Agent skill

Patch Diff Analyzer

by HacktronAI in HacktronAI/skills

Specialized in reverse-engineering compiled binaries (JARs, DLLs).

MITAuto-check passedSecurity

Install Patch Diff Analyzer

skills CLI
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/patch-diff-analyzer .claude/skills/patch-diff-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
patch-diff-analyzer
GitHub stars
115
Token cost
~2.2k tokens
SKILL.md length
773 words
Files
7 (incl. scripts)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Specialized in reverse-engineering compiled binaries (JARs, DLLs).

  • Works in 8 steps: Decompile Unpatched Version (Proprietary… → Commit Unpatched Version → Decompile Patched Version → …
  • Asks to compare versions
  • SKILL.md covers Available scripts, Workflow Decision Tree, Binary Identification and Setup & Decompilation, plus 7 more sections
  • Runs Shell scripts from its folder; calls git

What it does

Patch Diff Analyzer is an agent skill from HacktronAI/skills. Specialized in reverse-engineering compiled binaries (JARs, DLLs). Use this when the user asks to compare versions, find security fixes, or analyze binary patches.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `examples/example-workflow.md` and `scripts/analyze-diff.sh`). Compatibility notes: Requires git, jadx (for JAR), ilspycmd (for DLL)

It sits in Security, covering Reverse engineering and malware. It works with .NET and Git. The repository describes itself as: This repository consists of extensions, that hacktron uses to execute specific workflows in CLI. The licence is MIT.

When your agent uses it

  • Asks to compare versions
  • Find security fixes
  • Analyze binary patches

Example prompts

  • “/patch-diff-analyzer”

Requirements

  • A Bash shell
  • Compatibility (from SKILL.md): Requires git, jadx (for JAR), ilspycmd (for DLL)

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Decompile Unpatched Version (Proprietary Code)
  2. Commit Unpatched Version
  3. Decompile Patched Version
  4. Commit Patched Version
  5. Decompile Unpatched Version
  6. 4: Same as JAR Workflow
  7. Filter Third-Party Libraries
  8. Analysis Process

What it can do on your machine

Read from SKILL.md and the folder at commit 17ae4af. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires git, jadx (for JAR), ilspycmd (for DLL)

    From compatibility in the SKILL.md frontmatter.

Context cost

Patch Diff Analyzer loads about 2.2k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 773 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from HacktronAI/skills at commit 17ae4af, republished under its MIT licence (© HacktronAI). 773 words, ~2,168 tokens.

Download SKILL.mdSave it as .claude/skills/patch-diff-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
patch-diff-analyzer
description
Specialized in reverse-engineering compiled binaries (JARs, DLLs). Use this when the user asks to compare versions, find security fixes, or analyze binary patches.
compatibility
Requires git, jadx (for JAR), ilspycmd (for DLL)
license
MIT
metadata.author
hacktron
metadata.version
1.0.0

Patch Diff Analyzer

IMPORTANT: Users may request analysis of security patches in compiled binaries (JARs, DLLs, etc.) to understand what vulnerabilities were fixed. This extension helps decompile binaries, generate diffs, and identify security-relevant changes.

Available scripts

The extension have these scripts:

  • setup-workspace.sh <workspace-name>

What it does:

  1. Creates workspace directory
  2. Initializes git repository for diff tracking
  3. Configures git user for commits
  4. Creates subdirectories: decompiled/, output/
  • decompile-jar.sh <app.jar> <workspace>/decompiled/

What it does:

  1. Creates decompiled directory in workspace dir
  2. Decompiles the jar file in the dir.
  • decompile-dll.sh <app.dll> <workspace>/decompiled/

What it does:

  1. Creates decompiled directory in workspace dir
  2. Decompiles the dll file in the dir.
  • analyze-diff.sh <workspace>

What it does:

  1. Verifies git repository has 2+ commits
  2. Identifies unpatched and patched tags (or uses HEAD~1 and HEAD)
  3. Generates diff statistics
  4. Creates patch-analysis.diff file
  5. Creates changed-files.txt list

Workflow Decision Tree

When a user requests patch analysis:

  1. Identifying Binaries: Do you need to determine which file is patched vs unpatched?

  2. File Format: What type of binary are you analyzing?

  3. Analysis Context: Does the user provide vulnerability information?

    • YES (CVE/Description provided) → Focus analysis on related changes
    • NO (Blind analysis) → Perform comprehensive security change analysis

Binary Identification

CRITICAL: Before decompilation, correctly identify which binary is the patched version.

