Ctf Malware
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
Specialized in reverse-engineering compiled binaries (JARs, DLLs).
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/patch-diff-analyzer .claude/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .claude/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/patch-diff-analyzer .agents/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .agents/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/patch-diff-analyzer .cursor/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .cursor/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HacktronAI/skills.git --path patch-diff-analyzer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/patch-diff-analyzer .gemini/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .gemini/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HacktronAI/skills patch-diff-analyzerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/patch-diff-analyzer .github/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .github/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HacktronAI/skills --skill patch-diff-analyzer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HacktronAI/skills patch-diff-analyzer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/patch-diff-analyzer .opencode/skills/patch-diff-analyzer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "patch-diff-analyzer" agent skill from https://github.com/HacktronAI/skills/tree/main/patch-diff-analyzer into .opencode/skills/patch-diff-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "patch-diff-analyzer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
patch-diff-analyzerSpecialized in reverse-engineering compiled binaries (JARs, DLLs).
Patch Diff Analyzer is an agent skill from HacktronAI/skills. Specialized in reverse-engineering compiled binaries (JARs, DLLs). Use this when the user asks to compare versions, find security fixes, or analyze binary patches.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `examples/example-workflow.md` and `scripts/analyze-diff.sh`). Compatibility notes: Requires git, jadx (for JAR), ilspycmd (for DLL)
It sits in Security, covering Reverse engineering and malware. It works with .NET and Git. The repository describes itself as: This repository consists of extensions, that hacktron uses to execute specific workflows in CLI. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 17ae4af. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires git, jadx (for JAR), ilspycmd (for DLL)
From compatibility in the SKILL.md frontmatter.
Patch Diff Analyzer loads about 2.2k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 773 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from HacktronAI/skills at commit 17ae4af, republished under its MIT licence (© HacktronAI). 773 words, ~2,168 tokens.
.claude/skills/patch-diff-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.IMPORTANT: Users may request analysis of security patches in compiled binaries (JARs, DLLs, etc.) to understand what vulnerabilities were fixed. This extension helps decompile binaries, generate diffs, and identify security-relevant changes.
The extension have these scripts:
<workspace-name>What it does:
decompiled/, output/<workspace>/decompiled/What it does:
<workspace>/decompiled/What it does:
<workspace>What it does:
unpatched and patched tags (or uses HEAD~1 and HEAD)patch-analysis.diff filechanged-files.txt listWhen a user requests patch analysis:
Identifying Binaries: Do you need to determine which file is patched vs unpatched?
File Format: What type of binary are you analyzing?
Analysis Context: Does the user provide vulnerability information?
CRITICAL: Before decompilation, correctly identify which binary is the patched version.
Explicit Naming:
patched.jar / unpatched.jarvulnerable.jar / fixed.jarVersion Numbers:
app-1.2.3.jar vs app-1.2.4.jarFile Timestamps:
ls -lt *.jarWhen Ambiguous:
Use the provided setup script.
CRITICAL: For WAR files or large applications, extract ONLY proprietary code before decompiling. This saves significant time and storage.
WAR file structure:
application.war
├── WEB-INF/
│ ├── classes/ ← Application code (DECOMPILE THIS)
│ │ └── com/
│ │ └── vendor/ ← Proprietary packages
│ └── lib/ ← Third-party JARs (SKIP THESE)
│ ├── jackson-*.jar
│ ├── spring-*.jar
│ └── hibernate-*.jar
└── META-INF/# 1. List WAR contents to identify proprietary packages
unzip -l unpatched.war | grep "WEB-INF/classes" | grep "\.class$" | head -30
# Look for company-specific packages:
# WEB-INF/classes/com/acme/
# WEB-INF/classes/com/vendor/
# WEB-INF/classes/org/internal/
# 2. Extract ONLY proprietary classes
mkdir -p temp-unpatched
unzip unpatched.war "WEB-INF/classes/com/vendor/*" -d temp-unpatched/
unzip unpatched.war "WEB-INF/classes/com/acme/*" -d temp-unpatched/
# 3. Create JAR from extracted classes
cd temp-unpatched/WEB-INF/classes
jar cf ../../../vendor-unpatched.jar .
cd ../../..
