Agent skill

Performing Firmware Malware Analysis

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…

Apache-2.0Auto-check: notesSecurity

Install Performing Firmware Malware Analysis

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .claude/skills/performing-firmware-malware-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-firmware-malware-analysis
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
594 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…

  • Works in 6 steps: Extract and Identify Firmware Components → Analyze the Extracted Filesystem → Reverse Engineer Suspicious Binaries → …
  • Firmware security analysis
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls python, python3 and ssh; reaches github.com

What it does

Performing Firmware Malware Analysis is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Use for firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Reverse engineering and malware and Embedded systems. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Firmware security analysis
  • IoT malware investigation
  • UEFI rootkit detection
  • Embedded device compromise assessment

Example prompts

  • “Use the performing-firmware-malware-analysis skill to analyz firmware images for embedded malware, backdoors, and unauthorized modifications in…”
  • “/performing-firmware-malware-analysis”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Extract and Identify Firmware Components
  2. Analyze the Extracted Filesystem
  3. Reverse Engineer Suspicious Binaries
  4. UEFI/BIOS Firmware Analysis
  5. Emulate Firmware for Dynamic Analysis
  6. Document Firmware Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • python3
    • ssh
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Firmware Malware Analysis loads about 3k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 594 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:197
    sudo mount -o loop squashfs-root.img /mnt/firmware
  • NoteRuns commands with sudoSKILL.md:200
    sudo cp /usr/bin/qemu-arm-static /mnt/firmware/usr/bin/
  • NoteRuns commands with sudoSKILL.md:201
    sudo chroot /mnt/firmware /bin/sh

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 594 words, ~2,963 tokens.

Download SKILL.mdSave it as .claude/skills/performing-firmware-malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-firmware-malware-analysis
description
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Use for firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
domain
cybersecurity
subdomain
malware-analysis
tags
malware, firmware, IoT, UEFI, embedded-security
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
DE.AE-02, RS.AN-03, ID.RA-01, DE.CM-01
mitre_attack
T1027, T1055, T1140, T1497, T1505.003

Performing Firmware Malware Analysis

When to Use

  • A compromised IoT device or router needs firmware analysis to identify implanted backdoors
  • Investigating UEFI/BIOS rootkits that persist across OS reinstallations
  • Analyzing firmware updates for supply chain compromise or malicious modifications
  • Extracting and examining embedded Linux filesystems from IoT device firmware images
  • Verifying firmware integrity after a suspected hardware or firmware-level compromise

Do not use for standard operating system malware; use PE/ELF analysis tools for OS-level malware on conventional systems.

Prerequisites

  • binwalk installed for firmware image analysis and extraction (pip install binwalk)
  • Ghidra with ARM/MIPS architecture support for embedded binary reverse engineering
  • UEFI Tool (UEFITool) for UEFI firmware parsing and analysis
  • Firmware Analysis Toolkit (FAT) or EMBA for automated firmware analysis
  • QEMU for emulating extracted firmware filesystems
  • Cross-compilation toolchains for ARM, MIPS, and other embedded architectures

Workflow

Step 1: Extract and Identify Firmware Components

Analyze the firmware image structure and extract filesystems:

bash
# Identify embedded filesystems and compressed data
binwalk firmware.bin

# Extract all identified components
binwalk -e firmware.bin

# Recursive extraction with signature scanning
binwalk -eM firmware.bin

# Output typically includes:
# - Bootloader (U-Boot, GRUB, custom)
# - Kernel image (Linux, RTOS)
# - Root filesystem (SquashFS, JFFS2, CramFS, ext4)
# - Configuration data
# - Digital signatures or checksums

# Entropy analysis to find encrypted or compressed regions
binwalk -E firmware.bin

# Identify specific filesystem types
file _firmware.bin.extracted/*

# For SquashFS filesystems
unsquashfs _firmware.bin.extracted/squashfs-root.img
ls squashfs-root/
Step 2: Analyze the Extracted Filesystem

