Agent skill

Re Zig

by dslsdzc in dslsdzc/rev-skills

Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Zig

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-zig -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-zig --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-zig .claude/skills/re-zig && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-zig
GitHub stars
117
Token cost
~1.3k tokens
SKILL.md length
355 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills.

  • Works in 7 steps: 产物识别 → 符号可见性与启动路径 → panic/错误处理路径 → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls brew

What it does

Re Zig is an agent skill from dslsdzc/rev-skills. Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界。 触发词:Zig逆向、zig、comptime、zig 产物、panic。

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/layout.md`).

It sits in Security, covering Reverse engineering and malware. It works with C++. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re-zig”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. 产物识别
  2. 符号可见性与启动路径
  3. panic/错误处理路径
  4. 常量与字符串定位(行为分析入口)
  5. comptime 与泛型展开
  6. C ABI 边界
  7. stripped/ReleaseFast 兜底

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Zig loads about 1.3k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 24 tokens; SKILL.md has 355 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 355 words, ~1,261 tokens.

Download SKILL.mdSave it as .claude/skills/re-zig/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-zig
description
Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界。 触发词:Zig逆向、zig、comptime、zig 产物、panic。
type
atomic
capabilities
lang-runtime-analysis

Zig 逆向

何时使用 / 何时不用

  • 用:Zig 产物(无 C++ RTTI/异常表、panic 函数链特征、_start → main 启动形态),需要还原错误处理路径、C ABI 边界、comptime 展开后的行为
  • 用:Zig/C 混合产物中区分 Zig 侧代码(无 RTTI 侧 + Zig 符号模式)
  • 不用:C/C++ 产物(走 [[re-cpp-abi]];有 RTTI/异常表即非 Zig 单方产物)
  • 不用:只需函数逻辑(直接反编译技能)

工具准备

readelf / llvm-nm(符号与节分析)
  • 安装与验证见 [[re-cpp-abi]] 工具准备
  • 用途: readelf -S 查异常表节;readelf -s/llvm-nm 查符号与可见性(Zig 业务函数多为 LOCAL 符号)
llvm-objdump / objdump(反汇编)
  • 安装与验证见 [[re-cpp-abi]] 工具准备
  • 用途: 定位 panic 调用点、catch/orelse 的错误码比较(cmpw + 分支)
Ghidra / IDA(反编译底座)
  • 安装与验证见 [[re-ghidra]] / [[re-ida]]
  • Zig 产物无类型信息(无 DWARF 时),配合行为分析(见步骤 3/4)
strings(字符串池/错误名)
  • 系统自带;验证: strings --version
  • 用途: @errorName 错误名字符串、panic 消息、格式串定位
zig 编译器(可选,对照编译)
  • 官方 tarball / brew install zig / Windows 官方安装器;验证: zig version
  • 用途: 同版本编译对照产物,验证 panic 链/错误联合布局(版本差异大,见 [[layout]])

操作步骤

按顺序执行,每步产物存档(路径 + sha256,见 [[re-triage]])。

  1. 产物识别:

    sh
    readelf -s sample | grep -iE 'panicking|panicExtra|defaultPanic|zig' | head
    readelf -S sample | grep gcc_except_table   # 应无输出(Zig 产物常带 .eh_frame,不能作判别)
    readelf -s sample | grep __gxx_personality_v0   # 应无匹配
    readelf -s sample | grep -wE '_start|main'      # 启动形态
    • Zig 特征:panic 函数链(debug.panicExtra/debug.panicking 等,版本相关)、std 符号模式(std.debug.print 等)、无 C++ RTTI/异常表(对比 [[re-cpp-abi]] 的 RTTI/异常密集特征)
    • 判别组合:无 .gcc_except_table + 无 __gxx_personality_v0 + 无 _ZTV*(RTTI vtable)→ 无 C++ 异常机制;.eh_frame 两者都有,不能单独作判据
    • 与 C 混合编译:Zig 符号与 C 符号共存(见步骤 5 边界)
  2. 符号可见性与启动路径:

