Agent skill

Rust Reverse Engineering

by hashgraph-online in hashgraph-online/awesome-codex-plugins

A skill your agent uses when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing…

Apache-2.0Auto-check passedSecurity

Install Rust Reverse Engineering

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill rust-reverse-engineering -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins rust-reverse-engineering --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/jingjing2222/rust-reverse-engineering-skill/skills/rust-reverse-engineering .claude/skills/rust-reverse-engineering && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-reverse-engineering
GitHub stars
1.2k
Token cost
~3.7k tokens
SKILL.md length
1,607 words
Files
17 (incl. scripts, references)
Skills in repo
686
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing…

  • Works in 8 steps: Check and install dependencies → Materialize reverse-engineering… → Fast triage before any deep analysis → …
  • Analyzing a Rust binary without source code
  • SKILL.md covers When to Use, When NOT to Use, Prerequisites and Workflow, plus 3 more sections
  • Runs Shell and Java scripts from its folder; calls bash and cargo

What it does

Rust Reverse Engineering is an agent skill from hashgraph-online/awesome-codex-plugins. Use when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing panic or unwind paths, identifying FFI boundaries, or mapping behavior from ELF, Mach-O, PE, .so, .dylib, .dll, .a, .rlib, or object files.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/dynamic-analysis-notes.md` and `references/rust-patterns.md`).

It sits in Security, covering Reverse engineering and malware. It works with Rust. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Analyzing a Rust binary without source code
  • Reverse engineering Rust executables
  • Demangling Rust symbols
  • Recovering likely crate namespaces

Example prompts

  • “/rust-reverse-engineering”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Check and install dependencies
  2. Materialize reverse-engineering artifacts first
  3. Fast triage before any deep analysis
  4. Recover symbols and namespaces
  5. Recover high-level structure without assuming a stable Rust ABI
  6. Static analysis in a decompiler / disassembler
  7. Dynamic analysis when static evidence is weak
  8. Produce a structured report

What it can do on your machine

Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 10 files in scripts/ (Shell and Java), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Reverse Engineering loads about 3.7k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,607 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 1,607 words, ~3,736 tokens.

Download SKILL.mdSave it as .claude/skills/rust-reverse-engineering/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
rust-reverse-engineering
description
Use when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing panic or unwind paths, identifying FFI boundaries, or mapping behavior from ELF, Mach-O, PE, `.so`, `.dylib`, `.dll`, `.a`, `.rlib`, or object files.

Rust Reverse Engineering

Reverse engineer Rust-compiled binaries methodically. Start with fast triage, confirm that the target is actually Rust, recover namespaces and runtime clues, then move into static or dynamic analysis with a clear hypothesis.

Do not jump straight into decompiler output and treat it as source truth. Rust binaries often contain compiler-generated glue, monomorphized generic code, panic paths, and async state machines that will drown the signal if you skip the triage stage.

When to Use

Use this skill when the user wants to:

  • analyze a Rust executable, shared library, static archive, .rlib, or object file
  • confirm whether a binary was built from Rust
  • demangle Rust symbols and recover likely crate namespaces
  • trace entry points, panic/unwind paths, FFI exports/imports, or async executors
  • understand high-level architecture without source code
  • prepare a Rust binary for deeper work in Ghidra, IDA, Binary Ninja, gdb, or lldb

When NOT to Use

Do not use this skill when:

  • the user already has the Rust source code and wants normal code review or debugging
  • the target is primarily an Android APK/DEX/JAR/AAR package — use an Android-focused workflow instead
  • the task is generic PE/ELF malware triage with no Rust-specific angle
  • the request is to bypass licensing, DRM, or authorization controls on software the user is not authorized to analyze

Prerequisites

Required command-line tools:

  • file
  • strings
  • readelf or llvm-readelf for ELF, or otool for Mach-O
  • nm or llvm-nm
  • objdump or llvm-objdump, or otool on macOS

Recommended:

  • rustfilt
  • gdb or lldb
  • Ghidra, IDA Pro, or Binary Ninja

Verify availability first:

bash
bash <path-to-skill>/scripts/check-deps.sh

If tooling is missing, install one dependency at a time:

bash
bash <path-to-skill>/scripts/install-dep.sh rustfilt
bash <path-to-skill>/scripts/install-dep.sh ghidra

If automatic installation is not possible on the current machine, read references/setup-guide.md.

