Agent skill

TH08 Library Recovery

by N0zoM1z0 in N0zoM1z0/th08

Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence.

MITAuto-check passedDevelopment

Install TH08 Library Recovery

skills CLI
$ npx skills add N0zoM1z0/th08 --skill th08-library -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install N0zoM1z0/th08 th08-library --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/th08-library .claude/skills/th08-library && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
th08-library
GitHub stars
103
Token cost
~877 tokens
SKILL.md length
381 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence.

  • Works in 3 steps: Read AGENTS.md, docs/RE_HANDOFF.md,… → Run → Select one coherent runtime/D3DX family.…
  • Fixing the boundaries of library functions found in the TH08 binary
  • SKILL.md covers Preflight, Evidence gates, Ledger boundary and Whole-executable handoff
  • Calls python3

What it does

Work on the TH08 source reconstruction uses this skill for the library rows in the original 1.00d executable, not for the optional Detours dependency. The agent begins with a preflight: it reads the project's AGENTS.md and its reverse-engineering handoff, workflow and tools docs, runs verify-target.py and validate-tracking.py, then picks one coherent runtime or D3DX family and checks every start and extent against the target's control flow.

The evidence rules are strict. Each archive and member must be tied to its exact toolchain version with a SHA-256 recorded, and code is compared only after COFF relocations are replayed and padding, COMDATs, jump tables and thunks are accounted for. Inline assembly, byte arrays, empty stubs and copied target bytes are ruled out. No library ledger exists yet, so the skill lists what to propose first: a provenance manifest, a match-unit schema, validation that works in public CI and a separate progress view.

When your agent uses it

  • Fixing the boundaries of library functions found in the TH08 binary
  • Recording archive and member provenance with SHA-256 hashes
  • Designing a relocation-aware comparison for CRT or D3DX code
  • Preparing whole-executable link work once authored coverage is done

Example prompts

  • “Pick the next runtime family from the TH08 library rows and check its start and extent against the target.”
  • “Draft the archive-provenance manifest for the VC7 libraries we use as evidence.”
  • “Explain why this D3DX function stops matching once the relocations are replayed.”

Requirements

  • Python 3 for the repository's verify-target and tracking scripts
  • The original TH08 1.00d target image for target-required checks

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read AGENTS.md, docs/RE_HANDOFF.md, docs/RE_WORKFLOW.md, and
  2. Run
  3. Select one coherent runtime/D3DX family. Reconcile every start and extent

What it can do on your machine

Read from SKILL.md and the folder at commit d2a00f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

TH08 Library Recovery loads about 877 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 381 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~877

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from N0zoM1z0/th08 at commit d2a00f4, republished under its MIT licence (© N0zoM1z0). 381 words, ~877 tokens.

Download SKILL.mdSave it as .claude/skills/th08-library/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
th08-library
description
Recover and attest target-linked TH08 VC7 CRT, compiler-runtime, and D3DX library functions after authored coverage. Use for library inventory boundaries, archive/member provenance, hash pinning, relocation-aware comparison design, or whole-link preparation; do not use for repository third-party submodules.

TH08 target-linked library recovery

This skill covers type=library rows inside the original Japanese TH08 1.00d image. It does not cover 3rdparty/Detours, which only supports the optional reconstruction DLL.

Preflight

  1. Read AGENTS.md, docs/RE_HANDOFF.md, docs/RE_WORKFLOW.md, and docs/TOOLS.md.

  2. Run:

    bash
    python3 scripts/verify-target.py
    python3 scripts/validate-tracking.py --require-target
    python3 scripts/analysis/report-reconstruction-status.py \
      --category library --state missing-size --sort address

    The current first-lane result is seven rows. If that count changes, trust the command and current ledgers rather than copying an old prose list.

  3. Select one coherent runtime/D3DX family. Reconcile every start and extent against target control flow before editing mapping.csv; imported Ghidra boundaries and the next CSV address are leads, not accepted sizes.

Evidence gates

  • Identify the exact originating toolchain/library version and archive member. Record SHA-256 for each archive used as evidence. A same-name TH07 archive or a modern SDK library is not a substitute.
  • Keep target facts, archive/member facts, inferred symbol names, and unknown boundaries distinct.
  • Compare code only after replaying COFF relocations and accounting for archive member padding, COMDATs, jump tables, thunks, and linker-owned transformations.
  • Prefer compiler/library source or extracted COFF evidence. Never recreate CRT or D3DX bodies with inline assembly, byte arrays, empty stubs, or copied target bytes.
Show full SKILL.md (200 more words)Show less

Ledger boundary

No library exact ledger exists yet. config/implemented.csv, config/matches.csv, and docs/PROGRESS.md currently describe authored work; do not repurpose them for library percentages.

Before the first library acceptance, propose and review:

  1. an archive-provenance manifest with hashes and member identities;
  2. a library match-unit schema with target address, accepted extent, object or archive member, relocation replay, and evidence command;
  3. validation that works without private target bytes in public CI and a local target-required acceptance command;
  4. a separate library progress view that does not change authored totals.

