Agent skill

Analyzing Linux Elf Malware

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…

Apache-2.0Auto-check: warningsSecurity

Install Analyzing Linux Elf Malware

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-linux-elf-malware -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-linux-elf-malware --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-linux-elf-malware .claude/skills/analyzing-linux-elf-malware && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-linux-elf-malware
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
618 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…

  • Works in 6 steps: Identify ELF Binary Properties → Extract Strings and Indicators → Analyze System Calls and Library Usage → …
  • Investigating Linux malware
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls sh, wget and curl

What it does

Analyzing Linux Elf Malware is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and reverse engineering of x8664 and ARM samples. Use when investigating Linux malware, triaging a suspicious ELF binary, assessing a compromised Linux server, or analyzing container-targeted malware.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Linux administration, Reverse engineering and malware and Static analysis and SAST. It works with Linux and Ghidra. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Investigating Linux malware
  • Triaging a suspicious ELF binary
  • Assessing a compromised Linux server
  • Analyzing container-targeted malware

Example prompts

  • “/analyzing-linux-elf-malware”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify ELF Binary Properties
  2. Extract Strings and Indicators
  3. Analyze System Calls and Library Usage
  4. Dynamic Analysis with GDB
  5. Reverse Engineer with Ghidra
  6. Analyze Linux-Specific Persistence

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • sh
    • wget
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use wget and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Linux Elf Malware loads about 3.1k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 618 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:167
    grep -iE "(ssh|authorized_keys|id_rsa|shadow|passwd)" strings_output.txt

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 618 words, ~3,119 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-linux-elf-malware/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-linux-elf-malware
description
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM samples. Use when investigating Linux malware, triaging a suspicious ELF binary, assessing a compromised Linux server, or analyzing container-targeted malware.
domain
cybersecurity
subdomain
malware-analysis
tags
malware, Linux, ELF, reverse-engineering, server-malware
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
DE.AE-02, RS.AN-03, ID.RA-01, DE.CM-01
mitre_attack
T1027, T1059.004, T1620, T1574.006
mitre_f3.version
1.1
mitre_f3.tactics
positioning, monetization, reconnaissance

Analyzing Linux ELF Malware

When to Use

  • A Linux server or container has been compromised and suspicious ELF binaries are found
  • Analyzing Linux botnets (Mirai, Gafgyt, XorDDoS), cryptominers, or ransomware
  • Investigating malware targeting cloud infrastructure, Docker containers, or Kubernetes pods
  • Reverse engineering Linux rootkits and kernel modules
  • Analyzing cross-platform malware compiled for Linux x86_64, ARM, or MIPS architectures

Do not use for Windows PE binary analysis; use PEStudio, Ghidra, or IDA for Windows malware.

Prerequisites

  • Ghidra or IDA with Linux ELF support for disassembly and decompilation
  • Linux analysis VM (Ubuntu 22.04 recommended) with development tools installed
  • strace, ltrace, and GDB for dynamic analysis and debugging
  • readelf, objdump, and nm from GNU binutils for static inspection
  • Radare2 for quick binary triage and scripted analysis
  • Docker for isolated container-based malware execution

Workflow

Step 1: Identify ELF Binary Properties

Examine the ELF header and basic properties:

bash
# File type identification
file suspect_binary

# Detailed ELF header analysis
readelf -h suspect_binary

# Section headers
readelf -S suspect_binary

# Program headers (segments)
readelf -l suspect_binary

# Symbol table (if not stripped)
readelf -s suspect_binary
nm suspect_binary 2>/dev/null

# Dynamic linking information
readelf -d suspect_binary
ldd suspect_binary 2>/dev/null  # Only on matching architecture!

# Compute hashes
md5sum suspect_binary
sha256sum suspect_binary

# Check for packing/UPX
upx -t suspect_binary
python
# Python-based ELF analysis
from elftools.elf.elffile import ELFFile
import hashlib

with open("suspect_binary", "rb") as f:
    data = f.read()
    sha256 = hashlib.sha256(data).hexdigest()

with open("suspect_binary", "rb") as f:
    elf = ELFFile(f)

    print(f"SHA-256:      {sha256}")
    print(f"Class:        {elf.elfclass}-bit")
    print(f"Endian:       {elf.little_endian and 'Little' or 'Big'}")
    print(f"Machine:      {elf.header.e_machine}")
    print(f"Type:         {elf.header.e_type}")
    print(f"Entry Point:  0x{elf.header.e_entry:X}")

