Agent skill

Kernel Corpus Analysis

by kernullist in kernullist/PseudoForge

A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…

MITAuto-check passedSecurity

Install Kernel Corpus Analysis

skills CLI
$ npx skills add kernullist/PseudoForge --skill kernel-corpus-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kernullist/PseudoForge kernel-corpus-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kernullist/PseudoForge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tools/kernel_corpus/skills/kernel-corpus-analysis .claude/skills/kernel-corpus-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kernel-corpus-analysis
GitHub stars
162
Token cost
~3.7k tokens
SKILL.md length
1,329 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…

  • Works in 9 steps: Locate the pack root from the user,… → Run the local freshness validator when… → Call corpus_status before analysis.… → …
  • Answering questions about PseudoForge kernel corpus packs through MCP
  • SKILL.md covers First Moves, Tool Workflow, Canonical Answer Workflow and Evidence Discipline, plus 5 more sections
  • Calls python

What it does

Kernel Corpus Analysis is an agent skill from kernullist/PseudoForge. Use when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string, and evidence-grounded reverse-engineering analysis.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. It works with Model Context Protocol. The repository describes itself as: An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts. The licence is MIT.

When your agent uses it

  • Answering questions about PseudoForge kernel corpus packs through MCP
  • Local evidence packs
  • Including kernel lifecycle
  • Evidence-grounded reverse-engineering analysis

Example prompts

  • “/kernel-corpus-analysis”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Locate the pack root from the user, thread context, MCP config, or a local path such as /pseudoforge_out/kernel_corpus/.
  2. Run the local freshness validator when the pack may be old or when derived evidence packs/atlas pages already exist.
  3. Call corpus_status before analysis. Check schema, function count, skipped count, manifest path, SQLite path, and warnings.
  4. Use MCP first when available. If MCP is unavailable, use the local CLIs under tools/kernel_corpus/.
  5. For cross-build or pack-revision drift questions, call compare_canonical_answers first when available. Compare by canonical topic id and…
  6. For broad lifecycle, subsystem, or security-engineering questions, call plan_kernel_answer first when available. If the planner is…
  7. For multi-topic navigation, shared-function analysis, or "what connects these areas?" questions, call get_topic_graph, find_topic_paths…
  8. Prefer focused evidence packs over loading broad raw corpus output.
  9. Do not answer from generic Windows internals alone.

What it can do on your machine

Read from SKILL.md and the folder at commit 414aa57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kernel Corpus Analysis loads about 3.7k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 1,329 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kernullist/PseudoForge at commit 414aa57, republished under its MIT licence (© kernullist). 1,329 words, ~3,674 tokens.

Download SKILL.mdSave it as .claude/skills/kernel-corpus-analysis/SKILL.md (or your agent's skills folder).
name
kernel-corpus-analysis
description
Use when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string, and evidence-grounded reverse-engineering analysis.

Kernel Corpus Analysis

Use this skill for PseudoForge Kernel Corpus analysis. The corpus data stays outside this skill; this file only defines the operating procedure and answer contracts.

Hard rule for every major claim:

text
Claim -> EA -> function name -> artifact path -> inference level

First Moves

  1. Locate the pack root from the user, thread context, MCP config, or a local path such as <workspace>/pseudoforge_out/kernel_corpus/<target>.
  2. Run the local freshness validator when the pack may be old or when derived evidence packs/atlas pages already exist.
  3. Call corpus_status before analysis. Check schema, function count, skipped count, manifest path, SQLite path, and warnings.
  4. Use MCP first when available. If MCP is unavailable, use the local CLIs under tools/kernel_corpus/.
  5. For cross-build or pack-revision drift questions, call compare_canonical_answers first when available. Compare by canonical topic id and normalized function name; treat EAs as build-local evidence.
  6. For broad lifecycle, subsystem, or security-engineering questions, call plan_kernel_answer first when available. If the planner is unavailable, call find_canonical_answers or list_canonical_answers before live retrieval when canonical tools are available.
  7. For multi-topic navigation, shared-function analysis, or "what connects these areas?" questions, call get_topic_graph, find_topic_paths, or get_function_roles when available.
  8. Prefer focused evidence packs over loading broad raw corpus output.
  9. Do not answer from generic Windows internals alone.