Identification Methods
  1. Explicit Naming:

    • Files named patched.jar / unpatched.jar
    • Files named vulnerable.jar / fixed.jar
    • → Use as specified
  2. Version Numbers:

    • app-1.2.3.jar vs app-1.2.4.jar
    • → Higher version number is typically patched (1.2.4 > 1.2.3)
    • For semantic versioning: major.minor.patch format
  3. File Timestamps:

    bash
    ls -lt *.jar
    • Newer timestamp typically indicates patched version
    • Note: Not reliable if files were copied/moved
  4. When Ambiguous:

    • ALWAYS ask the user for clarification
    • Do not guess if there's any uncertainty

Setup & Decompilation

Workspace Setup Script

Use the provided setup script.


Efficient Extraction (Skip Third-Party Libraries)

CRITICAL: For WAR files or large applications, extract ONLY proprietary code before decompiling. This saves significant time and storage.

Identify Proprietary Code Location

WAR file structure:

application.war
├── WEB-INF/
│   ├── classes/          ← Application code (DECOMPILE THIS)
│   │   └── com/
│   │       └── vendor/   ← Proprietary packages
│   └── lib/              ← Third-party JARs (SKIP THESE)
│       ├── jackson-*.jar
│       ├── spring-*.jar
│       └── hibernate-*.jar
└── META-INF/
Extract Proprietary Code Only
bash
# 1. List WAR contents to identify proprietary packages
unzip -l unpatched.war | grep "WEB-INF/classes" | grep "\.class$" | head -30

# Look for company-specific packages:
# WEB-INF/classes/com/acme/
# WEB-INF/classes/com/vendor/
# WEB-INF/classes/org/internal/

# 2. Extract ONLY proprietary classes
mkdir -p temp-unpatched
unzip unpatched.war "WEB-INF/classes/com/vendor/*" -d temp-unpatched/
unzip unpatched.war "WEB-INF/classes/com/acme/*" -d temp-unpatched/

# 3. Create JAR from extracted classes
cd temp-unpatched/WEB-INF/classes
jar cf ../../../vendor-unpatched.jar .
cd ../../..

# 4. Repeat for patched version
mkdir -p temp-patched
unzip patched.war "WEB-INF/classes/com/vendor/*" -d temp-patched/
unzip patched.war "WEB-INF/classes/com/acme/*" -d temp-patched/
cd temp-patched/WEB-INF/classes
jar cf ../../../vendor-patched.jar .
cd ../../..

# Now decompile ONLY proprietary code (much faster!)

JAR Decompilation Workflow

Step 1: Decompile Unpatched Version (Proprietary Code)
  • Use the JAR decompilation script provided with extension to decompile the JAR.
Step 2: Commit Unpatched Version
bash
cd <workspace>
git add -A
git commit -m "Unpatched version"
git tag unpatched

CRITICAL: The unpatched tag is used by the diff analysis script.

Step 3: Decompile Patched Version

IMPORTANT: Clear the decompiled directory first to avoid mixing files.

bash
rm -rf <workspace>/decompiled/*
Step 4: Commit Patched Version
bash
cd <workspace>
git add -A
git commit -m "Patched version"
git tag patched

CRITICAL: The patched tag is used by the diff analysis script.


.NET Decompilation Workflow

Step 1: Decompile Unpatched Version
  • Use the DLL decompilation script provided with extension to decompile the DLL.
Show full SKILL.md (324 more words)Show less
Step 2-4: Same as JAR Workflow

Follow the same git commit process as the JAR workflow:

  1. Commit unpatched with tag
  2. Clear directory
  3. Decompile patched
  4. Commit patched with tag

Diff Generation & Analysis

Generate Diff
  • Use analyze-diff.sh <workspace> to generate patch-analysis.diff and changed-files.txt list
Read and Analyze Diff

MANDATORY: Read the generated diff file completely.

DO NOT use grep or pattern matching. The LLM must read and reason about the actual code changes.


Security Analysis

CRITICAL: This is where you apply security expertise to understand the vulnerability fix.

Step 1: Filter Third-Party Libraries

MANDATORY FIRST STEP: Before analyzing changes, separate proprietary code from third-party libraries.

Why This Matters:

  • Third-party library updates are expected and well-documented (Jackson, Spring, Hibernate, etc.)
  • Proprietary code changes indicate application-specific security fixes
  • Custom vulnerabilities are more interesting than known library CVEs
  • Focusing on proprietary code reveals unique attack vectors
Step 2: Analysis Process
  1. Read Every Change: Don't skip any modifications, even small ones
  2. Understand Context: Look at surrounding code, not just the diff lines
  3. Identify Security Changes: Distinguish security fixes from refactoring/features
  4. Reason About Vulnerability: What attack was possible before? What does the fix prevent?
  5. Assess Completeness: Is the fix comprehensive or could there be bypasses?
What to Look For

High-Priority Indicators:

  • Input validation added where none existed
  • Sanitization/encoding of user-controlled data
  • Authentication/authorization checks introduced
  • Bounds checking before array/buffer access
  • Type checking or casting changes
  • Canonicalization of file paths
  • Parameterized queries replacing string concatenation
  • Deserialization filters or whitelists
  • Resource limits (size, timeout, rate)

Reporting Findings

Report Structure

MANDATORY: Use this structure for your analysis report:

markdown
# Patch Analysis Summary

## Overview
[Brief description of what was analyzed]

## Vulnerability Identified: [Type/CVE]

**Severity**: [Critical/High/Medium/Low]

## Detailed Analysis

### File: [path/to/file.java:line-range]

[Detailed analysis following the framework above]

## Completeness Assessment

[Is the fix complete? Any potential bypasses? Additional recommendations?]

