Re Riscv
dslsdzc/rev-skills
RISC-V 架构逆向:RV32/RV64、压缩指令(RVC)、gp 相对寻址、ABI 与 ecall 系统调用约定、工具链指纹。
Agent skill
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .claude/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .claude/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .agents/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .agents/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .cursor/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .cursor/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/performing-firmware-malware-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .gemini/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .gemini/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .github/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .github/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-firmware-malware-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-firmware-malware-analysis .opencode/skills/performing-firmware-malware-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-firmware-malware-analysis" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-firmware-malware-analysis into .opencode/skills/performing-firmware-malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-firmware-malware-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-firmware-malware-analysisAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…
Performing Firmware Malware Analysis is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Use for firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security, covering Reverse engineering and malware and Embedded systems. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonpython3sshpipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Firmware Malware Analysis loads about 3k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 594 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo mount -o loop squashfs-root.img /mnt/firmwaresudo cp /usr/bin/qemu-arm-static /mnt/firmware/usr/bin/sudo chroot /mnt/firmware /bin/shAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 594 words, ~2,963 tokens.
.claude/skills/performing-firmware-malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for standard operating system malware; use PE/ELF analysis tools for OS-level malware on conventional systems.
pip install binwalk)Analyze the firmware image structure and extract filesystems:
# Identify embedded filesystems and compressed data
binwalk firmware.bin
# Extract all identified components
binwalk -e firmware.bin
# Recursive extraction with signature scanning
binwalk -eM firmware.bin
# Output typically includes:
# - Bootloader (U-Boot, GRUB, custom)
# - Kernel image (Linux, RTOS)
# - Root filesystem (SquashFS, JFFS2, CramFS, ext4)
# - Configuration data
# - Digital signatures or checksums
# Entropy analysis to find encrypted or compressed regions
binwalk -E firmware.bin
# Identify specific filesystem types
file _firmware.bin.extracted/*
# For SquashFS filesystems
unsquashfs _firmware.bin.extracted/squashfs-root.img
ls squashfs-root/Search for malicious modifications in the firmware filesystem:
# Directory structure analysis
find squashfs-root/ -type f | head -50
# Search for suspicious files
find squashfs-root/ -name "*.sh" -exec ls -la {} \;
find squashfs-root/ -perm -4000 -type f # SUID binaries
find squashfs-root/ -name "*.so" -newer squashfs-root/bin/busybox # Modified libraries
# Check startup scripts for backdoors
cat squashfs-root/etc/init.d/rcS
cat squashfs-root/etc/inittab
ls -la squashfs-root/etc/rc.d/
# Search for hardcoded credentials
grep -rn "password\|passwd\|secret\|key\|token" squashfs-root/etc/ 2>/dev/null
grep -rn "root:" squashfs-root/etc/shadow 2>/dev/null
# Check for unauthorized SSH keys
find squashfs-root/ -name "authorized_keys" -exec cat {} \;
# Network configuration backdoors
cat squashfs-root/etc/hosts
grep -rn "iptables\|nc\|netcat\|ncat" squashfs-root/etc/ squashfs-root/usr/bin/
# Check for reverse shells in cron
find squashfs-root/ -name "crontab" -o -name "cron*" | xargs cat 2>/dev/null
# Identify all ELF binaries for analysis
find squashfs-root/ -type f -exec file {} \; | grep ELFAnalyze extracted binaries that may be backdoors:
# Identify architecture and format
file squashfs-root/usr/bin/suspicious_binary
# Extract strings for IOC discovery
strings squashfs-root/usr/bin/suspicious_binary | grep -iE "http|ip|port|shell|connect|exec"
# Cross-reference against known firmware binaries
# Compare SHA-256 hashes with known-good firmware
sha256sum squashfs-root/usr/bin/* > current_hashes.txt
# diff against baseline: diff baseline_hashes.txt current_hashes.txt
# Import into Ghidra for disassembly (select correct architecture)
# ARM: ARM/AARCH64 (Little Endian for most IoT devices)
# MIPS: MIPS/MIPS64 (Big or Little Endian depending on device)
# x86: For UEFI modules
# Analyze with radare2 for quick triage
r2 -A squashfs-root/usr/bin/suspicious_binary
# Commands: afl (function list), pdf @main (disassemble main), iz (strings)Analyze system firmware for bootkits and implants:
# Extract UEFI firmware volumes with UEFITool
# GUI: UEFITool -> File -> Open -> Select firmware.rom
# CLI: UEFIExtract firmware.rom
# Analyze UEFI firmware with chipsec (requires hardware access)
python chipsec_main.py -m common.bios_wp # BIOS write protection
python chipsec_main.py -m common.spi_lock # SPI flash lock
python chipsec_main.py -m common.secureboot # Secure Boot status
python chipsec_main.py -m common.uefi.s3bootscript # S3 resume script
# Dump UEFI firmware from live system
python chipsec_util.py spi dump firmware_dump.rom
# Compare with known-good firmware
sha256sum firmware_dump.rom
# Compare against vendor-provided firmware hash
# Scan for known UEFI malware signatures
yara -r uefi_malware_rules.yar firmware_dump.romKnown UEFI Malware Families:
━━━━━━━━━━━━━━━━━━━━━━━━━━
LoJax: First in-the-wild UEFI rootkit (APT28/Fancy Bear)
Modifies SPI flash to drop persistence agent
MosaicRegressor: Modular UEFI framework dropping multiple payloads
CosmicStrand: UEFI firmware rootkit modifying kernel during boot
BlackLotus: UEFI bootkit bypassing Secure Boot on Windows 11
ESPecter: ESP (EFI System Partition) bootkit modifying boot manager