Search for malicious modifications in the firmware filesystem:

bash
# Directory structure analysis
find squashfs-root/ -type f | head -50

# Search for suspicious files
find squashfs-root/ -name "*.sh" -exec ls -la {} \;
find squashfs-root/ -perm -4000 -type f  # SUID binaries
find squashfs-root/ -name "*.so" -newer squashfs-root/bin/busybox  # Modified libraries

# Check startup scripts for backdoors
cat squashfs-root/etc/init.d/rcS
cat squashfs-root/etc/inittab
ls -la squashfs-root/etc/rc.d/

# Search for hardcoded credentials
grep -rn "password\|passwd\|secret\|key\|token" squashfs-root/etc/ 2>/dev/null
grep -rn "root:" squashfs-root/etc/shadow 2>/dev/null

# Check for unauthorized SSH keys
find squashfs-root/ -name "authorized_keys" -exec cat {} \;

# Network configuration backdoors
cat squashfs-root/etc/hosts
grep -rn "iptables\|nc\|netcat\|ncat" squashfs-root/etc/ squashfs-root/usr/bin/

# Check for reverse shells in cron
find squashfs-root/ -name "crontab" -o -name "cron*" | xargs cat 2>/dev/null

# Identify all ELF binaries for analysis
find squashfs-root/ -type f -exec file {} \; | grep ELF
Step 3: Reverse Engineer Suspicious Binaries

Analyze extracted binaries that may be backdoors:

bash
# Identify architecture and format
file squashfs-root/usr/bin/suspicious_binary

# Extract strings for IOC discovery
strings squashfs-root/usr/bin/suspicious_binary | grep -iE "http|ip|port|shell|connect|exec"

# Cross-reference against known firmware binaries
# Compare SHA-256 hashes with known-good firmware
sha256sum squashfs-root/usr/bin/* > current_hashes.txt
# diff against baseline: diff baseline_hashes.txt current_hashes.txt

# Import into Ghidra for disassembly (select correct architecture)
# ARM:   ARM/AARCH64 (Little Endian for most IoT devices)
# MIPS:  MIPS/MIPS64 (Big or Little Endian depending on device)
# x86:   For UEFI modules

# Analyze with radare2 for quick triage
r2 -A squashfs-root/usr/bin/suspicious_binary
# Commands: afl (function list), pdf @main (disassemble main), iz (strings)
Step 4: UEFI/BIOS Firmware Analysis

Analyze system firmware for bootkits and implants:

bash
# Extract UEFI firmware volumes with UEFITool
# GUI: UEFITool -> File -> Open -> Select firmware.rom
# CLI: UEFIExtract firmware.rom

# Analyze UEFI firmware with chipsec (requires hardware access)
python chipsec_main.py -m common.bios_wp     # BIOS write protection
python chipsec_main.py -m common.spi_lock     # SPI flash lock
python chipsec_main.py -m common.secureboot   # Secure Boot status
python chipsec_main.py -m common.uefi.s3bootscript  # S3 resume script

# Dump UEFI firmware from live system
python chipsec_util.py spi dump firmware_dump.rom

# Compare with known-good firmware
sha256sum firmware_dump.rom
# Compare against vendor-provided firmware hash

# Scan for known UEFI malware signatures
yara -r uefi_malware_rules.yar firmware_dump.rom
Known UEFI Malware Families:
━━━━━━━━━━━━━━━━━━━━━━━━━━
LoJax:         First in-the-wild UEFI rootkit (APT28/Fancy Bear)
               Modifies SPI flash to drop persistence agent
MosaicRegressor: Modular UEFI framework dropping multiple payloads
CosmicStrand:  UEFI firmware rootkit modifying kernel during boot
BlackLotus:    UEFI bootkit bypassing Secure Boot on Windows 11
ESPecter:      ESP (EFI System Partition) bootkit modifying boot manager
MoonBounce:    SPI flash implant modifying CORE_DXE module
FinSpy UEFI:  Surveillance software with UEFI persistence
Step 5: Emulate Firmware for Dynamic Analysis

