Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/forensics-disk .claude/skills/forensics-disk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .claude/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-diskType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/forensics-disk .agents/skills/forensics-disk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .agents/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/forensics-disk .cursor/skills/forensics-disk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .cursor/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MuWinds/BUUCTF_Agent.git --path skills/forensics-disk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/forensics-disk .gemini/skills/forensics-disk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .gemini/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MuWinds/BUUCTF_Agent forensics-diskInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/forensics-disk .github/skills/forensics-disk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .github/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/forensics-disk .opencode/skills/forensics-disk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "forensics-disk" agent skill from https://github.com/MuWinds/BUUCTF_Agent/tree/main/skills/forensics-disk into .opencode/skills/forensics-disk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "forensics-disk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
forensics-disk磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent.
Forensics Disk is an agent skill from MuWinds/BUUCTF_Agent. 磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能。
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: 专为CTF设计的可扩展AI Agent,可自动解CTF题,也能与用户协作交互解题~. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 95cc9e0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Forensics Disk loads about 1k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 194 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- Cookie:`%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies`- Cookie:`cookies.sqlite`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MuWinds/BUUCTF_Agent at commit 95cc9e0, republished under its Apache-2.0 licence (© MuWinds). 194 words, ~1,043 tokens.
.claude/skills/forensics-disk/SKILL.md (or your agent's skills folder).mount -o loop,ro 只读挂载镜像,或用 FTK Imager / Autopsy 加载fsstat 或 file -s 确认文件系统类型和参数fls -r 递归列出所有文件(含已删除),istat 查看 inode/MFT 详情icat 按 inode/MFT 编号提取文件内容mactime 从 MAC 时间戳生成完整活动时间线istat -f ntfs image.dd <MFT编号> # 查看 MFT 记录详情
icat -f ntfs image.dd <MFT编号> # 提取文件内容
fls -f ntfs -d image.dd # 仅列出已删除文件$LogFile:NTFS 事务日志,记录元数据变更,可恢复近期修改$UsnJrnl:USN 变更日志,记录文件创建/删除/重命名等操作MFTECmd、NTFS Log Tracker# 查看 ADS
streams <file>
# Sleuth Kit 方式
fls -r -f ntfs image.dd | grep ":"$FILE_NAME 和 $STANDARD_INFORMATION 可能有不同的时间戳,注意对比0x0FFFFFFF 标记文件结束0xE5,簇链清零,但数据区未擦除fls -f fat -d image.dd # 列出已删除文件
icat -f fat image.dd <簇号> # 提取内容
# 或使用 testdisk / photorecjournalctl 或直接解析dir_index,删除后 inode 标记清零extundelete 或 ext4magic 恢复extundelete --restore-all /dev/sdX1
ext4magic image.dd -f /path/to/deleted/file -d output/istat -f ext4 image.dd <inode号> 查看 atime/mtime/ctime/ctimedebugfs 进入交互式调试模式:debugfs image.dd
debugfs: ls -l /path/to/dir
debugfs: stat <inode>C:\Windows\System32\winevt\Logs\System.evtxC:\Windows\System32\winevt\Logs\Security.evtxC:\Windows\System32\winevt\Logs\Application.evtxMicrosoft-Windows-PowerShell%4Operational.evtxMicrosoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx| ID | 来源 | 含义 |
|---|---|---|
| 4624 | Security | 登录成功 |
| 4625 | Security | 登录失败 |
| 4634 | Security | 注销 |
| 4688 | Security | 新进程创建 |
| 4720 | Security | 账户创建 |
| 7045 | System | 服务安装 |
| 1102 | Security | 日志清除 |
# Python 解析
python3 -c "
import Evtx.Evtx as evtx
with evtx.Evtx('Security.evtx') as log:
for record in log.records():
print(record.xml())
"
# 命令行工具
wevtx_dump Security.evtx
chainsaw hunt Security.evtx --mapping sigma%LOCALAPPDATA%\Google\Chrome\User Data\Default\History(SQLite)downloads 表%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cache\%APPDATA%\Mozilla\Firefox\Profiles\<profile>\places.sqlitedownloads.sqlite(旧版)或 places.sqlitecookies.sqlite-- Chrome 历史记录
SELECT datetime(last_visit_time/1000000-11644473600,'unixepoch','localtime'),
url, title, visit_count
FROM urls ORDER BY last_visit_time DESC;
-- Chrome 下载记录
SELECT datetime(start_time/1000000-11644473600,'unixepoch','localtime'),
target_path, total_bytes, state
FROM downloads ORDER BY start_time DESC;# Sleuth Kit 命令行
fls -r -m / image.dd # 列出文件(TSK 路径格式)
mactime -b body.txt -d # 生成时间线
tsk_recover image.dd output/ # 批量恢复已删除文件
blkstat -f ntfs image.dd <簇号> # 查看块分配状态
mmstat image.dd # 查看分区表
# Autopsy / FTK
# GUI 工具,适合综合分析
# 系统相关
reglookup NTUSER.DAT # 注册表解析
regripper -r NTUSER.DAT -f ntuser # 注册表信息提取© MuWinds, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/forensics-disk of MuWinds/BUUCTF_Agent.
Open the folder on GitHubat commit 95cc9e0
Forensics Disk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Forensics Disk this skillMuWinds/BUUCTF_Agent | 267 | — | ~1k | Automated safety check: Warn | Apache-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 480 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
Categories
磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent. Forensics Disk is an agent skill from MuWinds/BUUCTF_Agent.
Forensics Disk fits situations like: security work in your project.
Run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a claude-code`. Or copy the skill folder (skills/forensics-disk in MuWinds/BUUCTF_Agent) into .claude/skills/forensics-disk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a codex`. Or copy the skill folder (skills/forensics-disk in MuWinds/BUUCTF_Agent) into .agents/skills/forensics-disk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/forensics-disk, .gemini/skills/forensics-disk, .github/skills/forensics-disk and .opencode/skills/forensics-disk in your project.
Going by SKILL.md and its folder, Forensics Disk needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Forensics Disk is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Forensics Disk: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MuWinds (a GitHub user) maintains it in MuWinds/BUUCTF_Agent, which has 267 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 5, 2026.
Source: MuWinds/BUUCTF_Agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.