Workflow

Phase 1: Check and install dependencies

Run the dependency checker first:

bash
bash <path-to-skill>/scripts/check-deps.sh

Parse the output looking for:

  • INSTALL_REQUIRED:
  • INSTALL_OPTIONAL:

If required tooling is missing, install it one dependency at a time:

bash
bash <path-to-skill>/scripts/install-dep.sh <dependency>

The installer:

  • uses Homebrew when available on macOS
  • uses apt, dnf, or pacman on Linux when available
  • uses cargo install rustfilt for rustfilt when cargo exists
  • prints exact manual instructions and exits when a dependency cannot be installed automatically

For optional tooling, recommend at least:

  • rustfilt
  • one debugger: gdb or lldb
  • ghidra

Re-run check-deps.sh after installation attempts. Do not proceed until all required dependencies show OK.

Phase 2: Materialize reverse-engineering artifacts first

Do not keep the analysis ephemeral. Create an artifact bundle on disk before doing interpretation.

bash
bash <path-to-skill>/scripts/collect-artifacts.sh /path/to/binary

The script writes a reusable output directory:

text
<target>-reverse-output/
├── input/
├── triage/
├── symbols/
├── headers/
├── disassembly/
├── decompiled/
│   └── ghidra/
└── reports/

Treat this directory as the source of truth for the rest of the workflow. It should contain:

  • triage/summary.txt — file type, architecture, strip/debug-info status, Rust confidence
  • triage/strings.txt and triage/interesting-strings.txt — raw and filtered strings
  • symbols/raw.txt, symbols/demangled.txt, symbols/namespaces.txt, symbols/imports.txt, symbols/exports.txt
  • headers/* — readelf, otool, or PE header dumps
  • disassembly/disassembly.txt — best-effort disassembly when available
  • decompiled/ghidra/status.txt, summary.txt, functions.tsv, decompile-errors.tsv, and functions/*.c — headless Ghidra pseudocode artifacts when available
  • reports/summary.md and reports/pattern-hits.txt
Phase 3: Fast triage before any deep analysis

If you need a quick rerun or a narrower pass, the underlying triage script is still available.

bash
bash <path-to-skill>/scripts/triage.sh /path/to/binary

Capture these facts before doing anything else:

  1. Container and file type

    • ELF, Mach-O, PE/COFF, static archive, object file, or .rlib
    • target architecture and bitness
    • executable vs shared library vs archive
  2. Symbol quality

    • stripped vs not stripped
    • exported vs imported symbols
    • whether a usable symbol table still exists
  3. Debug-info availability

    • DWARF sections
    • macOS DWARF segments / dSYM hints
    • Windows PDB hints in strings
    • split-debug or external-debug indicators when visible
  4. Rust confidence

    • v0 or legacy Rust mangling patterns
    • demangled core::, alloc::, std::, or crate-like namespaces
    • panic/unwind strings and runtime artifacts
    • Rust-specific crate names in symbols or strings

Do not describe the binary as “definitely Rust” from a single clue. Use multiple, independent signals.

Phase 4: Recover symbols and namespaces

Dump symbols and demangle them as early as possible.

bash
bash <path-to-skill>/scripts/demangle-symbols.sh /path/to/binary

Focus on these buckets:

  • standard runtime buckets: core::, alloc::, std::, panic, unwinding, formatting
  • user-space buckets: crate-like top-level namespaces that are not runtime crates
  • interop buckets: main, _start, exported C ABI functions, imported libc / Win32 / networking APIs
  • framework buckets: likely third-party crates such as serialization, async runtimes, HTTP stacks, crypto, CLI parsing, and logging

Build a short namespace inventory:

text
- runtime crates:
- likely app crates:
- likely third-party crates:
- exported ABI functions:
- imported platform APIs:

Use references/triage-and-fingerprinting.md for the triage rubric and references/rust-patterns.md for common Rust-specific fingerprints.

