Webhome Extension Builder
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-uefi --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-uefi .claude/skills/re-uefi && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .claude/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-uefi --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-uefi .agents/skills/re-uefi && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .agents/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-uefi --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-uefi .cursor/skills/re-uefi && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .cursor/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-uefi--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-uefi --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-uefi .gemini/skills/re-uefi && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .gemini/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-uefiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-uefi .github/skills/re-uefi && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .github/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-uefi -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-uefi --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-uefi .opencode/skills/re-uefi && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-uefi" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-uefi into .opencode/skills/re-uefi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-uefi", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-uefiUEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Re Uefi is an agent skill from dslsdzc/rev-skills. UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit。 触发词:UEFI、BIOS、DXE、PEI、SEC、PEIM、HOB、bootkit、Secure Boot、EFI 固件、runtime driver
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/pi-stages.md`).
It sits in Security, covering Reverse engineering and malware. It works with GitHub. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptdnfbrewchocoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Uefi loads about 2.3k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 36 tokens; SKILL.md has 679 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 679 words, ~2,336 tokens.
.claude/skills/re-uefi/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.<CORE RULE>
**看到 PE32/PE32+ 就按普通 Windows PE 应用分析,是本域首要要排除的判断错误。**
第一步永远是判阶段与模块类型:
SEC → PEI → DXE → BDS → OS / Runtime(+ SMM 独立一路)同一份固件里,不同阶段的模块运行在完全不同的执行环境:可用内存不同、可调用的服务不同(PPI / Protocol / Runtime Services)、生命周期不同(DXE_DRIVER 与 DXE_RUNTIME_DRIVER 不是一回事)。
所以顺序是:先判阶段与类型,再谈逻辑——类型判错,后面所有"它为什么这么写"的推理都会错。详见 [[pi-stages]]。 </CORE RULE>
| 类型 | 阶段 | 服务形式 / 生命周期 |
|---|---|---|
| SEC | 最早 | 安全与初始化入口,无通用内存环境 |
| PEIM | PEI | PPI;PEI 主要任务之一是建立永久内存 |
| DXE driver | DXE | Protocol;仅存在于 boot services 环境 |
| DXE runtime driver | DXE + Runtime | 跨生命周期:ExitBootServices() 后仍存在,SetVirtualAddressMap() 时被重定位 |
| UEFI driver / application | DXE/BDS 之后 | 跑在 UEFI 环境里的驱动/应用,与固件内建模块不是一回事 |
| SMM/MM driver | 独立 | SMM 内执行,特权层级与生命周期自成一套 |
三条高频判据(细节与决策树见 [[pi-stages]]):
LocateProtocol(&guid) → 做 GUID 字典解析,恢复成 EFI_XXX_PROTOCOL_GUID 与接口 vtable;协议图比直接调用图更有意义所有工具先验证再使用。固件镜像解析/模块静态分析可免沙箱;OVMF 仿真(步骤 5)是动态执行,默认沙箱 + 网络隔离([[re-analyze/platform-tips]] 最高原则)。
apt install uefitool uefitool-cli(官方包:GUI + CLI;CLI 含 UEFIExtract/UEFIFind)yay -S uefitool(或 uefitool-git;非官方仓库)choco install uefitool 如镜像可用)uefiextract --help 输出用法;GUI uefitool 能打开固件镜像uefifind imagefile {header|body|all} {list|count} pattern,无 -g/-t 选项uefiextract fw.bin <GUID>(见下)uefifind --helpapt install ovmf(/usr/share/OVMF/OVMF_CODE.fd、OVMF_VARS.fd)dnf install edk2-ovmf(路径 /usr/share/edk2/ovmf/OVMF_CODE.fd——旧 /usr/share/OVMF 布局已废弃)pacman -S edk2-ovmf(仅装 /usr/share/edk2/x64/OVMF_CODE.4m.fd,4m 格式)brew install qemu 自带固件($(brew --prefix)/share/qemu/edk2-x86_64-code.fd,随 qemu 包)ls /usr/share/OVMF/OVMF_CODE.fd;Fedora/RHEL ls /usr/share/edk2/ovmf/OVMF_CODE.fd;Arch ls /usr/share/edk2/x64/OVMF_CODE.4m.fd;macOS 用 brew 前缀路径apt install qemu-system-x86dnf install qemu-system-x86-core(完整虚拟化组为 dnf install @virtualization)pacman -S qemu-system-x86brew install qemuqemu-system-x86_64 --version按顺序执行,每步记录证据(路径 + sha256,见 [[re-triage]])。初勘先做:file fw.bin + 熵确认是否 UEFI 结构([[re-triage]])。