    # Check if stripped
    symtab = elf.get_section_by_name('.symtab')
    print(f"Stripped:     {'Yes' if symtab is None else 'No'}")

    # Section entropy analysis
    import math
    from collections import Counter
    for section in elf.iter_sections():
        data = section.data()
        if len(data) > 0:
            entropy = -sum((c/len(data)) * math.log2(c/len(data))
                          for c in Counter(data).values() if c > 0)
            if entropy > 7.0:
                print(f"  [!] High entropy section: {section.name} ({entropy:.2f})")
Step 2: Extract Strings and Indicators

Search for embedded IOCs and functionality clues:

bash
# ASCII strings
strings suspect_binary > strings_output.txt

# Search for network indicators
grep -iE "(http|https|ftp)://" strings_output.txt
grep -iE "([0-9]{1,3}\.){3}[0-9]{1,3}" strings_output.txt
grep -iE "[a-zA-Z0-9.-]+\.(com|net|org|io|ru|cn)" strings_output.txt

# Search for shell commands
grep -iE "(bash|sh|wget|curl|chmod|/tmp/|/dev/)" strings_output.txt

# Search for crypto mining indicators
grep -iE "(stratum|xmr|monero|pool\.|mining)" strings_output.txt

# Search for SSH/credential theft
grep -iE "(ssh|authorized_keys|id_rsa|shadow|passwd)" strings_output.txt

# Search for persistence mechanisms
grep -iE "(crontab|systemd|init\.d|rc\.local|ld\.so\.preload)" strings_output.txt

# FLOSS for obfuscated strings (if available)
floss suspect_binary
Step 3: Analyze System Calls and Library Usage

Identify what system calls and libraries the malware uses:

bash
# List imported functions (dynamically linked)
readelf -r suspect_binary | grep -E "socket|connect|exec|fork|open|write|bind|listen"

# Trace system calls during execution (in isolated VM only)
strace -f -e trace=network,process,file -o strace_output.txt ./suspect_binary

# Trace library calls
ltrace -f -o ltrace_output.txt ./suspect_binary

# Key system calls to watch:
# Network: socket, connect, bind, listen, accept, sendto, recvfrom
# Process: fork, execve, clone, kill, ptrace
# File:    open, read, write, unlink, rename, chmod
# Persistence: inotify_add_watch (file monitoring)
Step 4: Dynamic Analysis with GDB

Debug the malware to observe runtime behavior:

bash
# Start GDB with the binary
gdb ./suspect_binary

# Set breakpoints on key functions
(gdb) break main
(gdb) break socket
(gdb) break connect
(gdb) break execve
(gdb) break fork

# Run and analyze
(gdb) run
(gdb) info registers    # View register state
(gdb) x/20s $rdi        # Examine string argument
(gdb) bt                # Backtrace
(gdb) continue

# For stripped binaries, break on entry point
(gdb) break *0x400580   # Entry point from readelf
(gdb) run

# Monitor network connections during execution
# In another terminal:
ss -tlnp  # List listening sockets
ss -tnp   # List established connections
Step 5: Reverse Engineer with Ghidra

Perform deep code analysis on the ELF binary:

Ghidra Analysis for Linux ELF:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. Import: File -> Import -> Select ELF binary
   - Ghidra auto-detects ELF format and architecture
   - Accept default analysis options

2. Key analysis targets:
   - main() function (or entry point if stripped)
   - Socket creation and connection functions
   - Command dispatch logic (switch/case on received data)
   - Encryption/encoding routines
   - Persistence installation code
   - Self-propagation/scanning functions

3. For Mirai-like botnets, look for:
   - Credential list for brute-forcing (telnet/SSH)
   - Attack module selection (UDP flood, SYN flood, ACK flood)
   - Scanner module (port scanning for vulnerable devices)
   - Killer module (killing competing botnets)

4. For cryptominers, look for:
   - Mining pool connection (stratum protocol)
   - Wallet address strings
   - CPU/GPU utilization functions
   - Process hiding techniques
Step 6: Analyze Linux-Specific Persistence