For targeted bucket searches across the generated artifacts, run:

bash
bash <path-to-skill>/scripts/find-rust-patterns.sh <target>-reverse-output
Phase 5: Recover high-level structure without assuming a stable Rust ABI

Recover structure conservatively.

Look for:

  1. Entry and boundary functions

    • _start, main, CRT glue, loader entry points
    • exported extern "C" / no_mangle style boundaries
    • plugin or callback registration functions
    • thread starts, task executors, and worker loops
  2. Subsystem anchors

    • config parsing
    • logging initialization
    • network / filesystem / crypto imports
    • panic setup and error paths
    • serialization and IPC edges
  3. Call-shape clues

    • large dispatcher-style functions that may be async state machines
    • indirect calls through vtable-like structures
    • formatter-heavy branches around error handling or panic paths
    • repeated monomorphized helpers with type-specific variants

Critical rule: do not assume undocumented Rust layouts are stable.

  • Treat Option, Result, Vec, String, trait objects, and closure layouts as hypotheses until confirmed by debug info, repeated call-site evidence, or explicit repr(C) / repr(transparent) style interop boundaries.
  • Do not label every two-word structure as a trait object.
  • Do not infer source-level module boundaries from one demangled symbol alone; confirm using clusters of neighboring symbols, xrefs, and strings.
Show full SKILL.md (748 more words)Show less
Phase 6: Static analysis in a decompiler / disassembler

Once triage is complete, load the target into Ghidra, IDA, or Binary Ninja.

If analyzeHeadless is installed, collect-artifacts.sh should already materialize a decompiler bundle under decompiled/ghidra/. Treat those .c files as working pseudocode and review aids, not as original Rust source.

If the target is a universal Mach-O, thin it to the slice you actually want to analyze before trusting any disassembly or decompiler output. The automation now does this for you, defaulting to the host architecture when --macho-arch is omitted and recording the chosen slice in input/analysis-target.txt and decompiled/ghidra/analysis-target.txt. If the host slice is not the slice you want, pass --macho-arch explicitly.

Do not treat the export as complete until decompiled/ghidra/status.txt says STATE: completed or decompiled/ghidra/complete.marker exists. The export now writes progress and partial summary state during the run, so interrupted batches are clearly marked as partial or failed instead of looking empty.

Inside Codex, long-running Ghidra exports must stay attached to a live session and be allowed to run until STATE: completed. Do not interrupt them just because they are slow. Do not stop because “enough signal was gathered”, because the expected remaining value seems low, or because the auto-analysis phase looks quiet for a while. If the process is alive and decompiled/ghidra/runner-status.txt is still getting fresh heartbeats, the job is still in progress.

Use decompiled/ghidra/runner-status.txt to distinguish “slow but alive” from “actually stopped”, and use decompiled/ghidra/warning-summary.txt to see whether a small set of hotspot functions is dominating the Unable to resolve constructor / pcode error noise in headless.log. A fresh runner heartbeat together with PROCESS_ALIVE: yes means the export is still live. For detached jobs, ghidra-job.sh status now derives RUNNER_HEARTBEAT_AGE_SECONDS, RUNNER_HEARTBEAT_STALE, and LIVENESS_HINT so you can separate a slow analysis phase from a dead wrapper.

Recommended order:

  1. Run auto-analysis
  2. Apply or verify Rust demangling
  3. Rename obvious runtime buckets away from the app-specific namespace inventory
  4. Start from one of:
    • exported C ABI functions
    • main / startup glue
    • strong strings with xrefs
    • networking / filesystem imports
    • panic and formatting anchors
  5. Label crate clusters and subsystem boundaries
  6. Trace only one feature path at a time

Prefer strings, imports, exports, and clear subsystem anchors over huge decompiler functions. In stripped Rust binaries, anchor-based analysis is more reliable than trying to understand every generic helper.