MoonBounce: SPI flash implant modifying CORE_DXE module
FinSpy UEFI: Surveillance software with UEFI persistenceRun extracted firmware in an emulated environment:
# Emulate ARM-based IoT firmware with QEMU
# Mount the extracted filesystem
sudo mount -o loop squashfs-root.img /mnt/firmware
# Chroot into the firmware with QEMU user-mode emulation
sudo cp /usr/bin/qemu-arm-static /mnt/firmware/usr/bin/
sudo chroot /mnt/firmware /bin/sh
# Or use firmadyne for automated firmware emulation
# https://github.com/firmadyne/firmadyne
python3 fat.py firmware.bin
# Network service analysis within emulated firmware
# Scan for open ports and services
nmap -sV localhost -p 1-65535
# Monitor network traffic from emulated firmware
tcpdump -i tap0 -w firmware_traffic.pcapCompile comprehensive firmware analysis findings:
Analysis documentation should cover:
- Firmware image metadata (vendor, model, version, build date)
- Extraction results (filesystem type, kernel version, architecture)
- Modified files compared to known-good baseline
- Backdoor binaries discovered with reverse engineering findings
- Hardcoded credentials and unauthorized access mechanisms
- Network services and their security posture
- UEFI/BIOS integrity verification results
- Extracted IOCs (IPs, domains, file hashes, SSH keys)
- Remediation recommendations (reflash, replace, update)| Term | Definition |
|---|---|
| Firmware | Software permanently stored in device hardware (flash memory, EEPROM) controlling low-level device operations and boot process |
| UEFI (Unified Extensible Firmware Interface) | Modern system firmware replacing legacy BIOS; provides boot services, runtime services, and a modular driver architecture |
| SPI Flash | Serial Peripheral Interface flash memory chip storing UEFI/BIOS firmware; can be read and modified for persistence |
| Secure Boot | UEFI feature verifying digital signatures of boot components to prevent unauthorized code execution during startup |
| SquashFS | Read-only compressed filesystem commonly used in embedded Linux firmware for space-efficient storage |
| Bootkit | Malware infecting the boot process (MBR, VBR, UEFI) to load before the operating system and evade OS-level security |
| Firmware Emulation | Running extracted firmware in a virtual environment (QEMU, firmadyne) to analyze behavior without physical hardware |
Context: A network router continues to exhibit suspicious behavior (unexpected DNS resolutions, traffic to unknown IPs) even after factory resets. Firmware-level compromise is suspected.
Approach:
Pitfalls:
FIRMWARE MALWARE ANALYSIS REPORT
===================================
Device: NetGear R7000 Router
Firmware Version: V1.0.11.116 (modified)
Architecture: ARM (Little Endian)
Filesystem: SquashFS (Linux 3.4.103)
Dump Method: UART debug console
INTEGRITY CHECK
Vendor Firmware Hash: aaa111bbb222... (clean V1.0.11.116)
Analyzed Firmware Hash: ccc333ddd444... (MISMATCH)
Modified Files: 14 files differ from vendor baseline
BACKDOOR FINDINGS
[!] /usr/bin/httpd_backdoor (new binary, not in vendor firmware)
Architecture: ARM 32-bit
Function: Reverse shell to 185.220.101[.]42:4444
Persistence: Added to /etc/init.d/rcS
[!] /etc/shadow modified
Root password changed to known hash
New user 'admin2' added with UID 0
[!] /etc/crontab modified
Added: */5 * * * * /usr/bin/httpd_backdoor
[!] /root/.ssh/authorized_keys (new file)
Contains attacker's SSH public key
EXTRACTED IOCs
C2 IP: 185.220.101[.]42
C2 Port: 4444
SSH Key: ssh-rsa AAAA... attacker@control
Backdoor Hash: eee555fff666...
REMEDIATION
1. Flash clean vendor firmware via TFTP recovery mode
2. Change all device credentials
3. Update to latest firmware version
4. Enable firmware integrity checking if available
5. Monitor for re-compromise indicators© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/performing-firmware-malware-analysis of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Performing Firmware Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Firmware Malware Analysis this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | |
| Re Riscvdslsdzc/rev-skills | 135 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Create Sigma RuleTracecatHQ/tracecat | 3.8k | — | ~16k | Automated safety check: Pass | MIT | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT |
dslsdzc/rev-skills
RISC-V 架构逆向:RV32/RV64、压缩指令(RVC)、gp 相对寻址、ABI 与 ecall 系统调用约定、工具链指纹。
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
TracecatHQ/tracecat
Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
boyang-hu/website-rebuild-skill
1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis…. Performing Firmware Malware Analysis is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection.
Performing Firmware Malware Analysis fits situations like: firmware security analysis; ioT malware investigation; UEFI rootkit detection; embedded device compromise assessment.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a claude-code`. Or copy the skill folder (skills/performing-firmware-malware-analysis in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-firmware-malware-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a codex`. Or copy the skill folder (skills/performing-firmware-malware-analysis in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-firmware-malware-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-firmware-malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-firmware-malware-analysis, .gemini/skills/performing-firmware-malware-analysis, .github/skills/performing-firmware-malware-analysis and .opencode/skills/performing-firmware-malware-analysis in your project.
Going by SKILL.md and its folder, Performing Firmware Malware Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python, python3, ssh and pip). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Firmware Malware Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 411 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Firmware Malware Analysis: Re Riscv (dslsdzc/rev-skills, 135 stars), vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars) and Create Sigma Rule (TracecatHQ/tracecat, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.