There is intentionally no library scanner. Build one only after these inputs and failure modes are pinned; fail closed on unknown archive hashes, ambiguous members, boundary overlap, unsupported relocation, or target mismatch.

Whole-executable handoff

Once library objects are reproducible, carry exact object order and linker metadata into the whole-image lane: section layout, padding, globals/static initialization, imports, PE headers, resources, and non-code data. A successful normal link or a function-name match is not whole-executable exactness.

End each bounded batch with target address/range, boundary evidence, archive/member/hash evidence, exact comparison result or named missing schema, files changed, and remaining uncertainty. Keep config/claims.csv header-only, run python3 scripts/ci.py, and update docs/RE_HANDOFF.md only when the durable milestone changes.

© N0zoM1z0, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/th08-library of N0zoM1z0/th08.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit d2a00f4

Compare with similar skills

TH08 Library Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

TH08 Library Recovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
TH08 Library Recovery this skillN0zoM1z0/th08103—~877Automated safety check: PassMIT
Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills184—~826Automated safety check: PassMIT
Ghidra ReOrbitCurve/firmware-reverse-engineering216—~4.2kAutomated safety check: PassApache-2.0
Nuitka Nbc RebuilderDimaReverse/nuitka-static-unpacker132—~2kAutomated safety check: PassMIT
Electron App Security Analyzerptn1411/skill219—~830Automated safety check: NotesNone
Rev Unicorn Debugindex-login/MobileRE-Skill152—~1.9kAutomated safety check: PassMIT

Similar skills

  • Combine Dbc

    CSS-Electronics/can-bus-reverse-engineering-skills

    Combine multiple individual single-signal DBC files into one combined DBC at the application level.

    184 GitHub stars~826 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    216 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Nuitka Nbc Rebuilder

    DimaReverse/nuitka-static-unpacker

    Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.

    132 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 18 days ago
    SecurityAuto-check: notes
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    152 GitHub stars~1.9k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Binary Re

    aiskillstore/marketplace

    This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

    433 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed

More from N0zoM1z0/th08

  • Reconstructs bounded functions from the original Japanese TH08 1.00d executable for a source decompilation project, using hash-verified target evidence and labeled corroboration.

    103 GitHub stars~1.3k tokensUpdated 21 days ago
    Auto-check passed
  • Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison.

    103 GitHub stars~2.8k tokensUpdated 21 days ago
    Auto-check passed
  • Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches.

    103 GitHub stars~8.7k tokensUpdated 21 days ago
    Auto-check passed
  • Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.

    103 GitHub stars~2.3k tokensUpdated 21 days ago
    Auto-check passed

Works with

Questions about TH08 Library Recovery

What does TH08 Library Recovery do?

Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence. 00d executable, not for the optional Detours dependency.py, then picks one coherent runtime or D3DX family and checks every start and extent against the target's control flow.

When should I use TH08 Library Recovery?

TH08 Library Recovery fits situations like: fixing the boundaries of library functions found in the TH08 binary; recording archive and member provenance with SHA-256 hashes; designing a relocation-aware comparison for CRT or D3DX code; preparing whole-executable link work once authored coverage is done.

How do I install TH08 Library Recovery in Claude Code?

Run `npx skills add N0zoM1z0/th08 --skill th08-library -a claude-code`. Or copy the skill folder (.agents/skills/th08-library in N0zoM1z0/th08) into .claude/skills/th08-library in your project. Claude Code loads it when a task matches its description.

How do I install TH08 Library Recovery in Codex?

Run `npx skills add N0zoM1z0/th08 --skill th08-library -a codex`. Or copy the skill folder (.agents/skills/th08-library in N0zoM1z0/th08) into .agents/skills/th08-library in your project. Codex loads it when a task matches its description.

Can I use TH08 Library Recovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add N0zoM1z0/th08 --skill th08-library -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/th08-library, .gemini/skills/th08-library, .github/skills/th08-library and .opencode/skills/th08-library in your project.

What does TH08 Library Recovery need to run?

Going by SKILL.md and its folder, TH08 Library Recovery needs the command-line tools its instructions call (python3). Our summary lists: Python 3 for the repository's verify-target and tracking scripts; The original TH08 1.00d target image for target-required checks.

Does TH08 Library Recovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is TH08 Library Recovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does TH08 Library Recovery use?

TH08 Library Recovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does TH08 Library Recovery use?

About 877 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to TH08 Library Recovery?

Skills that share tags, products or a category with TH08 Library Recovery: Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 184 stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Nuitka Nbc Rebuilder (DimaReverse/nuitka-static-unpacker, 132 stars) and Electron App Security Analyzer (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains TH08 Library Recovery?

N0zoM1z0 (a GitHub user) maintains it in N0zoM1z0/th08, which has 103 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 19, 2026.

Source: N0zoM1z0/th08 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.