Run extracted firmware in an emulated environment:

bash
# Emulate ARM-based IoT firmware with QEMU
# Mount the extracted filesystem
sudo mount -o loop squashfs-root.img /mnt/firmware

# Chroot into the firmware with QEMU user-mode emulation
sudo cp /usr/bin/qemu-arm-static /mnt/firmware/usr/bin/
sudo chroot /mnt/firmware /bin/sh

# Or use firmadyne for automated firmware emulation
# https://github.com/firmadyne/firmadyne
python3 fat.py firmware.bin

# Network service analysis within emulated firmware
# Scan for open ports and services
nmap -sV localhost -p 1-65535

# Monitor network traffic from emulated firmware
tcpdump -i tap0 -w firmware_traffic.pcap
Step 6: Document Firmware Analysis

Compile comprehensive firmware analysis findings:

Analysis documentation should cover:
- Firmware image metadata (vendor, model, version, build date)
- Extraction results (filesystem type, kernel version, architecture)
- Modified files compared to known-good baseline
- Backdoor binaries discovered with reverse engineering findings
- Hardcoded credentials and unauthorized access mechanisms
- Network services and their security posture
- UEFI/BIOS integrity verification results
- Extracted IOCs (IPs, domains, file hashes, SSH keys)
- Remediation recommendations (reflash, replace, update)

Key Concepts

TermDefinition
FirmwareSoftware permanently stored in device hardware (flash memory, EEPROM) controlling low-level device operations and boot process
UEFI (Unified Extensible Firmware Interface)Modern system firmware replacing legacy BIOS; provides boot services, runtime services, and a modular driver architecture
SPI FlashSerial Peripheral Interface flash memory chip storing UEFI/BIOS firmware; can be read and modified for persistence
Secure BootUEFI feature verifying digital signatures of boot components to prevent unauthorized code execution during startup
SquashFSRead-only compressed filesystem commonly used in embedded Linux firmware for space-efficient storage
BootkitMalware infecting the boot process (MBR, VBR, UEFI) to load before the operating system and evade OS-level security
Firmware EmulationRunning extracted firmware in a virtual environment (QEMU, firmadyne) to analyze behavior without physical hardware
Show full SKILL.md (256 more words)Show less

Tools & Systems

  • binwalk: Firmware analysis tool for scanning, extracting, and analyzing embedded file systems and compressed data in firmware images
  • UEFITool: Open-source UEFI firmware image parser and extractor for analyzing UEFI volumes, modules, and drivers
  • chipsec: Intel's open-source framework for platform security assessment including SPI flash, Secure Boot, and UEFI analysis
  • firmadyne: Automated firmware analysis and emulation platform for Linux-based embedded devices
  • Ghidra: NSA's reverse engineering tool with ARM, MIPS, and other embedded architecture support for firmware binary analysis

Common Scenarios

Scenario: Investigating a Compromised Router with Persistent Backdoor

Context: A network router continues to exhibit suspicious behavior (unexpected DNS resolutions, traffic to unknown IPs) even after factory resets. Firmware-level compromise is suspected.

Approach:

  1. Dump the firmware from the router using JTAG/UART debug interface or vendor management tools
  2. Extract the filesystem with binwalk and identify the Linux distribution and kernel version
  3. Compare file hashes against known-good firmware image from the vendor
  4. Search startup scripts (rcS, inittab, crontab) for backdoor entries
  5. Analyze any modified or new binaries with Ghidra (ARM/MIPS architecture)
  6. Check for hardcoded credentials, unauthorized SSH keys, and reverse shell scripts
  7. Emulate the firmware to observe network behavior and identify C2 communication

Pitfalls:

  • Not dumping firmware from the actual device (downloading from vendor site gives clean version, not the compromised one)
  • Ignoring modified shared libraries (.so files) that may hook system functions
  • Missing firmware modifications stored outside the main filesystem (bootloader, configuration partitions)
  • Not checking both the primary and backup firmware partitions (some devices have dual-bank flash)