# 4. Repeat for patched version
mkdir -p temp-patched
unzip patched.war "WEB-INF/classes/com/vendor/*" -d temp-patched/
unzip patched.war "WEB-INF/classes/com/acme/*" -d temp-patched/
cd temp-patched/WEB-INF/classes
jar cf ../../../vendor-patched.jar .
cd ../../..
# Now decompile ONLY proprietary code (much faster!)cd <workspace>
git add -A
git commit -m "Unpatched version"
git tag unpatchedCRITICAL: The unpatched tag is used by the diff analysis script.
IMPORTANT: Clear the decompiled directory first to avoid mixing files.
rm -rf <workspace>/decompiled/*cd <workspace>
git add -A
git commit -m "Patched version"
git tag patchedCRITICAL: The patched tag is used by the diff analysis script.
Follow the same git commit process as the JAR workflow:
<workspace> to generate patch-analysis.diff and changed-files.txt listMANDATORY: Read the generated diff file completely.
DO NOT use grep or pattern matching. The LLM must read and reason about the actual code changes.
CRITICAL: This is where you apply security expertise to understand the vulnerability fix.
MANDATORY FIRST STEP: Before analyzing changes, separate proprietary code from third-party libraries.
Why This Matters:
High-Priority Indicators:
MANDATORY: Use this structure for your analysis report:
# Patch Analysis Summary
## Overview
[Brief description of what was analyzed]
## Vulnerability Identified: [Type/CVE]
**Severity**: [Critical/High/Medium/Low]
## Detailed Analysis
### File: [path/to/file.java:line-range]
[Detailed analysis following the framework above]
## Completeness Assessment
[Is the fix complete? Any potential bypasses? Additional recommendations?]
## Confidence Level
Overall confidence: [HIGH/MEDIUM/LOW] ([percentage]%)Solution: Install jadx (for JAR) or ilspycmd (for DLL)
Solution: Run setup-workspace.sh script first
Solution: Ensure both unpatched and patched versions were committed
Solution:
git log to see commits© HacktronAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts) in patch-diff-analyzer of HacktronAI/skills.
Open the folder on GitHubat commit 17ae4af
Patch Diff Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Patch Diff Analyzer this skillHacktronAI/skills | 115 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | 1 repos | ~2.1k | Automated safety check: Notes | MIT | |
| Nes Decompilejonathanpeppers/dotnes | 780 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Malware Analysishypnguyen1209/offensive-claude | 386 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Scaffoldingdotnet/efcore | 15k | — | ~165 | Automated safety check: Pass | MIT | |
| Dotnet Inspect Decompilerrichlander/dotnet-inspect | 151 | — | ~2.4k | Automated safety check: Pass | None |
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
jonathanpeppers/dotnes
Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes.
hypnguyen1209/offensive-claude
A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…
dotnet/efcore
Implementation details for EF Core scaffolding (reverse engineering).
richlander/dotnet-inspect
Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup.
ptn1411/skill
Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill.
HacktronAI/skills
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…
Categories
Specialized in reverse-engineering compiled binaries (JARs, DLLs). Patch Diff Analyzer is an agent skill from HacktronAI/skills. Specialized in reverse-engineering compiled binaries (JARs, DLLs).
Patch Diff Analyzer fits situations like: asks to compare versions; find security fixes; analyze binary patches.
Run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a claude-code`. Or copy the skill folder (patch-diff-analyzer in HacktronAI/skills) into .claude/skills/patch-diff-analyzer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a codex`. Or copy the skill folder (patch-diff-analyzer in HacktronAI/skills) into .agents/skills/patch-diff-analyzer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HacktronAI/skills --skill patch-diff-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/patch-diff-analyzer, .gemini/skills/patch-diff-analyzer, .github/skills/patch-diff-analyzer and .opencode/skills/patch-diff-analyzer in your project.
Going by SKILL.md and its folder, Patch Diff Analyzer needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell. Compatibility (from SKILL.md): Requires git, jadx (for JAR), ilspycmd (for DLL).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Patch Diff Analyzer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Patch Diff Analyzer: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Nes Decompile (jonathanpeppers/dotnes, 780 stars), Malware Analysis (hypnguyen1209/offensive-claude, 386 stars) and Scaffolding (dotnet/efcore, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HacktronAI (a GitHub organization) maintains it in HacktronAI/skills, which has 115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on June 4, 2026.
Source: HacktronAI/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.