Game Automation
rehan-remade/universal-modder
Launch, see and drive a real game so an agent can test its own mods.
系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-tracing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-tracing .claude/skills/re-tracing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .claude/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-tracing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-tracing .agents/skills/re-tracing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .agents/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-tracing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-tracing .cursor/skills/re-tracing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .cursor/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-tracing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-tracing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-tracing .gemini/skills/re-tracing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .gemini/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-tracingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-tracing .github/skills/re-tracing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .github/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-tracing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-tracing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-tracing .opencode/skills/re-tracing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-tracing" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-tracing into .opencode/skills/re-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-tracing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-tracing系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills.
Re Tracing is an agent skill from dslsdzc/rev-skills. 系统调用/函数调用跟踪:strace/ltrace/dtruss。 触发词:strace、跟踪系统调用、ltrace、API监控
Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/commands.md` and `references/gotchas.md`).
It sits in Security. It works with Linux and macOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptdnfchocoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Tracing loads about 940 tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 19 tokens; SKILL.md has 251 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- 验证: `sudo dtruss -c ls / 2>&1 | head` 输出去重调用统计sudo strace -f -p <pid> -o attach.log # attach 需要与目标同权限Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 251 words, ~940 tokens.
.claude/skills/re-tracing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.参考 [[re-analyze/platform-tips]] 最高原则——跟踪即动态执行,默认在沙箱内进行,网络隔离。
apt install stracednf install stracepacman -S stracestrace -V-f 跟子进程、-o 写文件、-e trace= 过滤、-s 200 放大字符串显示(默认 32 字节)、-x 非 ASCII 转十六进制、-y/-yy 把 fd 解析为路径、-c 汇总统计、-p attach——速查与组合见 [[commands]]apt install ltracednf install ltracepacman -S ltraceltrace -Vsudo dtruss -c ls / 2>&1 | head 输出去重调用统计choco install sysinternals(或官网下载)strace -f 全进程树跟踪:
strace -f -o trace.log ./target args-f 必须加:跟随 fork/vfork/clone 子进程——不加会漏掉全部子进程行为。
-tt 加微秒时间戳,-T 加每调用耗时(网络等待/慢调用线索);-s 200 放大字符串显示(默认 32 字节,路径/参数看不全时必加)。
已运行的目标用 attach(看不到 attach 之前的调用):
sudo strace -f -p <pid> -o attach.log # attach 需要与目标同权限
strace -f -c ./target # 退出时打印系统调用计数/耗时汇总(热点定位)过滤(-e trace=...):
strace -f -e trace=network,file ./target # 只看网络与文件
strace -f -e trace=write,read ./target # 只看读写
strace -f -e trace=execve,fork,clone ./target # 只看进程行为
strace -f -e trace=!futex ./target # 排除噪声(futex 高频)过滤规则先白名单后黑名单,控制输出体积(见坑 2)。
ltrace 库调用:
ltrace -f -o lib.log ./target
ltrace -e malloc+free ./target # 只跟踪指定库函数
ltrace -l /path/libfoo.so ./target # 跟踪 dlopen 动态加载的库
ltrace -f -S ./target # 库调用 + 系统调用一起跟踪
ltrace -f -c ./target # 退出时库调用汇总动态解析的 API(dlsym 拿到的函数)不会出现在静态 IAT 里,但会出现在 ltrace 输出中——与 [[re-imports]] 互补。
输出保存为证据:
strace -f -tt -o evidence/trace-$(date +%s).log ./target
# 或
ltrace -f -o evidence/libcall.log ./target每条记录带 pid 与时间戳;分析完成后在笔记中引用文件路径与哈希(样本与日志各存 sha256,见 [[re-triage]])。
Windows 用 APIMonitor/ProcMon:
比系统调用级更深一层——指令粒度执行流:
-plugin 加载指令级 trace 插件(insn 粒度、call/ret 路径、guest 代码块事件);用途——脱壳后真实路径还原、反混淆(静态混淆无法隐藏实际执行)perf record -e intel_pt)→ 解码(perf script 或第三方解析)→ 分支流还原;用途——无插桩开销的完整执行路径-f 是标配-e trace= 白名单,必要时 -o 写文件而非终端ptrace 状态检测/LD_PRELOAD 痕迹暴露 strace/ltrace——与 [[re-anti-analysis]] 的反调试绕过组合使用dlopen 后加载的库函数要加 -l 显式指定© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-tracing of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Tracing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Tracing this skilldslsdzc/rev-skills | 125 | — | ~940 | Automated safety check: Notes | Apache-2.0 | |
| Game Automationrehan-remade/universal-modder | 5.3k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Os Hardware Inventorycdxgen/cdxgen | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Forensics OsqueryAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.9k | Automated safety check: Notes | Custom licence | |
| Bumblebeesickn33/agentic-awesome-skills | 47k | 1 repos | ~2.5k | Automated safety check: Notes | MIT |
rehan-remade/universal-modder
Launch, see and drive a real game so an agent can test its own mods.
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
cdxgen/cdxgen
Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
sickn33/agentic-awesome-skills
Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.
mukul975/Anthropic-Cybersecurity-Skills
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills. Re Tracing is an agent skill from dslsdzc/rev-skills.
Re Tracing fits situations like: security work in your project.
Run `npx skills add dslsdzc/rev-skills --skill re-tracing -a claude-code`. Or copy the skill folder (.claude/skills/re-tracing in dslsdzc/rev-skills) into .claude/skills/re-tracing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-tracing -a codex`. Or copy the skill folder (.claude/skills/re-tracing in dslsdzc/rev-skills) into .agents/skills/re-tracing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-tracing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-tracing, .gemini/skills/re-tracing, .github/skills/re-tracing and .opencode/skills/re-tracing in your project.
Going by SKILL.md and its folder, Re Tracing needs the command-line tools its instructions call (apt, dnf and choco).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Re Tracing is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 940 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Tracing: Game Automation (rehan-remade/universal-modder, 5.3k stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Os Hardware Inventory (cdxgen/cdxgen, 1.1k stars) and Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.