Local freshness fallback:

powershell
python -B .\tools\kernel_corpus\validate_pack.py --pack-root "<pack-root>" --include-derived --format text

Local lifecycle fallback:

powershell
python -B .\tools\kernel_corpus\lifecycle.py --pack-root "<pack-root>" --topic process_object --depth 2 --output "<pack-root>\evidence-packs\process_object.json"

Supported lifecycle topics:

  • process_object
  • thread_object
  • file_object
  • driver_object
  • device_object
  • registry_key
  • section_object
  • module_image

Local subsystem atlas fallback:

powershell
python -B .\tools\kernel_corpus\atlas.py --pack-root "<pack-root>" --output-dir "<pack-root>\reports\atlas"

Local answer harness fallback:

powershell
python -B .\tools\kernel_corpus\answer_harness.py --pack-root "<pack-root>" --evidence-pack "<pack-root>\evidence-packs\process_object.json" --question "<question>" --atlas-page process.md --prompt-out "<pack-root>\answer-prompts\process_object.md" --answer-in "<pack-root>\answers\process_object.md" --report-out "<pack-root>\answer-reports\process_object.json"

Local canonical answer fallback:

powershell
python -B .\tools\kernel_corpus\canonical_store.py find --pack-root "<pack-root>" --query "<question>" --max-topics 5
python -B .\tools\kernel_corpus\canonical_store.py get --pack-root "<pack-root>" --topic process_object_lifecycle --quality --gaps --max-chars 12000

Local answer planner fallback:

powershell
python -B .\tools\kernel_corpus\answer_planner.py --pack-root "<pack-root>" --question "<question>" --format markdown --plan-out "<pack-root>\answer-plans\planned-answer.md"

Local answer eval fallback:

powershell
python -B .\tools\kernel_corpus\answer_eval.py --pack-root "<pack-root>" --answers-dir "<pack-root>\answers" --format markdown --report-out "<pack-root>\answer-eval\answer-eval-report.md"

Local canonical drift fallback:

powershell
python -B .\tools\kernel_corpus\canonical_compare.py --pack-root-a "<old-pack-root>" --pack-root-b "<new-pack-root>" --topic process_object_lifecycle --format markdown --report-out "<workspace>\pseudoforge_out\kernel_corpus\drift\process_object_lifecycle.md"

Local knowledge graph fallback:

powershell
python -B .\tools\kernel_corpus\knowledge_graph.py --pack-root "<pack-root>" --priority P0 --include-atlas --include-lifecycle --format markdown --output "<pack-root>\reports\knowledge-graph.md"
python -B .\tools\kernel_corpus\knowledge_graph.py shared-functions --pack-root "<pack-root>"
python -B .\tools\kernel_corpus\knowledge_graph.py function-topics --pack-root "<pack-root>" --function PspAllocateProcess