    sh
    readelf -s sample | grep -E 'GLOBAL|LOCAL' | grep -cE 'FUNC'
    readelf -s sample | grep -wE '_start|main' | head
    • 启动路径:_start(GLOBAL)→ 运行时初始化(std.start)→ main(LOCAL);Zig 的 main 是普通函数,入口经 std.start 包裹(exit 处理在包裹层)
    • 符号可见性:Zig 默认只导出 _start 与显式 export 的函数,业务函数是 LOCAL 符号(debug/ReleaseSafe 符号表仍在,ReleaseFast 可 strip)——nm 看得到不等于导出,hook/注入面按导出表算
    • comptime 展开产物:编译期计算已内联/展开——无对应源码结构,按行为分析(见坑 1)
  3. panic/错误处理路径:

    sh
    readelf -s sample | grep -iE 'panic' | head        # panic 链符号(版本相关命名)
    • panic 链:@panic/断言失败 → panic 函数(打印 + abort)——定位 panic 调用点可找输入校验/不变量;panic 处理函数本身是"打印+退出",调用点才是业务校验
    • 错误联合(error union):!T 类型,布局按载荷大小分两种(小载荷 8 字节槽、错误码在高位;大载荷错误码在前、载荷按对齐内联——[[layout]] 有实测表);调用点检查 orelse/catch 分支(编译为错误码比较 + 分支)
    • 分析:错误路径是逆向重点(校验逻辑、失败分支)——错误码比较点即分支条件,错误名可经 @errorName 字符串池还原
    • 错误名还原:@errorName(e) 的字符串在 __zig_tag_name_* 符号/字符串池——strings 里错误名与代码路径直接对应,是错误语义的第一手线索
  4. 常量与字符串定位(行为分析入口):

    sh
    strings -n 5 sample | head -30        # 格式串/错误名/panic 消息
    readelf -S sample | grep -E 'rodata|data'   # 常量区
    • std.debug.print 的格式串在只读数据区,交叉引用可回到调用点(错误输出路径)
    • comptime 求值的常量直接内联为立即数,无常量表——找"魔数"按调用点回溯参数
  5. comptime 与泛型展开:

    • comptime 计算的常量/内联函数无运行时痕迹;泛型实例化产生重复代码(按调用点参数特化)
    • 还原策略:按行为分析(常量出现处 → 回溯到哪个调用参数),不按源码映射
    • std.debug.print 等 std 函数大量内联(Release 模式),readelf -s 可能只剩启动与 panic 链
  6. C ABI 边界:

    • @extern / @cImport:Zig 调用 C 库(导入表清晰可查——readelf -d 的 NEEDED 与导入符号)
    • export fn:Zig 侧导出给 C/宿主调用(GLOBAL 符号,导出表可见)
    • 混合产物:按符号来源区分(Zig 符号 vs C 符号——链接器分组/节归属),边界处是逻辑入口(Zig 主体逻辑在边界内侧)
    • 调用约定:只在 extern / export 或显式 callconv(.c) 的边界上才是 C ABI——编译器自身的定义是「c 是本目标 C 调用约定的别名;标记为 extern 或 export 的函数默认获得该约定」,而普通 Zig fn 用的是 Zig 默认约定(定义原文:既非 export 也非 inline 时使用;不对栈对齐、寄存器等作任何保证,且只能在同一 Zig 编译单元内使用)。所以 callconv(.c) 是显式要求 C 约定,不是普通函数的默认值
    • 纯 Zig 内部函数不能无条件套 C ABI:寄存器参数、聚合类型传参、返回值规则都可能与目标平台 C ABI 不同,恢复原型时以调用点附近的实际用法推断;x86-64 上的 SysV 只适用于 .c 在该 target 的映射,不代表 Zig 内部约定本身
    • C 库调用点的参数布局按 ABI 读(与 [[re-cpp-abi]] 的 C++ thiscall 不同,无隐藏参数/虚表间接层)——这一条只适用于已确认的 C ABI 边界
  7. stripped/ReleaseFast 兜底:

    sh
    strings -n 6 sample | grep -iE 'panic|error' | head     # panic 消息/错误名(@errorName 字符串池)
    • ReleaseFast 下符号表与 panic 链都可能被裁;按行为特征(错误码比较模式、字符串池)恢复,初勘兜底见 [[re-triage]]
Show full SKILL.md (64 more words)Show less

