Agent skill

Performing Firmware Extraction With Binwalk

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material.

Apache-2.0Auto-check passedSecurity

Install Performing Firmware Extraction With Binwalk

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-extraction-with-binwalk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-extraction-with-binwalk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-firmware-extraction-with-binwalk .claude/skills/performing-firmware-extraction-with-binwalk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-firmware-extraction-with-binwalk
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
681 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material.

  • Works in 6 steps: Initial Firmware Reconnaissance → Entropy Analysis → Extract Embedded Files → …
  • Tasks that involve Embedded systems
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls pip

What it does

Performing Firmware Extraction With Binwalk is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Embedded systems, Reverse engineering and malware and Security review. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Embedded systems
  • Tasks that involve Reverse engineering and malware
  • Tasks that involve Security review

Example prompts

  • “Use the performing-firmware-extraction-with-binwalk skill to perform firmware image extraction and analysis using binwalk to identify embedded…”
  • “/performing-firmware-extraction-with-binwalk”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Initial Firmware Reconnaissance
  2. Entropy Analysis
  3. Extract Embedded Files
  4. Mount and Inspect Extracted Filesystems
  5. String Analysis and Credential Discovery
  6. Generate Firmware Analysis Report

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Firmware Extraction With Binwalk loads about 2.8k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 149 tokens; SKILL.md has 681 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 681 words, ~2,782 tokens.

Download SKILL.mdSave it as .claude/skills/performing-firmware-extraction-with-binwalk/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-firmware-extraction-with-binwalk
description
Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.
domain
cybersecurity
subdomain
firmware-analysis
tags
firmware, binwalk, extraction, entropy, IoT-security, reverse-engineering
version
1.0.0
author
mukul975
license
Apache-2.0
nist_csf
ID.RA-01, PR.PS-01, DE.AE-02
mitre_attack
T1078, T1190, T1059, T1003, T1110
mitre_f3.version
1.1
mitre_f3.tactics
reconnaissance, initial-access

Performing Firmware Extraction with Binwalk

When to Use

  • Analyzing IoT device firmware downloaded from vendor sites or extracted from flash chips
  • Reverse engineering router, camera, or embedded device firmware for vulnerability research
  • Identifying embedded filesystems (SquashFS, CramFS, JFFS2, UBIFS) within firmware blobs
  • Detecting encrypted or compressed regions using entropy analysis
  • Extracting hardcoded credentials, API keys, certificates, or configuration files from firmware
  • Performing security assessments of embedded devices in authorized penetration tests

Do not use for analyzing standard desktop application binaries or malware samples that are not firmware images; use dedicated malware analysis tools instead.

Prerequisites

  • binwalk v3.x installed (pip install binwalk3 or from system package manager)
  • Python 3.8+ with standard libraries (struct, math, hashlib, subprocess)
  • SquashFS tools (unsquashfs) for mounting extracted SquashFS filesystems
  • Jefferson for JFFS2 filesystem extraction (pip install jefferson)
  • Sasquatch for non-standard SquashFS variants used by vendors like TP-Link and D-Link
  • strings utility (GNU binutils) for string extraction
  • Optional: firmware-mod-kit for repacking modified firmware images

Workflow

Step 1: Initial Firmware Reconnaissance

Perform a signature scan to identify embedded file types and their offsets:

bash
# Basic signature scan - identify all recognized file types
binwalk firmware.bin

# Scan with verbose output showing confidence levels
binwalk -v firmware.bin

# Scan for specific file types only
binwalk -y "squashfs" firmware.bin
binwalk -y "gzip\|lzma\|xz" firmware.bin

# Opcode scan to identify CPU architecture
binwalk -A firmware.bin

# Scan for raw strings to find version info, URLs, credentials
binwalk -R "password" firmware.bin
binwalk -R "http://" firmware.bin
Step 2: Entropy Analysis

Analyze entropy to identify encrypted, compressed, and plaintext regions:

bash
# Generate entropy plot
binwalk -E firmware.bin

# Entropy with specific block size for higher resolution
binwalk -E -K 256 firmware.bin

# Combined entropy and signature scan
binwalk -BE firmware.bin

Interpreting entropy values:

  • 0.0 - 1.0: Empty or padding regions (null bytes, 0xFF fill)
  • 1.0 - 5.0: Plaintext data, code, ASCII strings, configuration
  • 5.0 - 7.0: Compressed data (gzip, LZMA, zlib)
  • 7.0 - 7.99: Strongly compressed or encrypted data
  • ~8.0: Maximum entropy, likely encrypted or random data
Step 3: Extract Embedded Files

Extract all identified components from the firmware image:

bash
# Automatic extraction of known file types
binwalk -e firmware.bin

# Recursive extraction (matryoshka mode) for nested archives
binwalk -Me firmware.bin

# Recursive extraction with depth limit
binwalk -Me -d 5 firmware.bin

# Extract specific file type with custom handler
binwalk -D "squashfs filesystem:squashfs:unsquashfs %e" firmware.bin

# Manual extraction of data at a known offset
dd if=firmware.bin of=extracted.squashfs bs=1 skip=327680 count=4194304
Step 4: Mount and Inspect Extracted Filesystems

