Agent skill

TH08 Typed Reconstruction

by N0zoM1z0 in N0zoM1z0/th08

Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison.

MITAuto-check passedDevelopment

Install TH08 Typed Reconstruction

skills CLI
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/th08-typed-re .claude/skills/th08-typed-re && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
th08-typed-re
GitHub stars
105
Token cost
~2.8k tokens
SKILL.md length
1,540 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison.

  • Works in 5 steps: Follow $th08-re preflight and… → Run → Read exact_observations first: target… → …
  • Diagnosing stack layout, register homes or access widths in a function being reconstructed
  • SKILL.md covers Generate a packet, Shape source, Improve the model and Handoff
  • Calls python3

What it does

The helper is a read-only fact extractor that sits below the semantic decompiler layer. It uses only the hash-attested game image and the repository's ledgers, and it never edits source, analysis databases or tracking state. You run `scripts/typed-re.py` on an address with comparison and JSON output, then read `exact_observations` first: target bytes, stack accesses, register homes, saved registers, direct calls, absolute operands and return cleanup. Compiler recommendations are only probes, and a match counts only through the canonical result from `scripts/compare-function.py`.

For shaping source, the guidance prefers a type or lifetime change that explains several observed instructions, keeps signed and unsigned narrow types where the instructions require them, and diagnoses frame differences through declaration order and real lifetimes, never through filler locals or fake behavior. It also covers large dispatchers, branch shapes produced by the VC7 compiler and the effect of the repository's variable-order pragma, where a rename counts as a code-generation change and must be compared again.

When your agent uses it

  • Diagnosing stack layout, register homes or access widths in a function being reconstructed
  • Checking direct calls and return cleanup before a strict comparison
  • Working out how to shape source so the VC7 compiler output matches the target

Example prompts

  • “Generate a typed-re packet for the function at this address and summarize the exact observations.”
  • “Use the fact packet to explain why the stack frame differs from the target.”
  • “Suggest a type change that accounts for the movsx and movzx accesses in this function.”

Requirements

  • Python 3 to run scripts/typed-re.py
  • The TH08 repository with its attested image and ledgers

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Follow $th08-re preflight and single-session scope rules.
  2. Run
  3. Read exact_observations first: target bytes, stack accesses, register
  4. Treat inferences.compiler_recommendations only as source-shaping probes.
  5. Accept matching only through the canonical comparison.report.result from

What it can do on your machine

Read from SKILL.md and the folder at commit 67e7e49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

TH08 Typed Reconstruction loads about 2.8k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 1,540 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from N0zoM1z0/th08 at commit 67e7e49, republished under its MIT licence (© N0zoM1z0). 1,540 words, ~2,841 tokens.

Download SKILL.mdSave it as .claude/skills/th08-typed-re/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
th08-typed-re
description
Generate and interpret target-pinned TH08 instruction and ABI fact packets with scripts/typed-re.py. Use for stack layout, register homes, access widths, direct calls, return cleanup, or VC7 source-shape diagnosis before strict comparison.

TH08 typed reconstruction

Use the helper as a read-only fact extractor below the semantic decompiler layer. It consumes only the hash-attested TH08 image and repository ledgers; it never edits source, analysis databases, or tracking state.

Generate a packet

  1. Follow $th08-re preflight and single-session scope rules.

  2. Run:

    bash
    python3 scripts/typed-re.py ADDRESS --compare --json \
      > build/typed-re-ADDRESS.json
  3. Read exact_observations first: target bytes, stack accesses, register homes, saved registers, direct calls, absolute operands, and return cleanup.

  4. Treat inferences.compiler_recommendations only as source-shaping probes.

  5. Accept matching only through the canonical comparison.report.result from scripts/compare-function.py.

If no match unit owns the address, the packet remains useful for ABI recovery, but comparison state is not_configured; define and review a canonical unit before claiming exactness.

