Agent skill

Re Tracing

by dslsdzc in dslsdzc/rev-skills

系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check: notesSecurity

Install Re Tracing

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-tracing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-tracing .claude/skills/re-tracing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-tracing
GitHub stars
125
Token cost
~940 tokens
SKILL.md length
251 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: strace -f 全进程树跟踪 → 过滤(-e trace=...) → ltrace 库调用 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 指令级追踪, plus 2 more sections
  • Calls apt, dnf and choco

What it does

Re Tracing is an agent skill from dslsdzc/rev-skills. 系统调用/函数调用跟踪:strace/ltrace/dtruss。 触发词:strace、跟踪系统调用、ltrace、API监控

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/commands.md` and `references/gotchas.md`).

It sits in Security. It works with Linux and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-tracing”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. strace -f 全进程树跟踪
  2. 过滤(-e trace=...)
  3. ltrace 库调用
  4. 输出保存为证据
  5. Windows 用 APIMonitor/ProcMon

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • choco

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Tracing loads about 940 tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 19 tokens; SKILL.md has 251 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~940
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:40
    - 验证: `sudo dtruss -c ls / 2>&1 | head` 输出去重调用统计
  • NoteRuns commands with sudoSKILL.md:58
    sudo strace -f -p <pid> -o attach.log     # attach 需要与目标同权限

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 251 words, ~940 tokens.

Download SKILL.mdSave it as .claude/skills/re-tracing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-tracing
description
系统调用/函数调用跟踪:strace/ltrace/dtruss。 触发词:strace、跟踪系统调用、ltrace、API监控
capabilities
tracing

系统调用/函数调用跟踪

何时使用 / 何时不用

  • 用:观察程序运行行为(文件/网络/进程操作);记录系统调用与库调用序列作为证据;定位动态解析的 API(GetProcAddress/dlopen 之后)
  • 不用:只需内存内容(走 [[re-memdump]]);只需静态逻辑(反编译技能)
  • 不用:Windows 目标用 APIMonitor/ProcMon(本技能 Linux/macOS 为主)

工具准备

参考 [[re-analyze/platform-tips]] 最高原则——跟踪即动态执行,默认在沙箱内进行,网络隔离。

strace(Linux)
  • Debian/Ubuntu: apt install strace
  • Fedora/RHEL: dnf install strace
  • Arch: pacman -S strace
  • WSL: Linux 包直接可用
  • 验证: strace -V
  • 常用选项:-f 跟子进程、-o 写文件、-e trace= 过滤、-s 200 放大字符串显示(默认 32 字节)、-x 非 ASCII 转十六进制、-y/-yy 把 fd 解析为路径、-c 汇总统计、-p attach——速查与组合见 [[commands]]
ltrace(Linux 库调用)
  • Debian/Ubuntu: apt install ltrace
  • Fedora/RHEL: dnf install ltrace
  • Arch: pacman -S ltrace
  • 验证: ltrace -V
dtruss(macOS,DTrace 版 strace)
  • macOS 自带(随 Xcode CLT);需要 root 且部分 SIP 场景受限
  • 验证: sudo dtruss -c ls / 2>&1 | head 输出去重调用统计
APIMonitor / ProcMon(Windows)
  • APIMonitor: rohitab.com 下载 zip 解压即用
  • ProcMon: Microsoft Sysinternals —— choco install sysinternals(或官网下载)
  • 验证: 打开 APIMonitor/ProcMon 能列出并附加进程

操作步骤

  1. strace -f 全进程树跟踪:

    sh
    strace -f -o trace.log ./target args

    -f 必须加:跟随 fork/vfork/clone 子进程——不加会漏掉全部子进程行为。 -tt 加微秒时间戳,-T 加每调用耗时(网络等待/慢调用线索);-s 200 放大字符串显示(默认 32 字节,路径/参数看不全时必加)。 已运行的目标用 attach(看不到 attach 之前的调用):

    sh
    sudo strace -f -p <pid> -o attach.log     # attach 需要与目标同权限
    strace -f -c ./target                      # 退出时打印系统调用计数/耗时汇总(热点定位)
  2. 过滤(-e trace=...):

    sh
    strace -f -e trace=network,file ./target     # 只看网络与文件
    strace -f -e trace=write,read ./target       # 只看读写
    strace -f -e trace=execve,fork,clone ./target # 只看进程行为
    strace -f -e trace=!futex ./target           # 排除噪声(futex 高频)

    过滤规则先白名单后黑名单,控制输出体积(见坑 2)。

  3. ltrace 库调用:

    sh
    ltrace -f -o lib.log ./target
    ltrace -e malloc+free ./target        # 只跟踪指定库函数
    ltrace -l /path/libfoo.so ./target    # 跟踪 dlopen 动态加载的库
    ltrace -f -S ./target                 # 库调用 + 系统调用一起跟踪
    ltrace -f -c ./target                 # 退出时库调用汇总