Tool Workflow

  • Cross-build drift questions: call compare_canonical_answers for compact JSON, or get_canonical_drift_report for bounded Markdown. Inspect missing topics, quality/status changes, same-name different-EA entries, selected-function additions/removals, phase changes, edge changes, and stale quality warnings before drafting.
  • Relationship/navigation questions: call get_topic_graph for a bounded subgraph, find_topic_paths for topic-to-topic paths, or get_function_roles for all topic roles of a function. Use graph output to choose follow-up canonical answers, evidence packs, get_function, or get_neighbors.
  • Canonical answer questions: call find_canonical_answers for the user's wording, then get_canonical_answer for the best passing topic. Inspect quality.md and gaps.md; use degraded topics only with caveats, and use failed topics only as retrieval hints. Cite the canonical topic id alongside EA, function name, and artifact path.
  • Broad natural-language questions: call plan_kernel_answer and follow its selected canonical candidates, live retrieval steps, citation contract, and stop conditions before drafting. The planner does not generate final prose.
  • Lifecycle questions: call trace_lifecycle first with topic such as process_object, thread_object, file_object, driver_object, device_object, registry_key, section_object, or module_image, then inspect high-impact functions with get_function, and use get_neighbors for ambiguous transitions.
  • Function questions: use search_functions or exact EA lookup with get_function; request disassembly when pseudocode precision matters, inspect data refs, then cite cleaned/raw/disassembly/summary artifact paths.
  • Subsystem questions: generate or inspect atlas pages first when available; then search by names, tags, imports, and strings; expand nearby callers/callees; build an evidence pack for broad answers.
  • Import/string/data-reference questions: use search_by_import, search_by_string, or search_by_data_ref, then verify with get_function.
  • Broad answers: prefer a passing canonical answer when available, then call build_evidence_pack or trace_lifecycle for verification, gap filling, or unsupported topic boundaries.
  • Freshness checks: use validate_pack.py before reusing older pack roots, lifecycle evidence packs, or atlas pages. Treat validator errors as stop-and-rebuild signals.
  • Durable handoff or review: call the local answer harness to generate the bounded prompt and validate the drafted Markdown answer. For repeatable workflow regression, run answer_eval.py against the pack and drafted answers.

Canonical Answer Workflow

Use canonical answers as the first evidence layer only after freshness and quality checks:

  1. Validate pack freshness before trusting canonical artifacts.
  2. Call find_canonical_answers for natural-language questions, or list_canonical_answers when filtering by priority, mode, or quality status.
  3. Prefer canonical answers with quality.status == pass and zero validation warnings.
  4. Inspect quality.md and gaps.md before making polished claims.
  5. Use live retrieval with search_functions, get_function, get_neighbors, or trace_lifecycle to verify high-impact claims and fill gaps.
  6. Cite canonical topic id, EA, function name, and artifact path for important claims.

Decision matrix:

StateAction
canonical pass + fresh packUse as first evidence layer, then verify high-impact claims.
canonical degraded + fresh packUse only with explicit caveats and live verification of gaps.
canonical fail + fresh packDo not use as final-answer evidence; use only as a tuning or retrieval hint.
canonical missing + fresh packRun live retrieval or generate the missing topic bundle.
canonical present + stale packRebuild or warn before use; stale canonical artifacts do not override fresh corpus evidence.

If a review queue exists, prefer topics with review_state == approved and quality.status == pass. Treat pass without approval as generated but unreviewed, not as human-reviewed truth. Treat stale approvals as review debt.

Canonical answers never override fresher function artifacts. If live retrieval contradicts a canonical draft, cite the fresh evidence and call out the canonical artifact as stale, degraded, or needing regeneration.

Show full SKILL.md (537 more words)Show less

Evidence Discipline

  • Cite EA, function name, and artifact path for important claims.
  • Separate confirmed corpus evidence from inference.
  • Treat lifecycle phase labels and LLM rename suggestions as hypotheses until supported by function evidence or edges.
  • Expect broad graph-neighbor lifecycle candidates from another object topic to be lower-quality unless the evidence pack records exact seed or target-topic evidence.
  • State gaps from skipped functions, missing exact seeds, missing edges, stale packs, or low-confidence phase assignments.
  • Do not claim a transition is proven unless the evidence pack contains a supporting edge or function relationship.
  • Do not hide validator errors. Rebuild stale packs or derived artifacts before answering, unless the user explicitly wants a stale-pack comparison.
  • Treat answer harness warnings as citation lint that must be reviewed before reusing an answer.
  • Treat answer eval results as routing and citation regression signals, not expert review of the final reverse-engineering conclusion.
  • Treat canonical quality status as retrieval quality metadata: pass can be used as the first evidence layer, degraded requires explicit caveats and live verification, and fail is not final-answer evidence.
  • For drift answers, cite both pack labels or roots, canonical topic id, function name, both EAs when relevant, and artifact paths from both sides. Do not describe different EAs as semantic drift unless function evidence or selected role/edge/phase changes support that inference.
  • Treat knowledge graph bridge functions, shared-function counts, topic paths, and centrality-like observations as navigation hints. Do not present them as proof without function artifacts or evidence packs.
  • Do not mutate the source corpus or IDB. Writing a derived evidence pack is acceptable only when the workflow or user asks for a durable artifact.