跨域联合

  • [[re-binary-core]] 网关:本技能归属(选择树「Zig 产物」分支)
  • [[re-cpp-abi]]:边界区分(无 RTTI/异常 → 非 C++)
  • [[re-imports]]:C 库边界(NEEDED/导入符号)与导出表
  • [[re-analyze/analysis-contract]]:符号表按数据契约传递
  • [[re-triage]]:初勘兜底

常见坑与陷阱

  • comptime 展开导致符号膨胀:现象——产物符号与源码不对应;原因——编译期展开/内联/泛型特化;对策——按行为分析而非源码映射
  • panic 路径误导:现象——大量 panic 处理代码被当主逻辑;原因——错误路径与正常路径交织;对策——先分离 panic 调用点(校验),再分析正常路径
  • 错误联合布局版本差异:现象——错误码读取错位;原因——error union 布局随版本变化(小载荷 8 字节槽/错误码高位,大载荷按对齐内联);对策——按目标版本确认布局([[layout]] 实测表),错误码恒为 u16
  • 与 C 混合编译难分界:现象——Zig/C 符号混杂;原因——混合编译;对策——按符号来源与节归属分组,边界处进 Zig 逻辑
  • 无异常表 ≠ 无保护:现象——误判无错误处理;原因——Zig 错误处理走 error union 不走异常表;对策——查错误联合调用点(catch/orelse 分支的错误码比较)
  • 业务函数是 LOCAL 符号:现象——nm 列表里函数一大堆,但 nm -g(全局)只有 _start;原因——Zig 默认不导出业务符号;对策——hook/注入按导出表算;分析按 LOCAL 符号仍可定位
  • panic 链命名随版本变:现象——按 std.debug.panic 找符号找不到;原因——0.14+ 重构为 debug.panicExtra/defaultPanic 链(老版本 std.debug.panic 直接命名);对策——按 panic 调用点(@panic 编译产物:打印+abort 序列)定位,不依赖具体符号名

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-zig of dslsdzc/rev-skills.

  • SKILL.md
  • references/examples.md
  • references/layout.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Zig next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Zig compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Zig this skilldslsdzc/rev-skills117—~1.3kAutomated safety check: PassApache-2.0
TH08 Semantic ReconstructionN0zoM1z0/th08100—~2.3kAutomated safety check: PassMIT
ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime22k—~3.3kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.

    100 GitHub stars~2.3k tokensUpdated 18 days ago
    DevelopmentAuto-check passed
  • Official

    Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

    22k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    935 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Works with

Categories

Questions about Re Zig

What does Re Zig do?

Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills. Re Zig is an agent skill from dslsdzc/rev-skills.

When should I use Re Zig?

Re Zig fits situations like: tasks that involve Reverse engineering and malware.

How do I install Re Zig in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-zig -a claude-code`. Or copy the skill folder (.claude/skills/re-zig in dslsdzc/rev-skills) into .claude/skills/re-zig in your project. Claude Code loads it when a task matches its description.

How do I install Re Zig in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-zig -a codex`. Or copy the skill folder (.claude/skills/re-zig in dslsdzc/rev-skills) into .agents/skills/re-zig in your project. Codex loads it when a task matches its description.

Can I use Re Zig in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-zig -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-zig, .gemini/skills/re-zig, .github/skills/re-zig and .opencode/skills/re-zig in your project.

What does Re Zig need to run?

Going by SKILL.md and its folder, Re Zig needs the command-line tools its instructions call (brew).

Does Re Zig access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Zig safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Zig use?

Re Zig is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Zig use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Re Zig?

Skills that share tags, products or a category with Re Zig: TH08 Semantic Reconstruction (N0zoM1z0/th08, 100 stars), ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Code Audit (3stoneBrother/code-audit, 893 stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Zig?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.