Agent skill

Re Stego

by dslsdzc in dslsdzc/rev-skills

隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Stego

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-stego -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-stego --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-stego .claude/skills/re-stego && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-stego
GitHub stars
130
Token cost
~1.2k tokens
SKILL.md length
308 words
Files
3 (incl. references)
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证. An agent skill from dslsdzc/rev-skills.

  • Works in 4 steps: 文件尾附加检测 → 图片 LSB → 其他载体 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, brew and gem

What it does

Re Stego is an agent skill from dslsdzc/rev-skills. 隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证。 触发词:隐写、stego、LSB、文件尾附加、隐写提取、图片隐写。

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/decision-tree.md` and `references/gotchas.md`).

It sits in Security. It works with Python, Homebrew, Linux and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-stego”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 文件尾附加检测
  2. 图片 LSB
  3. 其他载体
  4. 提取验证

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • brew
    • gem
    • dnf
    • java
    • pip
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Stego loads about 1.2k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 20 tokens; SKILL.md has 308 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 308 words, ~1,190 tokens.

Download SKILL.mdSave it as .claude/skills/re-stego/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-stego
description
隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证。 触发词:隐写、stego、LSB、文件尾附加、隐写提取、图片隐写。
type
atomic
capabilities
stego-detection

隐写术检测与提取

何时使用 / 何时不用

  • 用:隐写怀疑(CTF 题/取证对象)、文件尾异常、图片/音频异常(尺寸/噪声/文件结构不匹配)
  • 用:文件结构异常(IEND 后仍有数据/EXIF 段超长/像素数与文件大小不匹配)
  • 用:多载体组合(题目/取证场景常见——多文件各藏一部分)
  • 用:取证场景未分配空间/文件系统残留扫描(与 [[re-disk-forensics]] 配合)
  • 不用:正常文件分析(各归各域技能);加密数据解密(密文 ≠ 隐写,载荷解密转 [[re-crypto-decrypt]]);未知文件类型识别([[re-triage]] 先行)
  • 不用:无载体线索的漫无目的扫描(先有怀疑特征再动手,见 [[decision-tree]])

工具准备

zsteg(图片 LSB 扫描)
  • 多平台: gem install zsteg 或源码(GitHub)
  • 验证: zsteg -h 或 gem list zsteg
  • 覆盖范围:PNG/BMP 支持好,GIF 支持有限——GIF 载体换 python 脚本路径
steghide(图片/音频隐写)
  • Linux: apt install steghide / dnf install steghide;macOS: brew install steghide
  • 验证: steghide --version;steghide info file.jpg(查看是否嵌入数据,无需密码)
binwalk(尾部扫描)
  • 安装与验证见 [[re-fw-extract]] 工具准备
其他检测/提取工具
  • exiftool(EXIF/元数据):Linux apt install libimage-exiftool-perl / dnf install perl-Image-ExifTool;macOS brew install exiftool;验证 exiftool -ver
  • pngcheck(PNG 结构校验/异常):Linux apt install pngcheck;macOS brew install pngcheck;验证 pngcheck -v
  • sox(音频处理/频谱图):Linux apt install sox;macOS brew install sox;验证 sox --version
  • foremost(数据雕刻,取证场景):apt install foremost / brew install foremost
  • stegsolve(逐位平面查看,Java GUI):GitHub 下载 jar(java -jar stegsolve.jar)
  • outguess(JPEG DCT 域,旧工具):Linux apt install outguess
  • ffmpeg(音频格式转换,可选):apt install ffmpeg / brew install ffmpeg
  • python3(位操作/验证脚本 + PIL):安装见 [[re-python]];pip install pillow;验证 python3 -c "from PIL import Image"

操作步骤

按顺序执行,每步产物存档(路径 + sha256,见 [[re-triage]])。

  1. 文件尾附加检测:

    sh
    binwalk sample.png | tail -20       # 附加数据扫描
    hexdump -C sample.png | tail -10    # 尾部目检
    • 尾部附加:文件正常但尾部有多余数据(衔接尾部附加经验([[re-patching]] 补丁制作思路))
    • 结构核对:pngcheck -v sample.png 看 IEND 位置与文件尾差距(差值 ≈ 附加数据量)
    • 弱线索快速扫:strings -a sample.png | grep -iE 'flag|ctf|http'
    • 大小核对:与声称内容明显不符(如 3MB 的「小图」)是弱线索
    • 提取:binwalk 自动分割或 dd 按偏移提取(dd if=sample.png of=tail.bin bs=1 skip=<偏移>)→ magic 检查([[re-triage]])
    • EXIF 查看:exiftool -a sample.jpg(全段列出,异常字段/大块注释可疑)
    • 其他文件冗余区:EXIF 元数据(exiftool 查看)、文件头保留区、压缩文件未用空间
  2. 图片 LSB:

    sh
    zsteg sample.png                    # 全通道 LSB 扫描
    zsteg -E 'b1,rgb,lsb,xy' sample.png # 指定通道/位平面提取
    • 通道:RGB/alpha 各通道最低位;位平面:b1/b2(低 2 位)——alpha 通道也常被用于隐藏
    • zsteg 常用参数:-a 全通道扫描、-v 详细输出、-E 指定提取;输出解读:b1,rgb,lsb,xy 行 = 该平面提取结果,全 failed ≈ 无该平面隐写
    • 顺序:行序/位序影响提取结果(见坑 1;枚举组合见 [[decision-tree]] 提取失败分支)
    • 无工具时的脚本路径:python3 + PIL 按像素遍历提取位序列(getpixel 取通道低 bit → 拼位序列 → 转字节;参考 [[gotchas]] 顺序坑)
    • 脚本枚举模板:行序 × 位序 × 通道三重循环,每种组合输出文件并逐一 file 检查
    • stegsolve 逐位平面查看(GUI):多平面图对比,找视觉图案(LSB 图像隐写常见)
  3. 其他载体:

    • 音频:频谱隐写(sox 频谱图:sox in.wav -n spectrogram -o out.png 后目检频域图案)、steghide 提取(steghide extract -sf file.wav)、相位/回声隐写
    • 音频分支:先看波形/频谱(频域图案呈文本/二维码形状 → 频谱隐写),再按时域(LSB 类,steghide)与频域(相位/回声,需专门工具)区分处理
    • 图片 DCT 域(JPEG):outguess 类工具(旧工具,对新格式支持有限,见 [[gotchas]])
    • 文件冗余区:EXIF、文件头保留区、压缩文件未用空间(ZIP 内 CRC/未用空间)
    • 其他载体:文本(空白字符/行距)、网页(注释/隐藏标签)——按场景扩展
    • 多载体组合(题目常用):各文件分片拼接(按顺序/按特征关联,参考 [[re-triage]] 元数据初勘)
  4. 提取验证:

    • magic 检查(提取物头部特征)
    • 可读性验证(strings/file)
    • 提取物再检测:提取出的文件本身可能再藏(嵌套)——提取物走一遍完整流程;为脚本/压缩包时按对应域继续([[re-script-deob]] / [[re-python]] 等)
    • 验证产物:提取物 file 类型与预期一致才定「确认嵌入」(分级表见 [[decision-tree]])
    • 隐写前压缩:先提取再解压(提取物查压缩头——zlib 78 9C / gzip 1F 8B / bzip2 42 5A 68,见坑 3)
    • 加密载荷:无密钥时标注不可提取(不硬破解);有密钥线索走 [[re-crypto-decrypt]]

跨域联合

  • [[re-ctf]] 网关:本技能归属
  • [[re-fw-extract]]:binwalk 复用
  • [[re-patching]]:尾部附加经验衔接
  • [[re-triage]]:提取物初勘
  • [[re-crypto-decrypt]]:载荷解密衔接
  • [[re-disk-forensics]]:未分配空间/文件系统侧隐写(取证场景)

常见坑与陷阱

  • LSB 顺序:现象——提取乱码;原因——行序(从上到下/从下到上)/位序(LSB 优先/MSB 优先);对策——工具自动尝试或脚本枚举组合
  • 多载体误判:现象——一个文件中多个隐写层;原因——嵌套隐写;对策——分层提取,每层验证
  • 隐写前压缩:现象——提取物乱码;原因——明文先压缩再嵌入;对策——先查压缩特征(zlib/gzip/bzip2 头)再解压
  • 工具输出噪声:现象——大量候选;原因——扫描输出含误报;对策——按 magic/可读性过滤
  • 载体本身异常:现象——文件损坏;原因——隐写写入破坏结构;对策——先修复/容忍损坏(按位提取不依赖结构)
  • JPEG 有损混淆:现象——LSB 提取出噪声;原因——JPEG 有损压缩覆盖了位平面(LSB 类隐写主要针对 PNG/BMP,JPEG 走 DCT 域);对策——先判格式(pngcheck)再选方法
  • 熵误报:现象——扫描报「有隐写」但无内容;原因——压缩/随机数据天然高熵;对策——熵特征只作怀疑线索,不单独定性(判定分级见 [[decision-tree]])
  • steghide 密码:现象——无密码提取失败;原因——需要口令(CTF 常给提示);对策——先无密码试,再按提示/密钥线索尝试,无则标注
  • 单工具盲区:现象——zsteg 无结果但有隐写;原因——工具覆盖的通道/算法有限;对策——zsteg + steghide + 脚本多路交叉
  • 载体副本差异:现象——同一文件不同来源扫描结果不同;原因——副本被转码/压缩;对策——用原始载体(哈希核对,见 [[re-triage]])
  • 题目/场景提示被忽略:现象——扫了图片半天,载荷其实在配套文件里;原因——多载体提示未看;对策——先看提示,按提示分载体
  • 压缩层与隐写层混淆:现象——把压缩数据的随机性当成隐写线索;原因——压缩内容天然高熵;对策——先解压再分析内容(压缩不是隐写)
  • 乱码三分支判定:现象——提取出内容但像乱码;原因——可能是压缩/加密/顺序错,也可能就是随机填充;对策——按压缩头/可读性/统计分布走 [[decision-tree]] 提取失败分支
  • 检测/提取分支与证据分级见 [[decision-tree]];边界与反例见 [[gotchas]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-stego of dslsdzc/rev-skills.