Korean Query Mapping

Map Korean questions into corpus search terms and lifecycle topics before retrieval:

Korean intentUse topic/query terms
프로세스 생성/종료/삭제process_object, process, create process, exit process, delete process, Psp*Process
스레드 생성/종료/삭제thread_object, thread, create thread, exit thread, delete thread, Psp*Thread
파일 오브젝트 생성/닫기/삭제file_object, file object, create file, close file, delete file, NtCreateFile, Iop*File
드라이버 오브젝트 로드/언로드driver_object, driver object, load driver, unload driver, DriverEntry, Iop*Driver
디바이스 오브젝트 생성/삭제device_object, device object, create device, delete device, attach device, IoCreateDevice, IoDeleteDevice
섹션/맵드 뷰 생성/해제section_object, section object, create section, map view, unmap view, NtCreateSection, NtMapViewOfSection
모듈/이미지 로드/언로드module_image, image load, system image, load image notify, MmLoadSystemImage, PspCallImageNotifyRoutines
오브젝트/참조/삭제object, ObInsertObject, ObReferenceObject, ObDereferenceObject, delete
핸들/핸들 테이블handle, object table, handle table, ObReferenceObjectByHandle
IOCTL/디스패치ioctl, device control, IRP_MJ_DEVICE_CONTROL, dispatch
메모리/풀/매핑memory, pool, allocate, map, section, Mm
레지스트리registry_key, registry, Cm, NtCreateKey, ZwQueryValueKey, ZwSetValueKey
보안/토큰/권한security, token, privilege, Se, access check
콜백/노티파이callback, notify, PsSet*NotifyRoutine, PspCall*Notify*
로드/언로드load, unload, DriverEntry, Unload, PsSetLoadImageNotifyRoutine

Lifecycle Answer Contract

Use this shape for lifecycle questions:

markdown
Overall flow:
1. Entry
2. Allocation and initialization
3. Object insertion and visibility
4. Notification side paths
5. Exit and rundown
6. Final dereference and delete

Major functions:
- `0x...` `FunctionName`: role, phase confidence, artifact path.

Confirmed from this corpus:
- Evidence-backed observations with EA/function/path citations.

Inference:
- Clearly marked reasoning that connects evidence.

Gaps:
- Missing edges, skipped functions, ambiguous phase assignments, or missing seeds.

Function Answer Contract

For a single function:

markdown
Identity:
- EA, name, tags, mode, artifact paths.

What this function appears to do:
- Evidence-backed summary from cleaned/raw/disassembly/summary artifacts and data refs.

Callgraph/import/string/data-reference evidence:
- Direct callers/callees, imports, strings, data refs, and why they matter.

Confidence:
- Confirmed evidence vs inference, including warnings or missing artifacts.

Subsystem Atlas Contract

For a subsystem or broad flow:

markdown
Scope:
- Corpus status and retrieval query terms.

Core clusters:
- Function groups by role, with EA/name/path citations.

Edges and entry points:
- Caller/callee relationships that are present in the evidence pack.

Operational interpretation:
- What the evidence suggests, separated from assumptions.

Gaps and next retrieval:
- Missing tags, skipped functions, deeper neighbors, or extra evidence packs to build.

Atlas hub lists are filtered retrieval hints. Generic helpers and subsystem-unrelated neighbors may be intentionally absent; use get_neighbors for exhaustive graph expansion.