Output Format

FIRMWARE MALWARE ANALYSIS REPORT
===================================
Device:           NetGear R7000 Router
Firmware Version: V1.0.11.116 (modified)
Architecture:     ARM (Little Endian)
Filesystem:       SquashFS (Linux 3.4.103)
Dump Method:      UART debug console

INTEGRITY CHECK
Vendor Firmware Hash:  aaa111bbb222... (clean V1.0.11.116)
Analyzed Firmware Hash: ccc333ddd444... (MISMATCH)
Modified Files:        14 files differ from vendor baseline

BACKDOOR FINDINGS
[!] /usr/bin/httpd_backdoor (new binary, not in vendor firmware)
    Architecture: ARM 32-bit
    Function: Reverse shell to 185.220.101[.]42:4444
    Persistence: Added to /etc/init.d/rcS

[!] /etc/shadow modified
    Root password changed to known hash
    New user 'admin2' added with UID 0

[!] /etc/crontab modified
    Added: */5 * * * * /usr/bin/httpd_backdoor

[!] /root/.ssh/authorized_keys (new file)
    Contains attacker's SSH public key

EXTRACTED IOCs
C2 IP:            185.220.101[.]42
C2 Port:          4444
SSH Key:          ssh-rsa AAAA... attacker@control
Backdoor Hash:    eee555fff666...

REMEDIATION
1. Flash clean vendor firmware via TFTP recovery mode
2. Change all device credentials
3. Update to latest firmware version
4. Enable firmware integrity checking if available
5. Monitor for re-compromise indicators

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-firmware-malware-analysis of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Firmware Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Firmware Malware Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Firmware Malware Analysis this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.0
Re Riscvdslsdzc/rev-skills135—~2.2kAutomated safety check: PassApache-2.0
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Create Sigma RuleTracecatHQ/tracecat3.8k—~16kAutomated safety check: PassMIT
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT

Similar skills

  • Re Riscv

    dslsdzc/rev-skills

    RISC-V 架构逆向:RV32/RV64、压缩指令(RVC)、gp 相对寻址、ABI 与 ecall 系统调用约定、工具链指纹。

    135 GitHub stars~2.2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Create Sigma Rule

    TracecatHQ/tracecat

    Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…

    3.8k GitHub stars~16k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Firmware Malware Analysis

What does Performing Firmware Malware Analysis do?

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…. Performing Firmware Malware Analysis is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.

When should I use Performing Firmware Malware Analysis?

Performing Firmware Malware Analysis fits situations like: firmware security analysis; ioT malware investigation; UEFI rootkit detection; embedded device compromise assessment.

How do I install Performing Firmware Malware Analysis in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a claude-code`. Or copy the skill folder (skills/performing-firmware-malware-analysis in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-firmware-malware-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Performing Firmware Malware Analysis in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a codex`. Or copy the skill folder (skills/performing-firmware-malware-analysis in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-firmware-malware-analysis in your project. Codex loads it when a task matches its description.

Can I use Performing Firmware Malware Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-firmware-malware-analysis, .gemini/skills/performing-firmware-malware-analysis, .github/skills/performing-firmware-malware-analysis and .opencode/skills/performing-firmware-malware-analysis in your project.

What does Performing Firmware Malware Analysis need to run?

Going by SKILL.md and its folder, Performing Firmware Malware Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python, python3, ssh and pip). Our summary lists: Python 3.

Does Performing Firmware Malware Analysis access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Performing Firmware Malware Analysis safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Firmware Malware Analysis use?

Performing Firmware Malware Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Firmware Malware Analysis use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 411 tokens, read only when the agent opens those files.

What are the alternatives to Performing Firmware Malware Analysis?

Skills that share tags, products or a category with Performing Firmware Malware Analysis: Re Riscv (dslsdzc/rev-skills, 135 stars), vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars) and Create Sigma Rule (TracecatHQ/tracecat, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Firmware Malware Analysis?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.