Check for persistence mechanisms:

bash
# Check for LD_PRELOAD rootkit
strings suspect_binary | grep "ld.so.preload"
# Malware writing to /etc/ld.so.preload can hook all dynamic library calls

# Check for crontab persistence
strings suspect_binary | grep -i "cron"

# Check for systemd service creation
strings suspect_binary | grep -iE "systemd|\.service|systemctl"

# Check for init script creation
strings suspect_binary | grep -iE "init\.d|rc\.local|update-rc"

# Check for SSH key injection
strings suspect_binary | grep -i "authorized_keys"

# Check for kernel module (rootkit) loading
strings suspect_binary | grep -iE "insmod|modprobe|init_module"

# Check for process hiding
strings suspect_binary | grep -iE "proc|readdir|getdents"

Key Concepts

TermDefinition
ELF (Executable and Linkable Format)Standard binary format for Linux executables, shared libraries, and core dumps containing headers, sections, and segments
Stripped BinaryELF binary with debug symbols removed, making reverse engineering more difficult as function names are lost
LD_PRELOADLinux environment variable specifying shared libraries to load before all others; abused by rootkits to intercept system library calls
straceLinux system call tracer that logs all system calls and signals made by a process, revealing file, network, and process operations
GOT/PLTGlobal Offset Table and Procedure Linkage Table; ELF structures for dynamic linking that can be hijacked for function hooking
Statically LinkedBinary compiled with all library code included; common in IoT malware to run on systems without matching shared libraries
MiraiProlific Linux botnet targeting IoT devices via telnet brute-force; source code leaked, leading to many variants
Show full SKILL.md (266 more words)Show less

Tools & Systems

  • Ghidra: NSA reverse engineering tool with full ELF support for x86, x86_64, ARM, MIPS, and other Linux architectures
  • Radare2: Open-source reverse engineering framework with command-line interface for quick binary analysis and scripting
  • strace: Linux system call tracing tool for observing binary behavior including file, network, and process operations
  • GDB: GNU Debugger for setting breakpoints, examining memory, and stepping through Linux binary execution
  • pyelftools: Python library for parsing ELF files programmatically for automated analysis pipelines

Common Scenarios

Scenario: Analyzing a Cryptominer Found on a Compromised Linux Server

Context: A cloud server shows 100% CPU usage. Investigation reveals an unknown binary running from /tmp with a suspicious name. The binary needs analysis to confirm it is a cryptominer and identify the attacker's wallet and pool.

Approach:

  1. Copy the binary to an analysis VM and compute SHA-256 hash
  2. Run file and readelf to identify architecture and linking type
  3. Extract strings and search for mining pool addresses (stratum+tcp://) and wallet addresses
  4. Run with strace in a sandbox to observe network connections (mining pool connection)
  5. Import into Ghidra to identify the mining algorithm and configuration extraction
  6. Check for persistence mechanisms (crontab, systemd service, SSH keys)
  7. Document all IOCs including pool address, wallet, C2 for updates, and persistence artifacts

Pitfalls:

  • Running ldd on malware outside a sandbox (ldd can execute code in the binary)
  • Not checking for ARM/MIPS architecture before attempting x86_64 execution
  • Missing companion scripts (.sh files) that may handle persistence and cleanup
  • Ignoring the initial access vector (how the miner was deployed: SSH brute force, web exploit, container escape)

Output Format

LINUX ELF MALWARE ANALYSIS REPORT
====================================
File:             /tmp/.X11-unix/.rsync
SHA-256:          e3b0c44298fc1c149afbf4c8996fb924...
Type:             ELF 64-bit LSB executable, x86-64
Linking:          Statically linked (all libraries embedded)
Stripped:         Yes
Size:             2,847,232 bytes
Packer:           UPX 3.96 (unpacked for analysis)

CLASSIFICATION
Family:           XMRig Cryptominer (modified)
Variant:          Custom build with C2 update mechanism

FUNCTIONALITY
[*] XMR (Monero) mining via RandomX algorithm
[*] Stratum pool connection for work submission
[*] C2 check-in for configuration updates
[*] Process name masquerading (argv[0] = "[kworker/0:0]")
[*] Competitor process killing (kills other miners)
[*] SSH key injection for re-access

NETWORK INDICATORS
Mining Pool:      stratum+tcp://pool.minexmr[.]com:4444
C2 Server:        hxxp://update.malicious[.]com/config
Wallet:           49jZ5Q3b...Monero_Wallet_Address...