Shape source

  • Prefer a type or lifetime change that explains several observed instructions.
  • Preserve signed and unsigned narrow types when movsx or movzx requires them.
  • Diagnose frame differences through declaration order and real lifetimes; never add anonymous filler, inert locals, fake behavior, or ABI lies.
  • For a large dispatcher, derive switch-wide scratch locals from stable target EBP homes across several handlers. Reuse a real outer scalar/index home when the target does, and keep a table lookup direct when the target has no stable pointer home. Probe one slot at a time so movement of later homes remains attributable.
  • If a target branches once around an entire large dispatch but VC7 emits a short inverse branch followed by a near jump, test the positive condition with the whole dispatch lexically nested inside it. Equivalent early exits and gotos can produce a different branch shape.
  • Under the repository's VC7 #pragma var_order wrapper, local identifiers can affect allocation. After a stack layout is proven, treat a rename as a code-generation change and recompare it; prefer a semantic comment over a readability-only rename while tuning exact stack homes. Use the pragma only to express an already-observed lifetime/order: Player::RegisterChain at 0x0044C230 has the resource pointers at EBP-4 and EBP-0xC, with the g_Player local at EBP-8; the natural preserve-reset-restore flow plus #pragma var_order(primaryShtFile, player, secondaryShtFile) exactly reproduces that target layout. It is not a license for inert locals or arbitrary stack shaping.
  • When a target resolves one value into a stack home and then uses that same value both to write a field and to call a setter, first test the natural chained assignment setter = (field = ReadValue(...)). It preserves the C++ value flow while allowing VC7 to retain one temporary; a separately named local can move fastcall parameter homes. Verify the whole function, since this is a source-shaping hypothesis rather than a byte-forcing device.
  • For a fixed-size slot allocator, retain the target-observed aggregate layout and express the scan as a real for loop over the active member. Under this VC7 /Od profile, for (index = 0; index < limit; index++, slot++) with if (!slot->active) break; preserves the target's initial jump, increment block, and split false/continue branches; assigning Float2::x and y separately preserves two source-address loads and stores. This is evidence for reusable allocator semantics, not permission to copy the limit, stride, offsets, or field meanings into another subsystem. TH08 Player slot allocators at 0x0044DE60..0x0044E0D8 are the exact corpus example.
  • When a recovered leaf accepts a pointer to a prefix of a larger aggregate, inspect its target callers before freezing the parameter type: a caller may prove the owning aggregate even when the leaf reads only a smaller prefix. Update the mapping signature and decorated match-unit symbol together, then re-run every affected comparator. Player::FUN_0044de60 reads only x/y but is called with Player::position (Float3) by exact 0x0044D2C0.
  • In a VC7 /Od counted loop, an early continue can preserve a target's explicit fall-through body and separate jump back to the increment block where a positive if scope emits a shorter inverse branch. Use it only when the target's condition and the skipped work establish the same semantics; Player::FUN_0044c5b0 at 0x0044C5B0 is the exact corpus example.
  • If an inlined fixed-size structure-tail memcpy has the correct semantics, size, and rep movsd but schedules its count and source setup differently, probe the typed address of the first copied field instead of byte-pointer arithmetic from the parent object. This is a source-shape hypothesis, not a shortcut around full relocation replay; ReplayManager::SaveReplay at 0x004531F0 is the exact corpus example.
  • An ECX home proves only that incoming ECX was saved to a stack slot. Decide whether it is a C++ receiver or fastcall argument zero from the decorated symbol, ledger convention, and call sites; never create inert code merely to reproduce the home.
  • Keep target facts separate from field names, calling-convention guesses, compiler recommendations, and TH06/TH07 hypotheses.
