Agent skill

vphone600 Kernel Symbol Analysis

by Lakr233 in Lakr233/vphone-cli

Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

MITAuto-check passedSecurity

Install vphone600 Kernel Symbol Analysis

skills CLI
$ npx skills add Lakr233/vphone-cli --skill kernel-analysis-vphone600 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Lakr233/vphone-cli kernel-analysis-vphone600 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Lakr233/vphone-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/kernel-analysis-vphone600 .claude/skills/kernel-analysis-vphone600 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kernel-analysis-vphone600
GitHub stars
15k
Token cost
~530 tokens
SKILL.md length
180 words
Files
3 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

  • Works in 5 steps: Confirm scope is vphone600 only. → Query kernel_symbols.db to select… → Load the linked JSON symbol file and… → …
  • Resolving an address to a symbol in a vphone600 kernelcache
  • SKILL.md covers Required Paths, Workflow, Output Rules and References
  • Calls git; reaches github.com

What it does

A local symbol dataset under Research/KernelSymbols is treated as the first source of truth for the vphone600 kernel, and the XNU source tree at Research/Reference/xnu serves as the reference for semantics and structure. The dataset consists of a database named kernel_symbols.db, a tab-separated index and JSON symbol files for the release and research kernelcaches.

The workflow confirms the scope is vphone600 only, queries the database to choose the release or research dataset, loads the linked JSON symbol file to look up symbols or addresses, and cross-references candidate code paths in XNU. If the XNU folder is missing, it is created with a shallow clone of Apple's open source distribution. Paths stored in the data refer to the machine where symbolication ran, so the JSON files are resolved from the local json folder instead.

Reports must name the kernel used, give exact symbol names and addresses when available, mark which statements are fact and which are inference when mapping symbols to XNU behavior, and avoid claims beyond vphone600. A reference note holds reusable SQL and shell query snippets.

When your agent uses it

  • Resolving an address to a symbol in a vphone600 kernelcache
  • Comparing the release and research kernels for differences
  • Analyzing a kernel patch against the matching XNU source

Example prompts

  • “Look up which symbol contains this address in the research kernel and show the nearby XNU code.”
  • “Compare how the release and research vphone600 kernels differ for this function.”
  • “Find the symbol path and address for the function that handles this syscall in the release kernel.”

Requirements

  • The Research/KernelSymbols dataset in the repository
  • Git, to clone the XNU source into Research/Reference/xnu if it is missing

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm scope is vphone600 only.
  2. Query kernel_symbols.db to select release or research dataset by name.
  3. Load the linked JSON symbol file and perform symbol/address lookups.
  4. Cross-reference candidate code paths in Research/Reference/xnu.
  5. Report findings with explicit kernel name, symbol path, and address.

What it can do on your machine

Read from SKILL.md and the folder at commit 625f6c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

vphone600 Kernel Symbol Analysis loads about 530 tokens when it runs, and up to ~886 if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 180 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~530
With references · SKILL.md plus every file in references/, read only if the agent opens them
~886

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Lakr233/vphone-cli at commit 625f6c6, republished under its MIT licence (© Lakr233). 180 words, ~530 tokens.

Download SKILL.mdSave it as .claude/skills/kernel-analysis-vphone600/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
kernel-analysis-vphone600
description
Analyze vphone600 kernel artifacts using the local symbol database and XNU source tree. Use when working on kernel reverse engineering, address-to-symbol lookup, release-vs-research kernel comparison, or patch analysis for vphone600 variants in this repository.

Kernel Analysis Vphone600

Use the local Research/KernelSymbols dataset as the first source of truth for symbol lookup. Use Research/Reference/xnu as the source-level reference for semantics and structure.

Required Paths

  • Research/KernelSymbols/kernel_symbols.db
  • Research/KernelSymbols/kernel_index.tsv (plain-text kernel_name → json_path index with json_sha256)
  • Research/KernelSymbols/json/ — the recovered symbol datasets:
    • kernelcache.release.vphone600.bin.symbols.json
    • kernelcache.research.vphone600.bin.symbols.json
  • Research/Reference/xnu

The json_path column in both the database and kernel_index.tsv records the absolute path from symbolication time and may not match this checkout; resolve the JSON files under Research/KernelSymbols/json/ instead.