PERSISTENCE
[1] Crontab entry: */5 * * * * /tmp/.X11-unix/.rsync
[2] SSH key added to /root/.ssh/authorized_keys
[3] Systemd service: /etc/systemd/system/rsync-daemon.service
[4] Modified /etc/ld.so.preload for process hiding

PROCESS HIDING
LD_PRELOAD:       /usr/lib/.libsystem.so
Hook:             readdir() to hide /tmp/.X11-unix/.rsync from ls
Hook:             fopen() to hide from /proc/*/maps reading

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/analyzing-linux-elf-malware of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Analyzing Linux Elf Malware next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Linux Elf Malware compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Linux Elf Malware this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: WarnApache-2.0
Firmware Security ReportsOrbitCurve/firmware-reverse-engineering214—~4.1kAutomated safety check: PassApache-2.0
Re Riscvdslsdzc/rev-skills1251 repos~2.2kAutomated safety check: PassApache-2.0
Binary Reaiskillstore/marketplace4301 repos~2.6kAutomated safety check: PassNone
Re Armdslsdzc/rev-skills125—~2.2kAutomated safety check: PassApache-2.0
Ghidra ReOrbitCurve/firmware-reverse-engineering214—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Firmware Security Reports

    OrbitCurve/firmware-reverse-engineering

    Evidence-based security report generation for firmware assessments.

    214 GitHub stars~4.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Re Riscv

    dslsdzc/rev-skills

    RISC-V 架构逆向:RV32/RV64、压缩指令(RVC)、gp 相对寻址、ABI 与 ecall 系统调用约定、工具链指纹。

    125 GitHub starsUsed in 1 repo~2.2k tokens
    SecurityAuto-check passed
  • Binary Re

    aiskillstore/marketplace

    This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

    430 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Re Arm

    dslsdzc/rev-skills

    ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。

    125 GitHub stars~2.2k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    214 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Bench Experiment

    DavidClawson/OpenScope-2C53T

    Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.

    116 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Analyzing Linux Elf Malware

What does Analyzing Linux Elf Malware do?

Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…. Analyzing Linux Elf Malware is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and reverse engineering of x8664 and ARM samples.

When should I use Analyzing Linux Elf Malware?

Analyzing Linux Elf Malware fits situations like: investigating Linux malware; triaging a suspicious ELF binary; assessing a compromised Linux server; analyzing container-targeted malware.

How do I install Analyzing Linux Elf Malware in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-linux-elf-malware -a claude-code`. Or copy the skill folder (skills/analyzing-linux-elf-malware in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-linux-elf-malware in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Linux Elf Malware in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-linux-elf-malware -a codex`. Or copy the skill folder (skills/analyzing-linux-elf-malware in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-linux-elf-malware in your project. Codex loads it when a task matches its description.

Can I use Analyzing Linux Elf Malware in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-linux-elf-malware -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-linux-elf-malware, .gemini/skills/analyzing-linux-elf-malware, .github/skills/analyzing-linux-elf-malware and .opencode/skills/analyzing-linux-elf-malware in your project.

What does Analyzing Linux Elf Malware need to run?

Going by SKILL.md and its folder, Analyzing Linux Elf Malware needs Python for the scripts in its folder and the command-line tools its instructions call (sh, wget and curl). Our summary lists: Python 3; Docker.

Does Analyzing Linux Elf Malware access the network?

SKILL.md contains no URLs. Its commands use wget and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Analyzing Linux Elf Malware safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyzing Linux Elf Malware use?

Analyzing Linux Elf Malware is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Linux Elf Malware use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 782 tokens, read only when the agent opens those files.

What are the alternatives to Analyzing Linux Elf Malware?

Skills that share tags, products or a category with Analyzing Linux Elf Malware: Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 214 stars), Re Riscv (dslsdzc/rev-skills, 125 stars), Binary Re (aiskillstore/marketplace, 430 stars) and Re Arm (dslsdzc/rev-skills, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Linux Elf Malware?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.