int, data: 内联字符数组}——字符串是"len + 堆上 payload 指针",cap 高位带字面量标记位(见 [[layout]])
    • refc(旧默认):NimStringDesc = {len, reserved, data[]}——字符内联在结构体里
    • 定位:rawNewString(1.x 与 2.x 均为此 importc 名)分配调用点 → 结构布局 → 字符串操作函数(eqStrings 等)
    • 分析:字符串比较点是关键逻辑(校验/协议/命令分发)——eqStrings 调用点即字符串相等判断
    • 序列(seq)与 string 同构:v2 布局同为 len + payload 指针(payload 带 cap),refc 同为 len/reserved + 内联——按同一判别表处理
    • 内存视图(v2 布局,64 位):
      栈/对象内:  len(int64) | p(ptr) ───────────────┐
      堆上 payload:  cap(int64, bit62=字面量标记) | data[cap+1] ←┘
      字符串本体只有 16 字节句柄,内容在独立堆块——分析对象结构时按句柄跳转,别在对象里找字符数据
  3. 内存中定位字符串(动态/转储场景):

    python
    # 在内存转储中按 v2 布局找字符串:cap 是 8 字节对齐的容量值,data 后跟可打印 ASCII
    # 候选: 8 字节对齐的 cap + len 匹配的 data → 反推 NimStringV2 起点

    字符串内容在堆上 payload 里,栈上只有 len+指针;先按 cap 前缀特征定位 payload,再往回找引用它的 NimStringV2([[examples]] 有完整示例)。

  4. 异常与 raises 路径:

    • Nim 2.2.x(Linux x86-64 默认)异常走 goto 式异常表,无 setjmp 符号;raise 路径经 raiseExceptionEx/raiseExceptionAux
    • 老默认(--exceptions:setjmp,Nim 2.0 及以前)用 setjmp/longjmp:nimSetjmp 符号可见
    • 定位:raiseExceptionEx 调用点 → 异常对象分配与消息 → catch 分支(异常表驱动)
    • 分析:异常路径揭示输入校验与失败处理,比正常路径更早暴露边界条件
  5. GC 与引用计数(按 GC 模式分叉):

    • refc:引用计数 + 周期收集——nimGC_*/nimGCunref/nimIncRef/nimDecRef 调用点
    • orc/arc:ARC 语义——nimIncRefCyclic/nimDecRefIsLastCyclicDyn 等;显式 inc/dec 少,释放由编译期插入
    • 分析:GC 调用点帮助识别对象生命周期与所有权(配合字符串结构);release 下内联后改用分配/释放边界推断
  6. C 混合编译边界:

    • {.compile:} / {.importc:} 混合时 Nim 与 C 符号并存:Nim 侧符号带模块前缀(hello__u8 形态)与运行时(NimMain/NimString),C 侧符号无
    • 边界处是逻辑入口:Nim 业务逻辑在 NimMain 调用链内侧,C 库调用经导入表
  7. stripped 产物兜底:

    sh
    strings -n 6 sample | grep -E '@m.*\.nim\.c' | head      # C 生成缓存文件名(含模块名,release 也嵌入)
    strings -n 6 sample | grep -iE 'fatal\.nim|Exception' | head
    • NimMain 等被 strip 后按特征串(@m<模块>.nim.c、std 运行时源文件名)与运行时行为识别([[re-triage]] 初勘兜底);业务源码名不嵌入二进制,别指望它
Show full SKILL.md (146 more words)Show less

跨域联合

  • [[re-binary-core]] 网关:本技能归属(选择树「Nim 产物」分支)
  • [[re-analyze/analysis-contract]]:符号表按数据契约传递
  • [[re-cpp-abi]]:C 混合侧与无 RTTI 判别参考
  • [[re-triage]]:初勘兜底(strip 产物按特征串识别)