Mount extracted filesystems for deep inspection:

bash
# Mount SquashFS filesystem
mkdir /tmp/squashfs_root
unsquashfs -d /tmp/squashfs_root extracted.squashfs

# Mount CramFS filesystem
mkdir /tmp/cramfs_root
mount -t cramfs -o loop extracted.cramfs /tmp/cramfs_root

# Extract JFFS2 filesystem
jefferson extracted.jffs2 -d /tmp/jffs2_root

# Inspect the extracted filesystem
ls -la /tmp/squashfs_root/
find /tmp/squashfs_root -name "*.conf" -o -name "*.cfg" -o -name "*.key"
find /tmp/squashfs_root -name "passwd" -o -name "shadow"
Step 5: String Analysis and Credential Discovery

Search extracted filesystem and raw firmware for sensitive data:

bash
# Extract all printable strings
strings -a firmware.bin > all_strings.txt
strings -n 12 firmware.bin | sort -u > long_strings.txt

# Search for credentials and secrets
grep -rni "password\|passwd\|secret\|api_key\|token" /tmp/squashfs_root/etc/
grep -rni "BEGIN.*PRIVATE KEY" /tmp/squashfs_root/

# Find hardcoded URLs and endpoints
grep -rnoE "https?://[a-zA-Z0-9./?=_-]+" /tmp/squashfs_root/

# Search for certificate files
find /tmp/squashfs_root -name "*.pem" -o -name "*.crt" -o -name "*.key" -o -name "*.p12"

# Identify busybox and service versions
strings /tmp/squashfs_root/bin/busybox | grep "BusyBox v"
cat /tmp/squashfs_root/etc/banner 2>/dev/null
Step 6: Generate Firmware Analysis Report

Compile comprehensive extraction and analysis findings:

Report should include:
- Firmware metadata (vendor, model, version, build date)
- Identified components with offsets and sizes (bootloader, kernel, filesystem, config)
- Entropy analysis summary with regions of interest
- Extracted filesystem structure and key contents
- Discovered credentials, keys, certificates
- Identified services, daemons, and their versions
- Known CVEs applicable to identified component versions
- Recommendations for hardening or vulnerability remediation

Key Concepts

TermDefinition
FirmwareSoftware embedded in hardware devices providing low-level control; typically contains a bootloader, kernel, root filesystem, and configuration data
Entropy AnalysisStatistical measurement of randomness in binary data; high entropy indicates encryption or compression, low entropy indicates plaintext or structured data
SquashFSRead-only compressed filesystem commonly used in embedded Linux devices; supports LZMA, gzip, LZO, and zstd compression
Magic BytesKnown byte sequences at fixed offsets that identify file types; binwalk uses a database of magic signatures to detect embedded files
Matryoshka ExtractionRecursive extraction mode where binwalk re-scans extracted files for additional embedded content, handling deeply nested archives
CramFSCompressed ROM filesystem designed for embedded systems with limited flash storage; supports only zlib compression
JFFS2Journalling Flash File System version 2, designed for NOR and NAND flash memory in embedded devices
Show full SKILL.md (260 more words)Show less

Tools & Systems

  • binwalk: Primary firmware analysis tool for signature scanning, entropy analysis, and automated extraction of embedded files
  • unsquashfs: SquashFS extraction utility for mounting read-only compressed filesystems found in router and IoT firmware
  • jefferson: Python tool for extracting JFFS2 flash filesystem images commonly found in embedded devices
  • sasquatch: Patched SquashFS utility supporting non-standard vendor-modified SquashFS variants
  • firmware-mod-kit: Toolkit for extracting, modifying, and repacking firmware images for security testing

Common Scenarios

Scenario: Extracting and Auditing Router Firmware for Hardcoded Credentials

Context: A security researcher is performing an authorized assessment of a consumer router. The firmware update file was downloaded from the vendor's support page. The goal is to identify hardcoded credentials, insecure default configurations, and known vulnerable components.

Approach:

  1. Run binwalk -e firmware.bin to perform initial extraction
  2. Use binwalk -E firmware.bin to check entropy and identify encrypted regions
  3. Locate the SquashFS root filesystem in the extracted output
  4. Mount with unsquashfs and inspect /etc/passwd, /etc/shadow, and web server configs
  5. Search for hardcoded credentials with grep -rni "password" /tmp/root/etc/
  6. Identify service versions and cross-reference with CVE databases
  7. Check for debug interfaces (telnet, UART, JTAG references) in startup scripts
  8. Examine web application code for authentication bypass or command injection

Pitfalls:

  • Some vendors use non-standard SquashFS with custom compression; use sasquatch instead of unsquashfs
  • Encrypted firmware requires decryption keys often found in bootloader or previous unencrypted versions
  • Firmware headers may need to be stripped before binwalk can identify the embedded filesystem
  • Obfuscated strings may evade simple grep searches; use entropy analysis to locate data blobs

Output Format

FIRMWARE EXTRACTION REPORT
====================================
Firmware:         TP-Link TL-WR841N v14
File:             wr841nv14_en_3_16_9_up.bin
Size:             3,932,160 bytes (3.75 MB)
SHA-256:          a1b2c3d4e5f6...