Guardrails

  • Do not copy generated ntoskrnl data into this skill.
  • Do not rely on memory or generic Windows behavior when corpus evidence is available.
  • Do not treat cleaned pseudocode as perfect; inspect raw, summary, and full-function disassembly artifacts when precision matters.
  • Do not hide uncertainty. A useful kernel answer can say "unknown from this corpus" and propose the next retrieval.

© kernullist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in tools/kernel_corpus/skills/kernel-corpus-analysis of kernullist/PseudoForge.

Open the folder on GitHubat commit 414aa57

Compare with similar skills

Kernel Corpus Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kernel Corpus Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kernel Corpus Analysis this skillkernullist/PseudoForge162—~3.7kAutomated safety check: PassMIT
Tiktok Account Auditaronhy/tiktok-agent-skills167—~492Automated safety check: PassMIT
Rev Unicorn Debugindex-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT
Karpathy Guidelinesindex-login/MobileRE-Skill111—~242Automated safety check: PassMIT
JS Reversesickn33/agentic-awesome-skills47k1 repos~1.8kAutomated safety check: PassMIT
Decompiler MCPpardeike/DecompilerServer105—~1.5kAutomated safety check: PassMIT

Similar skills

  • Tiktok Account Audit

    aronhy/tiktok-agent-skills

    A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research…

    167 GitHub stars~492 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    111 GitHub stars~1.9k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    111 GitHub stars~242 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • JS Reverse

    sickn33/agentic-awesome-skills

    Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.

    47k GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Decompiler MCP

    pardeike/DecompilerServer

    A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld…

    105 GitHub stars~1.5k tokensUpdated 6 days ago
    Game DevelopmentAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed

Categories

Questions about Kernel Corpus Analysis

What does Kernel Corpus Analysis do?

A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…. Kernel Corpus Analysis is an agent skill from kernullist/PseudoForge. Use when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string, and evidence-grounded reverse-engineering analysis.

When should I use Kernel Corpus Analysis?

Kernel Corpus Analysis fits situations like: answering questions about PseudoForge kernel corpus packs through MCP; local evidence packs; including kernel lifecycle; evidence-grounded reverse-engineering analysis.

How do I install Kernel Corpus Analysis in Claude Code?

Run `npx skills add kernullist/PseudoForge --skill kernel-corpus-analysis -a claude-code`. Or copy the skill folder (tools/kernel_corpus/skills/kernel-corpus-analysis in kernullist/PseudoForge) into .claude/skills/kernel-corpus-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Kernel Corpus Analysis in Codex?

Run `npx skills add kernullist/PseudoForge --skill kernel-corpus-analysis -a codex`. Or copy the skill folder (tools/kernel_corpus/skills/kernel-corpus-analysis in kernullist/PseudoForge) into .agents/skills/kernel-corpus-analysis in your project. Codex loads it when a task matches its description.

Can I use Kernel Corpus Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kernullist/PseudoForge --skill kernel-corpus-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kernel-corpus-analysis, .gemini/skills/kernel-corpus-analysis, .github/skills/kernel-corpus-analysis and .opencode/skills/kernel-corpus-analysis in your project.

What does Kernel Corpus Analysis need to run?

Going by SKILL.md and its folder, Kernel Corpus Analysis needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Kernel Corpus Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kernel Corpus Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kernel Corpus Analysis use?

Kernel Corpus Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kernel Corpus Analysis use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kernel Corpus Analysis?

Skills that share tags, products or a category with Kernel Corpus Analysis: Tiktok Account Audit (aronhy/tiktok-agent-skills, 167 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 111 stars), Karpathy Guidelines (index-login/MobileRE-Skill, 111 stars) and JS Reverse (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kernel Corpus Analysis?

kernullist (a GitHub user) maintains it in kernullist/PseudoForge, which has 162 GitHub stars. The repository was last updated on July 7, 2026.

Source: kernullist/PseudoForge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.