Implementing Ransomware Kill Switch Detection
mukul975/Anthropic-Cybersecurity-Skills
Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.
OS development from scratch skill for bootloader through context switching.
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratch --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kernel/os-dev-scratch .claude/skills/os-dev-scratch && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .claude/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratch --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kernel/os-dev-scratch .agents/skills/os-dev-scratch && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .agents/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratch --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kernel/os-dev-scratch .cursor/skills/os-dev-scratch && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .cursor/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mohitmishra786/low-level-dev-skills.git --path skills/kernel/os-dev-scratch--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratch --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kernel/os-dev-scratch .gemini/skills/os-dev-scratch && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .gemini/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kernel/os-dev-scratch .github/skills/os-dev-scratch && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .github/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills os-dev-scratch --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kernel/os-dev-scratch .opencode/skills/os-dev-scratch && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "os-dev-scratch" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/kernel/os-dev-scratch into .opencode/skills/os-dev-scratch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "os-dev-scratch", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
os-dev-scratchOS development from scratch skill for bootloader through context switching.
Os Dev Scratch is an agent skill from mohitmishra786/low-level-dev-skills. OS development from scratch skill for bootloader through context switching. Use when building a minimal x86-64 OS, setting up GDT/IDT/page tables, writing keyboard/serial drivers, or using QEMU for kernel boot. Activates on queries about bootloader, long mode, page tables, IDT, PIC/APIC, xv6, or x8664-elf-gcc.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
brewgitmakeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Os Dev Scratch loads about 1.7k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 293 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 293 words, ~1,738 tokens.
.claude/skills/os-dev-scratch/SKILL.md (or your agent's skills folder).Guide agents through building a minimal operating system from scratch: bootloader stages (BIOS/GRUB vs UEFI/limine), 64-bit long mode setup with GDT and page tables, IDT and interrupt handlers, PIC/APIC configuration, basic keyboard and serial drivers, physical and virtual memory managers, context switching, with xv6-RISC-V as a reference architecture.
main()-kernel and cross-compiler x86_64-elf-gccBIOS path (legacy)
├── BIOS POST
├── MBR (512 bytes) → boot sector loads stage2
├── GRUB/multiboot → loads kernel ELF
└── kernel entry (_start)
UEFI path (modern)
├── UEFI firmware
├── EFI bootloader (limine, systemd-boot)
├── Loads kernel + initrd from ESP
└── kernel entry (handoff with memory map)# Cross-compiler for bare metal
brew install x86_64-elf-gcc x86_64-elf-binutils # macOS
# or build from source / apt install gcc-x86-64-elf
x86_64-elf-gcc --version
# QEMU for testing
qemu-system-x86_64 --versionLinker script essentials:
/* linker.ld */
ENTRY(_start)
SECTIONS {
. = 0x100000; /* 1MB — typical kernel load address */
.text : { *(.text .text.*) }
.rodata : { *(.rodata .rodata.*) }
.data : { *(.data .data.*) }
.bss : { *(.bss .bss.*) }
}x86_64-elf-gcc -ffreestanding -nostdlib -c kernel.c -o kernel.o
x86_64-elf-ld -T linker.ld kernel.o -o kernel.elf# QEMU direct kernel boot (no disk)
qemu-system-x86_64 \
-kernel kernel.elf \
-serial stdio \
-m 128M \
-no-reboot -no-shutdown
# With limine (UEFI)
qemu-system-x86_64 \
-bios /usr/share/ovmf/OVMF.fd \
-drive file=disk.img,format=raw \
-serial stdioProtected mode (32-bit) → enable PAE → setup 4-level page tables → enable long mode// Minimal GDT entry (64-bit flat segments)
struct gdt_entry {
uint16_t limit_low;
uint16_t base_low;
uint8_t base_mid;
uint8_t access;
uint8_t granularity;
uint8_t base_high;
} __attribute__((packed));
// Page table setup (4KB pages, identity map first 1GB)
uint64_t pml4[512] __attribute__((aligned(4096)));
uint64_t pdpt[512] __attribute__((aligned(4096)));
uint64_t pd[512] __attribute__((aligned(4096)));
void setup_paging(void) {
for (int i = 0; i < 512; i++)
pd[i] = (i * 0x200000) | 0x83; // 2MB huge pages
pdpt[0] = (uint64_t)pd | 0x03;
pml4[0] = (uint64_t)pdpt | 0x03;
__asm__ volatile("mov %0, %%cr3" :: "r"(pml4));
}struct idt_entry {
uint16_t offset_low;
uint16_t selector;
uint8_t ist;
uint8_t type_attr;
uint16_t offset_mid;
uint32_t offset_high;
uint32_t zero;
} __attribute__((packed));
// ISR stub (assembly) → common handler → dispatch by vector
void interrupt_handler(struct trap_frame *frame) {
if (frame->vector == 14) // page fault
handle_page_fault(frame->cr2, frame->error_code);
else if (frame->vector == 33) // keyboard IRQ remapped
keyboard_handler();
}# Test page fault
# QEMU monitor: info registers// Legacy PIC remapping (8259)
// Remap IRQ 0-15 to vectors 32-47
outb(0x20, 0x11); outb(0xA0, 0x11);
outb(0x21, 0x20); outb(0xA1, 0x28); // vector offsets
// ...