SIGNATURE SCAN RESULTS
Offset       Type                          Size
------       ----                          ----
0x00000000   U-Boot bootloader header      64 bytes
0x00020000   LZMA compressed data          1,048,576 bytes
0x00120000   SquashFS filesystem v4.0      2,752,512 bytes
0x003B0000   Configuration partition       131,072 bytes

ENTROPY ANALYSIS
Region 0x000000-0x020000: 4.21 (bootloader - plaintext code)
Region 0x020000-0x120000: 7.89 (kernel - LZMA compressed)
Region 0x120000-0x3B0000: 7.45 (filesystem - SquashFS compressed)
Region 0x3B0000-0x3C0000: 1.12 (config - mostly empty)

EXTRACTED FILESYSTEM
Root filesystem: SquashFS v4.0, LZMA compression
Total files: 847
Total dirs: 112
BusyBox version: 1.19.4

SECURITY FINDINGS
[CRITICAL] Hardcoded root password in /etc/shadow (hash: $1$...)
[HIGH]     Telnet daemon enabled by default in /etc/init.d/rcS
[HIGH]     Private RSA key at /etc/ssl/private/server.key
[MEDIUM]   BusyBox 1.19.4 (CVE-2021-42373, CVE-2021-42374)
[MEDIUM]   Dropbear SSH 2014.63 (CVE-2016-3116)
[LOW]      UPnP service enabled by default

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-firmware-extraction-with-binwalk of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Firmware Extraction With Binwalk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Firmware Extraction With Binwalk compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Firmware Extraction With Binwalk this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Binary Reverse Engineering Audittihanyin/REx-skill108—~5.1kAutomated safety check: PassMIT
Electron App Security Analyzerptn1411/skill219—~830Automated safety check: NotesNone
Sharp Edges Analysistrailofbits/skills7.5k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0
Zeroization Audittrailofbits/skills7.5k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

    108 GitHub stars~5.1k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 19 days ago
    SecurityAuto-check: notes
  • Sharp Edges Analysis

    trailofbits/skills

    Official

    Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

    7.5k GitHub starsUsed in 3 repos~3k tokens
    SecurityAuto-check passed
  • Zeroization Audit

    trailofbits/skills

    Official

    Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

    7.5k GitHub starsUsed in 4 repos~5.9k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Firmware Extraction With Binwalk

What does Performing Firmware Extraction With Binwalk do?

Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Performing Firmware Extraction With Binwalk is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material.

When should I use Performing Firmware Extraction With Binwalk?

Performing Firmware Extraction With Binwalk fits situations like: tasks that involve Embedded systems; tasks that involve Reverse engineering and malware; tasks that involve Security review.

How do I install Performing Firmware Extraction With Binwalk in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-extraction-with-binwalk -a claude-code`. Or copy the skill folder (skills/performing-firmware-extraction-with-binwalk in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-firmware-extraction-with-binwalk in your project. Claude Code loads it when a task matches its description.

How do I install Performing Firmware Extraction With Binwalk in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-extraction-with-binwalk -a codex`. Or copy the skill folder (skills/performing-firmware-extraction-with-binwalk in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-firmware-extraction-with-binwalk in your project. Codex loads it when a task matches its description.

Can I use Performing Firmware Extraction With Binwalk in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-extraction-with-binwalk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-firmware-extraction-with-binwalk, .gemini/skills/performing-firmware-extraction-with-binwalk, .github/skills/performing-firmware-extraction-with-binwalk and .opencode/skills/performing-firmware-extraction-with-binwalk in your project.

What does Performing Firmware Extraction With Binwalk need to run?

Going by SKILL.md and its folder, Performing Firmware Extraction With Binwalk needs Python for the scripts in its folder and the command-line tools its instructions call (pip). Our summary lists: Python 3.

Does Performing Firmware Extraction With Binwalk access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Performing Firmware Extraction With Binwalk safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Firmware Extraction With Binwalk use?

Performing Firmware Extraction With Binwalk is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Firmware Extraction With Binwalk use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Performing Firmware Extraction With Binwalk?

Skills that share tags, products or a category with Performing Firmware Extraction With Binwalk: Security Review (getsentry/skills, 1k stars), Binary Reverse Engineering Audit (tihanyin/REx-skill, 108 stars), Electron App Security Analyzer (ptn1411/skill, 219 stars) and Sharp Edges Analysis (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Firmware Extraction With Binwalk?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.