## Confidence Level

Overall confidence: [HIGH/MEDIUM/LOW] ([percentage]%)

Error Messages & Solutions

"No decompiler found"

Solution: Install jadx (for JAR) or ilspycmd (for DLL)

"Not a git repository"

Solution: Run setup-workspace.sh script first

"Need at least 2 commits"

Solution: Ensure both unpatched and patched versions were committed

"No differences found"

Solution:

  • Verify you decompiled different versions
  • Check git log to see commits
  • May indicate files are identical

© HacktronAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts) in patch-diff-analyzer of HacktronAI/skills.

  • SKILL.md
  • README.md
  • examples/example-workflow.md
  • scripts/analyze-diff.sh
  • scripts/decompile-dll.sh
  • scripts/decompile-jar.sh
  • scripts/setup-workspace.sh

Open the folder on GitHubat commit 17ae4af

Compare with similar skills

Patch Diff Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Patch Diff Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Patch Diff Analyzer this skillHacktronAI/skills115—~2.2kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k1 repos~2.1kAutomated safety check: NotesMIT
Nes Decompilejonathanpeppers/dotnes780—~1.6kAutomated safety check: PassMIT
Malware Analysishypnguyen1209/offensive-claude386—~2.3kAutomated safety check: PassMIT
Scaffoldingdotnet/efcore15k—~165Automated safety check: PassMIT
Dotnet Inspect Decompilerrichlander/dotnet-inspect151—~2.4kAutomated safety check: PassNone

Similar skills

  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check: notes
  • Nes Decompile

    jonathanpeppers/dotnes

    Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes.

    780 GitHub stars~1.6k tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Malware Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

    386 GitHub stars~2.3k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Scaffolding

    dotnet/efcore

    Official

    Implementation details for EF Core scaffolding (reverse engineering).

    15k GitHub stars~165 tokensUpdated today
    SecurityAuto-check passed
  • Dotnet Inspect Decompiler

    richlander/dotnet-inspect

    Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup.

    151 GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Dotnet Decompiler

    ptn1411/skill

    Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill.

    219 GitHub stars~929 tokensUpdated 16 days ago
    SecurityAuto-check: notes

More from HacktronAI/skills

  • Finding Triage

    HacktronAI/skills

    Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…

    115 GitHub stars~2.9k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Patch Diff Analyzer

What does Patch Diff Analyzer do?

Specialized in reverse-engineering compiled binaries (JARs, DLLs). Patch Diff Analyzer is an agent skill from HacktronAI/skills. Specialized in reverse-engineering compiled binaries (JARs, DLLs).

When should I use Patch Diff Analyzer?

Patch Diff Analyzer fits situations like: asks to compare versions; find security fixes; analyze binary patches.

How do I install Patch Diff Analyzer in Claude Code?

Run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a claude-code`. Or copy the skill folder (patch-diff-analyzer in HacktronAI/skills) into .claude/skills/patch-diff-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Patch Diff Analyzer in Codex?

Run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a codex`. Or copy the skill folder (patch-diff-analyzer in HacktronAI/skills) into .agents/skills/patch-diff-analyzer in your project. Codex loads it when a task matches its description.

Can I use Patch Diff Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/patch-diff-analyzer, .gemini/skills/patch-diff-analyzer, .github/skills/patch-diff-analyzer and .opencode/skills/patch-diff-analyzer in your project.

What does Patch Diff Analyzer need to run?

Going by SKILL.md and its folder, Patch Diff Analyzer needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell. Compatibility (from SKILL.md): Requires git, jadx (for JAR), ilspycmd (for DLL).

Does Patch Diff Analyzer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Patch Diff Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Patch Diff Analyzer use?

Patch Diff Analyzer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Patch Diff Analyzer use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Patch Diff Analyzer?

Skills that share tags, products or a category with Patch Diff Analyzer: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Nes Decompile (jonathanpeppers/dotnes, 780 stars), Malware Analysis (hypnguyen1209/offensive-claude, 386 stars) and Scaffolding (dotnet/efcore, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Patch Diff Analyzer?

HacktronAI (a GitHub organization) maintains it in HacktronAI/skills, which has 115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on June 4, 2026.

Source: HacktronAI/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.