固件镜像解析(Firmware Volume → File → Section):
file fw.bin
uefiextract fw.bin all # 全量递归解包(含嵌套 FV 与压缩节,见坑 1/2)
ls fw.bin.dump/ # 树:Volume0/ → File0/ → Section0/ → PE32 等DXE 驱动提取:
ueifind fw.bin all list <GUID> # 按模式串(含 GUID 文本)定位文件——NE 版仅位置参数语法,无 -g/-t
# 按 GUID 直接提取指定文件(UEFIExtract 的 GUID 参数模式):
# -m 合法值: all|body|header|info|file;-t 是十六进制节类型(PE32=0x10,即 -t 10)
uefiextract fw.bin <GUID> -o driver.efi -m body -t 10
file driver.efi # 期望输出: PE32+ executable (EFI boot service driver)sha256sum 存证([[re-triage]]),再进反编译器模块分析(入口 / Protocol 服务):
gBS->LocateProtocol(&guid,...)(获取服务)、gBS->InstallProtocolInterface(...)(注册服务)、gBS->CreateEvent(...)(事件/回调)、gST->ConOut(控制台输出)strings driver.efi | grep -iE 'protocol|runtime|efi_' | head -30bootkit 定位(SMM / 定时器回调 / 启动路径挂钩):
gBS->CreateEvent(EVT_TIMER, TPL, Callback, ...) + gBS->SetTimer(..., PERIODIC/ONESHOT, ...) → 回调函数就是周期执行恶意逻辑的地方(最常见挂点)SmiHandlerRegister / SMST 服务 → SMM driver 注册 SMI handler(SMM 内执行的代码,比内核 ring0 更高特权、SMRAM 内执行的持久层)gRT->SetVariable/GetVariable 等 Runtime Services 指针OVMF 仿真验证(运行恶意代码——沙箱内,网络 -net none):
# 只读代码固件 + 可写变量固件(两片 pflash 标准做法);OVMF_CODE.fd 路径按发行版:
# Debian/Ubuntu: /usr/share/OVMF/OVMF_CODE.fd
# Fedora/RHEL: /usr/share/edk2/ovmf/OVMF_CODE.fd(旧 /usr/share/OVMF 布局已废弃)
# Arch: /usr/share/edk2/x64/OVMF_CODE.4m.fd(4m 格式)
qemu-system-x86_64 -drive if=pflash,format=raw,readonly=on,file=/usr/share/OVMF/OVMF_CODE.fd \
-drive if=pflash,format=raw,file=OVMF_VARS.fd \
-m 1024 -net none -boot menu=onBuild*Hob 在 DXE 会断言);GUID 字典解析(Protocol/PPI/FFS/HOB/变量命名空间/配置表);FV → FFS → section → PE 层次(别按 PE 魔数直接 carve);DXE_DRIVER vs DXE_RUNTIME_DRIVER(ExitBootServices 后 boot services 全不可用、EVT_SIGNAL_VIRTUAL_ADDRESS_CHANGE 通知函数禁调任何服务、ConvertPointer、EFI_RUNTIME_ARCH_PROTOCOL 的 VirtualMode/AtRuntime 判据)uefiextract fw.bin all 全量递归展开(自动处理嵌套),或 GUI 里逐层展开子 FV;先确认镜像结构再分析uefiextract fw.bin <GUID> -m body 导出裸 PE,导出后 file 确认输出含 "PE32+ executable (EFI boot service driver)" 再进反编译器;手工提取要按 Section 布局算偏移LocateProtocol 一类调用还原成语义名与接口 vtable,用协议图补足调用图DXE_DRIVER 与 DXE_RUNTIME_DRIVER:现象——拿固件里的地址与 OS runtime 阶段抓到的地址比对,判定被 hook;原因——runtime driver 在 ExitBootServices() 后仍存在、并会按 SetVirtualAddressMap() 的映射被重定位,固件地址本就不等于 runtime 地址;对策——先判模块类型与所处生命周期(EFI_RUNTIME_ARCH_PROTOCOL 的 VirtualMode/AtRuntime 是现成判据),再谈一致性([[pi-stages]])© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .claude/skills/re-uefi of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Uefi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Uefi this skilldslsdzc/rev-skills | 130 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Codeqlelastic/kibana | 21k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Supply Chain Securityzhaoxuya520/reverse-skill | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT |
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
elastic/kibana
Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
symfony/symfony
Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.
Works with
Categories
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills. Re Uefi is an agent skill from dslsdzc/rev-skills.
Re Uefi fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add dslsdzc/rev-skills --skill re-uefi -a claude-code`. Or copy the skill folder (.claude/skills/re-uefi in dslsdzc/rev-skills) into .claude/skills/re-uefi in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-uefi -a codex`. Or copy the skill folder (.claude/skills/re-uefi in dslsdzc/rev-skills) into .agents/skills/re-uefi in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-uefi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-uefi, .gemini/skills/re-uefi, .github/skills/re-uefi and .opencode/skills/re-uefi in your project.
Going by SKILL.md and its folder, Re Uefi needs the command-line tools its instructions call (apt, dnf, brew and choco).
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Uefi is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Uefi: Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Codeql (elastic/kibana, 21k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.