  • SKILL.md
  • references/decision-tree.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Stego next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Stego compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Stego this skilldslsdzc/rev-skills130—~1.2kAutomated safety check: PassApache-2.0
Ppt CompressorLeoYeAI/openclaw-master-skills2.2k—~3.9kAutomated safety check: PassMIT
OrcaSlicer G-code Slicingearthtojake/text-to-cad19k—~989Automated safety check: PassMIT
Env Doctorcat-xierluo/legal-skills717—~756Automated safety check: PassMIT
Tdoc DOCXLeoYeAI/openclaw-master-skills2.2k—~3.6kAutomated safety check: NotesMIT
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT

Similar skills

  • Ppt Compressor

    LeoYeAI/openclaw-master-skills

    This skill should be used when the user wants to compress a PowerPoint (.pptx) file by reducing the size of embedded videos and large images.

    2.2k GitHub stars~3.9k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • OrcaSlicer G-code Slicing

    earthtojake/text-to-cad

    Slices STL, 3MF or OBJ models into printer-ready G-code with OrcaSlicer, either headless from the command line or by opening the model in the app.

    19k GitHub stars~989 tokensUpdated today
    Media & CreativeAuto-check passed
  • Env Doctor

    cat-xierluo/legal-skills

    本机开发环境与全局包的体检、账本与安装纪律,覆盖所有包管理器(npm/npx、nvm、pip/pipx、uv、brew、bun)与运行时环境面(~/.local/bin 垫片、PATH、python 解释器版图、LaunchAgents、cron、shell rc 漂移对照)。当用户问「node/python 为什么是这个版本」「npm/pip…

    717 GitHub stars~756 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Tdoc DOCX

    LeoYeAI/openclaw-master-skills

    Word 文档全能处理技能 | Complete Word Document Processing Skill. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~3.6k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check: notes
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Youtube Clipper

    op7418/Youtube-clipper-skill

    YouTube 视频智能剪辑工具。下载视频和字幕,AI 分析生成精细章节(几分钟级别), 用户选择片段后自动剪辑、翻译字幕为中英双语、烧录字幕到视频,并生成总结文案。

    2.2k GitHub stars~1.6k tokensUpdated 8 mo ago
    Media & CreativeAuto-check: notes

More from dslsdzc/rev-skills

All 40 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Re Format Elf

    dslsdzc/rev-skills

    ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Questions about Re Stego

What does Re Stego do?

隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证. An agent skill from dslsdzc/rev-skills. Re Stego is an agent skill from dslsdzc/rev-skills.

When should I use Re Stego?

Re Stego fits situations like: security work in your project.

How do I install Re Stego in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-stego -a claude-code`. Or copy the skill folder (.claude/skills/re-stego in dslsdzc/rev-skills) into .claude/skills/re-stego in your project. Claude Code loads it when a task matches its description.

How do I install Re Stego in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-stego -a codex`. Or copy the skill folder (.claude/skills/re-stego in dslsdzc/rev-skills) into .agents/skills/re-stego in your project. Codex loads it when a task matches its description.

Can I use Re Stego in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-stego -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-stego, .gemini/skills/re-stego, .github/skills/re-stego and .opencode/skills/re-stego in your project.

What does Re Stego need to run?

Going by SKILL.md and its folder, Re Stego needs the command-line tools its instructions call (apt, brew, gem, dnf, java and pip). Our summary lists: Python 3.

Does Re Stego access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Re Stego safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Stego use?

Re Stego is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Stego use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Re Stego?

Skills that share tags, products or a category with Re Stego: Ppt Compressor (LeoYeAI/openclaw-master-skills, 2.2k stars), OrcaSlicer G-code Slicing (earthtojake/text-to-cad, 19k stars), Env Doctor (cat-xierluo/legal-skills, 717 stars) and Tdoc DOCX (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Stego?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.