常见坑与陷阱

  • GC 版本差异(refc/orc):现象——找不到引用计数调用;原因——orc 无显式 inc/dec(ARC 语义)且 release 下 GC 符号内联;对策——先按 Nim 版本与 GC 模式确认再分析,debug/refc 构建符号更全
  • NimString 布局随 GC/版本变化:现象——按 len/reserved/data 手写解析器读 2.x 产物全错;原因——2.x orc 默认是 NimStringV2{len, p}(payload 带 cap),len/reserved/data 内联是 refc 的 NimStringDesc(1.x 默认);对策——先确认产物 GC 模式(见 [[layout]] 判别表)再选布局:debug 构建看 GC 符号(refc 有 nimGCunref,orc 有 nimIncRefCyclic),release 构建看分配函数命名与 cap 字段是否出现
  • 导出符号被 strip:现象——无 NimMain/NimString 符号;原因——strip 处理;对策——按特征字符串/运行时行为识别(步骤 6 兜底)
  • C 混合编译:现象——Nim/C 符号混杂;原因——{.compile:} 混合;对策——按符号来源分组,Nim 侧进本技能路径
  • 字符串比较点误判:现象——关键校验被当普通比较;原因——eqStrings 包装;对策——追踪 Nim 字符串函数调用点定位比较逻辑
  • 异常实现代际误判:现象——按老思路找 nimSetjmp 找不到;原因——2.2+ Linux amd64 默认 goto 式异常(无 setjmp);对策——无 nimSetjmp 时沿 raiseExceptionEx 与异常表定位 catch,别当"无异常处理"
  • release 内联导致符号稀疏:现象——debug 能看到的 nimGC_*/eqStrings 在 release 里消失;原因——-d:release 内联;对策——release 产物按行为特征(分配/释放边界、字符串函数调用模式)分析,符号表只是线索不是依据
  • 字符串内容在堆上,栈上只有句柄:现象——在栈上按内容搜索字符串找不到;原因——v2 布局的字符数据在独立 payload 堆块里,栈上只有 len + p 两个字段;对策——动态/转储场景先按 cap 前缀特征定位 payload 块,再回找引用它的句柄([[examples]] 内存定位示例)
  • 32 位产物结构尺寸减半:现象——64 位布局表套 32 位产物偏移全错;原因——NI 在 32 位平台是 4 字节(NimStringV2 为 8 字节而非 16,NimStrPayload cap 为 4 字节);对策——解析前先确认产物位数,按 4/8 字节 NI 选结构尺寸
  • 非 PIE 老构建入口即固定地址:现象——readelf -h 的 e_entry 是绝对地址(如 0x401xxx),在内存里直接对得上;原因——非 PIE 构建(老默认);对策——入口链定位用符号(NimMain 三连)不依赖 PIE 与否,但换算地址时按 e_type 区分

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-nim of dslsdzc/rev-skills.

  • SKILL.md
  • references/examples.md
  • references/layout.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Nim next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Nim compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Nim this skilldslsdzc/rev-skills130—~1.3kAutomated safety check: PassApache-2.0
Analyzing Linux Elf Malwaremukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: WarnApache-2.0
Memory Forensics Volatilityyaklang/hack-skills2.4k—~2.5kAutomated safety check: PassMIT
ONNX Runtime Source Buildmicrosoft/onnxruntime22k—~1.4kAutomated safety check: PassMIT
JS Cpp Protocolnotepadqq/notepadqq2.3k—~3.2kAutomated safety check: PassGPL-3.0
Rsid SDKrealsenseai/RealSenseID122—~4.1kAutomated safety check: PassApache-2.0

Similar skills

  • Analyzing Linux Elf Malware

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Memory Forensics Volatility

    yaklang/hack-skills

    Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.5k tokensUpdated 26 days ago
    SecurityAuto-check passed
  • ONNX Runtime Source Build

    microsoft/onnxruntime

    Official

    Builds ONNX Runtime from source with its build scripts, explaining the update, build and test phases, key flags and where the build output lands.

    22k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • JS Cpp Protocol

    notepadqq/notepadqq

    Reference for the communication protocol between the JavaScript editor (CodeMirror or Monaco) and the C++/Qt UI layer via QWebChannel.

    2.3k GitHub stars~3.2k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Rsid SDK

    realsenseai/RealSenseID

    RealSenseID face authentication SDK reference. An agent skill from realsenseai/RealSenseID.

    122 GitHub stars~4.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Xilinx Suite

    QingquanYao/xilinx-skill

    Xilinx 全工具链综合助手,覆盖从零到一的完整 FPGA/MPSoC 工程构建,包括: - Vivado:硬件设计、Block Design、IP 配置、XDC 约束、综合实现、比特流生成 - Vitis HLS:C/C++ 高层次综合,生成自定义 IP 核 - Vitis Unified IDE(2022.x+):嵌入式软件开发,Platform/Domain/Application…

    463 GitHub stars~1.5k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from dslsdzc/rev-skills

All 40 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Re Format Elf

    dslsdzc/rev-skills

    ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Re Nim

What does Re Nim do?

Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径. An agent skill from dslsdzc/rev-skills. Re Nim is an agent skill from dslsdzc/rev-skills.

When should I use Re Nim?

Re Nim fits situations like: tasks that involve Reverse engineering and malware.

How do I install Re Nim in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-nim -a claude-code`. Or copy the skill folder (.claude/skills/re-nim in dslsdzc/rev-skills) into .claude/skills/re-nim in your project. Claude Code loads it when a task matches its description.

How do I install Re Nim in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-nim -a codex`. Or copy the skill folder (.claude/skills/re-nim in dslsdzc/rev-skills) into .agents/skills/re-nim in your project. Codex loads it when a task matches its description.

Can I use Re Nim in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-nim -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-nim, .gemini/skills/re-nim, .github/skills/re-nim and .opencode/skills/re-nim in your project.

What does Re Nim need to run?

Going by SKILL.md and its folder, Re Nim needs the command-line tools its instructions call (apt, dnf and brew). Our summary lists: Python 3.

Does Re Nim access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Nim safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Nim use?

Re Nim is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Nim use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Re Nim?

Skills that share tags, products or a category with Re Nim: Analyzing Linux Elf Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Memory Forensics Volatility (yaklang/hack-skills, 2.4k stars), ONNX Runtime Source Build (microsoft/onnxruntime, 22k stars) and JS Cpp Protocol (notepadqq/notepadqq, 2.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Nim?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.