TH08 Semantic Reconstruction
N0zoM1z0/th08
Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.
Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-zig -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-zig --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-zig .claude/skills/re-zig && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .claude/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zigType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-zig -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-zig --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-zig .agents/skills/re-zig && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .agents/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-zig -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-zig --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-zig .cursor/skills/re-zig && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .cursor/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-zig--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-zig -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-zig --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-zig .gemini/skills/re-zig && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .gemini/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-zigInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-zig -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-zig .github/skills/re-zig && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .github/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-zig -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-zig --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-zig .opencode/skills/re-zig && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-zig" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-zig into .opencode/skills/re-zig/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-zig", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-zigZig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills.
Re Zig is an agent skill from dslsdzc/rev-skills. Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界。 触发词:Zig逆向、zig、comptime、zig 产物、panic。
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).
It sits in Security, covering Reverse engineering and malware. It works with C++. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
brewFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Zig loads about 1.3k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 24 tokens; SKILL.md has 355 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 355 words, ~1,261 tokens.
.claude/skills/re-zig/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub._start → main 启动形态),需要还原错误处理路径、C ABI 边界、comptime 展开后的行为readelf -S 查异常表节;readelf -s/llvm-nm 查符号与可见性(Zig 业务函数多为 LOCAL 符号)cmpw + 分支)strings --version@errorName 错误名字符串、panic 消息、格式串定位brew install zig / Windows 官方安装器;验证: zig version按顺序执行,每步产物存档(路径 + sha256,见 [[re-triage]])。
产物识别:
readelf -s sample | grep -iE 'panicking|panicExtra|defaultPanic|zig' | head
readelf -S sample | grep gcc_except_table # 应无输出(Zig 产物常带 .eh_frame,不能作判别)
readelf -s sample | grep __gxx_personality_v0 # 应无匹配
readelf -s sample | grep -wE '_start|main' # 启动形态debug.panicExtra/debug.panicking 等,版本相关)、std 符号模式(std.debug.print 等)、无 C++ RTTI/异常表(对比 [[re-cpp-abi]] 的 RTTI/异常密集特征).gcc_except_table + 无 __gxx_personality_v0 + 无 _ZTV*(RTTI vtable)→ 无 C++ 异常机制;.eh_frame 两者都有,不能单独作判据符号可见性与启动路径:
readelf -s sample | grep -E 'GLOBAL|LOCAL' | grep -cE 'FUNC'
readelf -s sample | grep -wE '_start|main' | head_start(GLOBAL)→ 运行时初始化(std.start)→ main(LOCAL);Zig 的 main 是普通函数,入口经 std.start 包裹(exit 处理在包裹层)_start 与显式 export 的函数,业务函数是 LOCAL 符号(debug/ReleaseSafe 符号表仍在,ReleaseFast 可 strip)——nm 看得到不等于导出,hook/注入面按导出表算panic/错误处理路径:
readelf -s sample | grep -iE 'panic' | head # panic 链符号(版本相关命名)@panic/断言失败 → panic 函数(打印 + abort)——定位 panic 调用点可找输入校验/不变量;panic 处理函数本身是"打印+退出",调用点才是业务校验!T 类型,布局按载荷大小分两种(小载荷 8 字节槽、错误码在高位;大载荷错误码在前、载荷按对齐内联——[[layout]] 有实测表);调用点检查 orelse/catch 分支(编译为错误码比较 + 分支)@errorName 字符串池还原@errorName(e) 的字符串在 __zig_tag_name_* 符号/字符串池——strings 里错误名与代码路径直接对应,是错误语义的第一手线索常量与字符串定位(行为分析入口):
strings -n 5 sample | head -30 # 格式串/错误名/panic 消息
readelf -S sample | grep -E 'rodata|data' # 常量区std.debug.print 的格式串在只读数据区,交叉引用可回到调用点(错误输出路径)comptime 与泛型展开:
std.debug.print 等 std 函数大量内联(Release 模式),readelf -s 可能只剩启动与 panic 链C ABI 边界:
@extern / @cImport:Zig 调用 C 库(导入表清晰可查——readelf -d 的 NEEDED 与导入符号)export fn:Zig 侧导出给 C/宿主调用(GLOBAL 符号,导出表可见)extern / export 或显式 callconv(.c) 的边界上才是 C ABI——编译器自身的定义是「c 是本目标 C 调用约定的别名;标记为 extern 或 export 的函数默认获得该约定」,而普通 Zig fn 用的是 Zig 默认约定(定义原文:既非 export 也非 inline 时使用;不对栈对齐、寄存器等作任何保证,且只能在同一 Zig 编译单元内使用)。所以 callconv(.c) 是显式要求 C 约定,不是普通函数的默认值.c 在该 target 的映射,不代表 Zig 内部约定本身stripped/ReleaseFast 兜底:
strings -n 6 sample | grep -iE 'panic|error' | head # panic 消息/错误名(@errorName 字符串池)catch/orelse 分支的错误码比较)nm 列表里函数一大堆,但 nm -g(全局)只有 _start;原因——Zig 默认不导出业务符号;对策——hook/注入按导出表算;分析按 LOCAL 符号仍可定位std.debug.panic 找符号找不到;原因——0.14+ 重构为 debug.panicExtra/defaultPanic 链(老版本 std.debug.panic 直接命名);对策——按 panic 调用点(@panic 编译产物:打印+abort 序列)定位,不依赖具体符号名© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-zig of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Zig next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Zig this skilldslsdzc/rev-skills | 117 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| TH08 Semantic ReconstructionN0zoM1z0/th08 | 100 | — | ~2.3k | Automated safety check: Pass | MIT | |
| ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime | 22k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 |
N0zoM1z0/th08
Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.
microsoft/onnxruntime
Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Works with
Categories
Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills. Re Zig is an agent skill from dslsdzc/rev-skills.
Re Zig fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add dslsdzc/rev-skills --skill re-zig -a claude-code`. Or copy the skill folder (.claude/skills/re-zig in dslsdzc/rev-skills) into .claude/skills/re-zig in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-zig -a codex`. Or copy the skill folder (.claude/skills/re-zig in dslsdzc/rev-skills) into .agents/skills/re-zig in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-zig -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-zig, .gemini/skills/re-zig, .github/skills/re-zig and .opencode/skills/re-zig in your project.
Going by SKILL.md and its folder, Re Zig needs the command-line tools its instructions call (brew).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Zig is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Zig: TH08 Semantic Reconstruction (N0zoM1z0/th08, 100 stars), ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Code Audit (3stoneBrother/code-audit, 893 stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.