Use references/static-analysis-workflow.md for the detailed workflow.

Phase 7: Dynamic analysis when static evidence is weak

When stripped code or compiler-generated glue makes static analysis ambiguous, move to a debugger.

Use gdb or lldb to:

  • break at exported ABI functions or main
  • watch network, file I/O, process creation, and crypto-adjacent imports
  • break on panic / abort paths
  • confirm which indirect call sites are real dispatch points
  • trace buffer lifetimes and ownership hand-offs across FFI boundaries

Dynamic analysis is especially valuable for:

  • heavily stripped binaries
  • async runtimes
  • plugin or callback architectures
  • binaries with large amounts of monomorphized generic code
  • distinguishing app logic from runtime support

Use references/dynamic-analysis-notes.md for breakpoint ideas and debugger notes.

Phase 8: Produce a structured report

At the end, deliver both the artifact bundle and a structured report.

The artifact bundle should exist on disk and include at least:

  1. Captured input and triage

    • original target under input/
    • triage summary
    • raw and filtered strings
  2. Recovered symbol artifacts

    • raw symbols
    • demangled symbols
    • namespace histogram
    • imports and exports
  3. Low-level evidence

    • header dumps
    • disassembly when available
    • grouped pattern hits
    • Ghidra pseudocode files when headless export is available
  4. Human-readable report

    • reports/summary.md

Then, in the chat response, deliver:

  1. Binary fingerprint

    • format, architecture, strip/debug-info status, Rust confidence
  2. Namespace inventory

    • runtime crates
    • likely application crates
    • likely third-party crates
  3. Entry points and boundaries

    • startup path
    • exported functions
    • imported APIs
    • likely FFI edges
  4. Recovered subsystems

    • networking
    • storage
    • crypto
    • config
    • async/task execution
    • panic/error handling
  5. Key call flows

    • one or two high-value paths only
    • note confidence and evidence for each path
  6. Open questions

    • what remains ambiguous
    • what extra evidence is needed next (debug info, runtime breakpoints, comparison build, related library)

Rationalizations to Reject

Reject these shortcuts:

  • “The decompiler said it, so it must be true.”
  • “This looks like a trait object because it has two pointers.”
  • “Demangled symbols prove the original source layout.”
  • “A crate name in strings means the feature is definitely used.”
  • “This large dispatcher is obviously business logic.”
    It may just be compiler-generated async or panic/runtime machinery.

Output standard

Always mention the output directory first, then summarize the findings.

Use this format when reporting to the user:

markdown
## Reverse output

- **Output dir**: `path/to/target-reverse-output`
- **Summary report**: `path/to/target-reverse-output/reports/summary.md`

## Rust binary summary

- **Target**: `path/to/binary`
- **Format / arch**: `ELF x86-64`
- **Symbols**: `partially stripped`
- **Debug info**: `DWARF absent`
- **Rust confidence**: `high`

## Namespaces

- **Runtime crates**: `core`, `alloc`, `std`
- **Likely app crates**: `my_app`, `engine`
- **Likely third-party crates**: `tokio`, `serde_json`, `reqwest`

## Entry points and boundaries

- **Startup**: `_start -> ... -> main`
- **Exports**: `plugin_init`, `process_request`
- **Imports**: `connect`, `send`, `recv`, `pthread_create`
- **FFI edges**: `plugin_init`, `process_request`

## Key findings

1. `process_request` appears to drive the request parsing path.
2. Networking likely flows through a `reqwest`/`hyper`-adjacent stack.
3. A large dispatcher near `...::poll` is a strong async-state-machine candidate.