// Modern: use APIC/IOAPIC (ACPI MADT parsing)
// LAPIC timer for preemption// COM1 serial (0x3F8)
void serial_putc(char c) {
while ((inb(0x3F8 + 5) & 0x20) == 0);
outb(0x3F8, c);
}
// PS/2 keyboard scancode → ASCII lookup table
void keyboard_handler(void) {
uint8_t scancode = inb(0x60);
char c = scancode_to_ascii[scancode];
if (c) serial_putc(c);
outb(0x20, 0x20); // EOI to PIC
}qemu-system-x86_64 -kernel kernel.elf -serial stdio
# printk output appears in terminal// Bitmap allocator over usable RAM regions
// From multiboot memory map or UEFI memory map
#define PAGE_SIZE 4096
uint8_t *frame_bitmap;
uint64_t total_frames;
uint64_t alloc_frame(void) {
for (uint64_t i = 0; i < total_frames; i++) {
if (!test_bit(frame_bitmap, i)) {
set_bit(frame_bitmap, i);
return i * PAGE_SIZE;
}
}
return 0; // OOM
}struct context {
uint64_t rax, rbx, rcx, rdx, rsi, rdi, rbp, rsp;
uint64_t r8, r9, r10, r11, r12, r13, r14, r15;
uint64_t rip;
};
void switch_context(struct context *old, struct context *new);
// Assembly: save callee-saved regs to old, restore from new, ret to new->ripCooperative scheduling first; add timer IRQ preemption later.
git clone https://github.com/mit-pdos/xv6-riscv
cd xv6-riscv && make qemu| xv6 component | x86 equivalent |
|---|---|
kernel/vm.c | Page table management |
kernel/trap.c | IDT/interrupt dispatch |
kernel/proc.c | Context switch, scheduler |
kernel/plic.c | PIC/APIC interrupt controller |
user/usys.pl | System call stubs |
| Symptom | Cause | Fix |
|---|---|---|
| Triple fault on boot | Invalid GDT/IDT or stack | Set up stack before enabling interrupts |
| QEMU black screen | No serial output configured | -serial stdio; early serial_init |
| Page fault in kernel | Unmapped address | Identity-map kernel; check CR3 |
| IRQ never fires | PIC mask or IDT not loaded | lidt; unmask IRQ in PIC |
| Timer doesn't tick | LAPIC not initialized | Parse ACPI; calibrate LAPIC timer |
| Linker relocation error | Wrong load address | Match linker.ld with bootloader expectation |
skills/low-level-programming/assembly-x86 — x86-64 assembly for ISR stubsskills/low-level-programming/assembly-riscv — xv6-RISC-V reference ISAskills/platform/riscv-privileged — RISC-V trap handling and page tablesskills/virtualization/qemu-kvm — QEMU flags for kernel developmentskills/kernel/kernel-internals — Linux implementation of these conceptsskills/low-level-programming/linux-kernel-modules — graduate to Linux once basics work© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/kernel/os-dev-scratch of mohitmishra786/low-level-dev-skills.
Open the folder on GitHubat commit bdc5847
Os Dev Scratch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Os Dev Scratch this skillmohitmishra786/low-level-dev-skills | 253 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Implementing Ransomware Kill Switch Detectionmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Wiki SwitchAr9av/obsidian-wiki | 3.5k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Switch Personaopenakita/openakita | 2k | — | ~286 | Automated safety check: Pass | AGPL-3.0 | |
| Kermt Pretrain ScratchNVIDIA/skills | 3.5k | 1 repos | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Bio Isoform SwitchingFreedomIntelligence/OpenClaw-Medical-Skills | 3.1k | — | ~1.5k | Automated safety check: Pass | None |
mukul975/Anthropic-Cybersecurity-Skills
Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.
Ar9av/obsidian-wiki
List, create, or switch named Obsidian wiki vault profiles under the global config directory.
openakita/openakita
Switch Agent persona preset. An agent skill from openakita/openakita.
NVIDIA/skills
Pretrain a fresh KERMT model from scratch on a user-provided corpus.
FreedomIntelligence/OpenClaw-Medical-Skills
Analyzes isoform switching events and functional consequences using IsoformSwitchAnalyzeR.
mohitagw15856/pm-claude-skills
Summarise what Credit From Scratch does in one line. An agent skill from mohitagw15856/pm-claude-skills.
mohitmishra786/low-level-dev-skills
Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.
mohitmishra786/low-level-dev-skills
Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.
mohitmishra786/low-level-dev-skills
Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.
mohitmishra786/low-level-dev-skills
Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.
mohitmishra786/low-level-dev-skills
Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.
mohitmishra786/low-level-dev-skills
GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.
OS development from scratch skill for bootloader through context switching. Os Dev Scratch is an agent skill from mohitmishra786/low-level-dev-skills. OS development from scratch skill for bootloader through context switching.
Os Dev Scratch fits situations like: building a minimal x86-64 OS; setting up GDT/IDT/page tables; writing keyboard/serial drivers; using QEMU for kernel boot.
Run `npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a claude-code`. Or copy the skill folder (skills/kernel/os-dev-scratch in mohitmishra786/low-level-dev-skills) into .claude/skills/os-dev-scratch in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a codex`. Or copy the skill folder (skills/kernel/os-dev-scratch in mohitmishra786/low-level-dev-skills) into .agents/skills/os-dev-scratch in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill os-dev-scratch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/os-dev-scratch, .gemini/skills/os-dev-scratch, .github/skills/os-dev-scratch and .opencode/skills/os-dev-scratch in your project.
Going by SKILL.md and its folder, Os Dev Scratch needs the command-line tools its instructions call (brew, git and make).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Os Dev Scratch is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Os Dev Scratch: Implementing Ransomware Kill Switch Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Wiki Switch (Ar9av/obsidian-wiki, 3.5k stars), Switch Persona (openakita/openakita, 2k stars) and Kermt Pretrain Scratch (NVIDIA/skills, 3.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.
Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.