If Research/Reference/xnu is missing, create it with a shallow clone:

bash
mkdir -p Research/Reference
git clone --depth 1 https://github.com/apple-oss-distributions/xnu.git Research/Reference/xnu

Workflow

  1. Confirm scope is vphone600 only.
  2. Query kernel_symbols.db to select release or research dataset by name.
  3. Load the linked JSON symbol file and perform symbol/address lookups.
  4. Cross-reference candidate code paths in Research/Reference/xnu.
  5. Report findings with explicit kernel name, symbol path, and address.

Output Rules

  • Always include which kernel was used: kernelcache.release.vphone600 or kernelcache.research.vphone600.
  • Always include exact symbol name and address when available.
  • Always distinguish fact from inference when mapping symbols to XNU behavior.
  • Avoid claiming coverage outside vphone600 unless explicitly requested.

References

  • Read references/kernel-info-queries.md for reusable SQL and shell query snippets.

© Lakr233, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in Skills/kernel-analysis-vphone600 of Lakr233/vphone-cli.

  • SKILL.md
  • agents/openai.yaml
  • references/kernel-info-queries.md

Open the folder on GitHubat commit 625f6c6

Compare with similar skills

vphone600 Kernel Symbol Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

vphone600 Kernel Symbol Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
vphone600 Kernel Symbol Analysis this skillLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Penetration Flowlingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT

Similar skills

  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated today
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Openfasttrace Reverse Specs

    itsallcode/openfasttrace

    Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.

    197 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from Lakr233/vphone-cli

  • Authoring VPhone Patch Sets

    Lakr233/vphone-cli

    Explains how to declare a firmware patch in a vphone patch set, add a new set, or write a preset, including naming, gating and the checks that catch undeclared patches.

    15k GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • VPhone Guest Control

    Lakr233/vphone-cli

    Drives a virtual iPhone running on an Apple Silicon Mac through the vphone-launchpad-cli, from checking host setup and starting a machine to tapping, typing and installing apps in the guest.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Categories

Questions about vphone600 Kernel Symbol Analysis

What does vphone600 Kernel Symbol Analysis do?

Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference. A local symbol dataset under Research/KernelSymbols is treated as the first source of truth for the vphone600 kernel, and the XNU source tree at Research/Reference/xnu serves as the reference for semantics and structure.db, a tab-separated index and JSON symbol files for the release and research kernelcaches.

When should I use vphone600 Kernel Symbol Analysis?

vphone600 Kernel Symbol Analysis fits situations like: resolving an address to a symbol in a vphone600 kernelcache; comparing the release and research kernels for differences; analyzing a kernel patch against the matching XNU source.

How do I install vphone600 Kernel Symbol Analysis in Claude Code?

Run `npx skills add Lakr233/vphone-cli --skill kernel-analysis-vphone600 -a claude-code`. Or copy the skill folder (Skills/kernel-analysis-vphone600 in Lakr233/vphone-cli) into .claude/skills/kernel-analysis-vphone600 in your project. Claude Code loads it when a task matches its description.

How do I install vphone600 Kernel Symbol Analysis in Codex?

Run `npx skills add Lakr233/vphone-cli --skill kernel-analysis-vphone600 -a codex`. Or copy the skill folder (Skills/kernel-analysis-vphone600 in Lakr233/vphone-cli) into .agents/skills/kernel-analysis-vphone600 in your project. Codex loads it when a task matches its description.

Can I use vphone600 Kernel Symbol Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Lakr233/vphone-cli --skill kernel-analysis-vphone600 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kernel-analysis-vphone600, .gemini/skills/kernel-analysis-vphone600, .github/skills/kernel-analysis-vphone600 and .opencode/skills/kernel-analysis-vphone600 in your project.

What does vphone600 Kernel Symbol Analysis need to run?

Going by SKILL.md and its folder, vphone600 Kernel Symbol Analysis needs the command-line tools its instructions call (git). Our summary lists: The Research/KernelSymbols dataset in the repository; Git, to clone the XNU source into Research/Reference/xnu if it is missing.

Does vphone600 Kernel Symbol Analysis access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is vphone600 Kernel Symbol Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does vphone600 Kernel Symbol Analysis use?

vphone600 Kernel Symbol Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does vphone600 Kernel Symbol Analysis use?

About 530 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 356 tokens, read only when the agent opens those files.

What are the alternatives to vphone600 Kernel Symbol Analysis?

Skills that share tags, products or a category with vphone600 Kernel Symbol Analysis: Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars) and Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains vphone600 Kernel Symbol Analysis?

Lakr233 (a GitHub user) maintains it in Lakr233/vphone-cli, which has 15,070 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.

Source: Lakr233/vphone-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.