## Next best move

- break on `process_request`
- trace the async poll path
- inspect nearby strings/xrefs for request routing or serialization formats

References

  • references/setup-guide.md
  • references/triage-and-fingerprinting.md
  • references/rust-patterns.md
  • references/static-analysis-workflow.md
  • references/dynamic-analysis-notes.md

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references) in plugins/jingjing2222/rust-reverse-engineering-skill/skills/rust-reverse-engineering of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • agents/openai.yaml
  • references/dynamic-analysis-notes.md
  • references/rust-patterns.md
  • references/setup-guide.md
  • references/static-analysis-workflow.md
  • references/triage-and-fingerprinting.md
  • scripts/check-deps.sh
  • scripts/collect-artifacts.sh
  • scripts/demangle-symbols.sh
  • scripts/export-ghidra-pseudocode.sh
  • scripts/find-rust-patterns.sh
  • scripts/ghidra-job.sh
  • scripts/ghidra/ExportRustPseudocode.java
  • scripts/install-dep.sh
  • scripts/macho-slice.sh
  • scripts/triage.sh

Open the folder on GitHubat commit 78497e5

Compare with similar skills

Rust Reverse Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Reverse Engineering compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Reverse Engineering this skillhashgraph-online/awesome-codex-plugins1.2k—~3.7kAutomated safety check: PassApache-2.0
Go Rust Reversezhaoxuya520/reverse-skill40k2 repos~339Automated safety check: PassMIT
Go Rust Reversesickn33/agentic-awesome-skills47k1 repos~458Automated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT

Similar skills

  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    40k GitHub starsUsed in 2 repos~339 tokens
    SecurityAuto-check passed
  • Go Rust Reverse

    sickn33/agentic-awesome-skills

    Reverse engineer stripped Go and Rust binaries: runtime recognition, pclntab/module metadata recovery, panic-string analysis, and idiomatic decompilation strategies.

    47k GitHub starsUsed in 1 repo~458 tokens
    SecurityAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check: notes

More from hashgraph-online/awesome-codex-plugins

All 686 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Manuscript Engagement Analytics

    hashgraph-online/awesome-codex-plugins

    Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…

    1.2k GitHub stars~875 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Rust Reverse Engineering

What does Rust Reverse Engineering do?

A skill your agent uses when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing…. Rust Reverse Engineering is an agent skill from hashgraph-online/awesome-codex-plugins.rlib, or object files.

When should I use Rust Reverse Engineering?

Rust Reverse Engineering fits situations like: analyzing a Rust binary without source code; reverse engineering Rust executables; demangling Rust symbols; recovering likely crate namespaces.

How do I install Rust Reverse Engineering in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill rust-reverse-engineering -a claude-code`. Or copy the skill folder (plugins/jingjing2222/rust-reverse-engineering-skill/skills/rust-reverse-engineering in hashgraph-online/awesome-codex-plugins) into .claude/skills/rust-reverse-engineering in your project. Claude Code loads it when a task matches its description.

How do I install Rust Reverse Engineering in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill rust-reverse-engineering -a codex`. Or copy the skill folder (plugins/jingjing2222/rust-reverse-engineering-skill/skills/rust-reverse-engineering in hashgraph-online/awesome-codex-plugins) into .agents/skills/rust-reverse-engineering in your project. Codex loads it when a task matches its description.

Can I use Rust Reverse Engineering in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill rust-reverse-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-reverse-engineering, .gemini/skills/rust-reverse-engineering, .github/skills/rust-reverse-engineering and .opencode/skills/rust-reverse-engineering in your project.

What does Rust Reverse Engineering need to run?

Going by SKILL.md and its folder, Rust Reverse Engineering needs a shell and Java for the scripts in its folder and the command-line tools its instructions call (bash and cargo). Our summary lists: A Bash shell.

Does Rust Reverse Engineering access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Reverse Engineering safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Rust Reverse Engineering use?

Rust Reverse Engineering is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Reverse Engineering use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Rust Reverse Engineering?

Skills that share tags, products or a category with Rust Reverse Engineering: Go Rust Reverse (zhaoxuya520/reverse-skill, 40k stars), Go Rust Reverse (sickn33/agentic-awesome-skills, 47k stars), Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Reverse Engineering?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.