    动态解析的 API(dlsym 拿到的函数)不会出现在静态 IAT 里,但会出现在 ltrace 输出中——与 [[re-imports]] 互补。

  4. 输出保存为证据:

    sh
    strace -f -tt -o evidence/trace-$(date +%s).log ./target
    # 或
    ltrace -f -o evidence/libcall.log ./target

    每条记录带 pid 与时间戳;分析完成后在笔记中引用文件路径与哈希(样本与日志各存 sha256,见 [[re-triage]])。

  5. Windows 用 APIMonitor/ProcMon:

    • APIMonitor: 运行(管理员)→ 选中目标进程 → 勾选要监控的 API 类(File/Network/Registry/Process)→ 附加,观察调用参数与返回值
    • ProcMon: 全系统级(文件/注册表/网络/进程事件),先按进程过滤(Process Name 过滤目标名),再按 Operation 过滤
    • 可疑点: 对注入类 API 连续调用序列(OpenProcess→VirtualAllocEx→WriteProcessMemory→CreateRemoteThread)即恶意行为证据

指令级追踪

比系统调用级更深一层——指令粒度执行流:

  • QEMU 插件:-plugin 加载指令级 trace 插件(insn 粒度、call/ret 路径、guest 代码块事件);用途——脱壳后真实路径还原、反混淆(静态混淆无法隐藏实际执行)
  • Intel PT:硬件 trace(perf record -e intel_pt)→ 解码(perf script 或第三方解析)→ 分支流还原;用途——无插桩开销的完整执行路径
  • trace 分析:热点(执行频次排序)、路径还原(调用链重建)、与 [[re-deobfuscate]] 衔接(按真实路径过滤死代码)
  • 输出:指令级执行流摘要(供 [[re-analyze/analysis-contract]] 证据存档)

跨域联合

  • [[re-binary-core]]:工作流第 6 步(行为跟踪)
  • [[re-malware]]:恶意行为观察(回连/持久化/自启动)
  • [[re-cracking]]:监控校验/注册相关的 API 调用参数
  • 与 [[re-imports]] 互补(动态解析 API);发现反调试时转 [[re-anti-analysis]]
  • [[re-ebpf]]:BPF 观测/跟踪取证还原——strace 覆盖不到的 skb/内核路径由 BPF 观测互补

常见坑与陷阱

  • 不加 -f 漏子进程:目标 fork 后父进程退出/exec,未跟踪的子进程行为全部丢失——-f 是标配
  • 输出巨大:不过滤时大程序日志可达 GB 级拖垮磁盘——先 -e trace= 白名单,必要时 -o 写文件而非终端
  • 反调试样本检测 trace 环境:ptrace 状态检测/LD_PRELOAD 痕迹暴露 strace/ltrace——与 [[re-anti-analysis]] 的反调试绕过组合使用
  • ltrace 默认只跟踪 PLT 层调用——dlopen 后加载的库函数要加 -l 显式指定
  • 命令族速查与操作序列见 [[commands]];工具特有坑与版本差异见 [[gotchas]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-tracing of dslsdzc/rev-skills.

  • SKILL.md
  • references/commands.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Tracing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Tracing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Tracing this skilldslsdzc/rev-skills125—~940Automated safety check: NotesApache-2.0
Game Automationrehan-remade/universal-modder5.3k—~1.9kAutomated safety check: PassMIT
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Os Hardware Inventorycdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Bumblebeesickn33/agentic-awesome-skills47k1 repos~2.5kAutomated safety check: NotesMIT

Similar skills

  • Game Automation

    rehan-remade/universal-modder

    Launch, see and drive a real game so an agent can test its own mods.

    5.3k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Bumblebee

    sickn33/agentic-awesome-skills

    Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check: notes
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    125 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Works with

Categories

Questions about Re Tracing

What does Re Tracing do?

系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills. Re Tracing is an agent skill from dslsdzc/rev-skills.

When should I use Re Tracing?

Re Tracing fits situations like: security work in your project.

How do I install Re Tracing in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-tracing -a claude-code`. Or copy the skill folder (.claude/skills/re-tracing in dslsdzc/rev-skills) into .claude/skills/re-tracing in your project. Claude Code loads it when a task matches its description.

How do I install Re Tracing in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-tracing -a codex`. Or copy the skill folder (.claude/skills/re-tracing in dslsdzc/rev-skills) into .agents/skills/re-tracing in your project. Codex loads it when a task matches its description.

Can I use Re Tracing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-tracing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-tracing, .gemini/skills/re-tracing, .github/skills/re-tracing and .opencode/skills/re-tracing in your project.

What does Re Tracing need to run?

Going by SKILL.md and its folder, Re Tracing needs the command-line tools its instructions call (apt, dnf and choco).

Does Re Tracing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Tracing safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Re Tracing use?

Re Tracing is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Tracing use?

About 940 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Re Tracing?

Skills that share tags, products or a category with Re Tracing: Game Automation (rehan-remade/universal-modder, 5.3k stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Os Hardware Inventory (cdxgen/cdxgen, 1.1k stars) and Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Tracing?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.