  • Do not name an absolute memory operand as a standalone global from read-side evidence alone. Search write, construction, and destruction xrefs for a known global owner. If the target address is global + member_offset, keep that ownership in source so VC7 emits a DIR32 relocation to the base symbol with the real addend; a zero-addend alias records the wrong layout even when it resolves to the same runtime address. RunEcl's enemy ANM pointers at 0x00F54E0C and 0x00F54E10 are the corpus example: both are members of g_EnemyManager, not independent globals. Likewise, GameManager::AddToYoukaiGauge at 0x0043C0BB reads 0x017D6ED4; Player receiver reads and writes establish it as g_Player + 0xFDC. Modelling it as Player::frameStop produces the required g_Player DIR32 relocation with addend 0xFDC, whereas a standalone symbol cannot faithfully replay it.
  • Resolve comparison destinations by each CSV header's named address column; the function/global ledgers place it differently from float/string ledgers. Keep attested IAT slots, import thunks, and other non-inventory symbols in config/reccmp-relocations.csv. Never add a fake function or global merely to make relocation replay pass. A destination being ledgered only removes an evidence gap: require exact isolated extent and full zero-difference replay before adding a match. The zwave and AnmManager unblocked batches are the corpus example (15 functions, 5,259 authored bytes, 146 relocations).
  • Test every source-shaping change through $th08-matching.
  • If target code ends before the next mapped function but the COFF auxiliary size continues through switch tables, compare the complete associated extent with compare_size while keeping size at the authored code extent. Report and count authored coverage from size only. Normalize compiler-local table symbols by relocation offset and resolved target, and replay every entry. A size error is a boundary question before it is a source-shaping instruction. The four exact AnmVm accessors at 0x0045E650..0x0045E953 are the compact corpus: 615 authored bytes plus 136 associated table bytes, all 751 compared.
  • Large dispatchers may own several adjacent compiler tables. Prove each table boundary from code-local pointers and the next trusted function start, keep all table-entry relocations in the canonical manifest, and require exact relocation replay over the full COFF auxiliary extent. AnmManager::ExecuteScript is the corpus example: 0x366D code plus 0x1A0 bytes of 91+6+7 entries.
  • Do not infer a local vector type solely from matching three f32 fields. An observed default-constructor call is a type/translation-unit fact: test the candidate type in the affected handler and retain it only if the span crosswalk improves. In particular, TH08 RunEcl opcode 140's 0x0040B460 construction is not reproduced by substituting SDK D3DXVECTOR3 or the project Float3: both probes grew the handler by 11 bytes because they moved the vector home from the target's EBP-0x60 to the object's EBP-0x90. Reconcile the dispatcher stack layout first.
  • When a dispatcher’s COFF extent grows or shrinks, make a read-only span crosswalk before changing source: resolve every target jump-table slot and every COFF table DIR32 relocation to its handler start, deduplicate and sort starts in physical order, then compare adjacent target and object handler spans. This attributes a size delta to a bounded handler (including shared/default handlers) without treating Ghidra/IDA extents as compiler boundaries. It is a diagnostic fact map, not a matching claim; retain full relocation replay and canonical comparison as the acceptance gate.
  • When a target passes a raw float operand with mov/push but VC7 emits an fld/fstp argument shuffle, changing only a byte-tail reinterpret cast into an overlay union can leave the COFF completely unchanged. Reject that no-op probe; investigate the resolver call expression or ABI instead. TH08 RunEcl opcodes 34 and 39 are the corpus case.
  • For a dispatcher handler, do not accept a lower total COFF size as evidence that a source-shape probe is closer. Crosswalk the handler itself. In TH08 RunEcl opcode 39, fusing the two subtraction operands into each resolver branch shortened the whole object by 42 bytes, yet disagreed with the target's four independent resolved-value homes followed by two subtractions. Restore such a probe unless its target handler sequence improves. TH07 may suggest an expression form, but it is corroboration only; modelling TH08's operand tail as i32[1] rather than a byte tail did not alter this COFF.
Show full SKILL.md (111 more words)Show less

Improve the model

The stable CLI is scripts/typed-re.py; implementation modules live under scripts/typed_re/. Changes to this automation, its rules, regressions, or skill need a dedicated reviewed commit.

For a new extractor or rule, fail closed on target identity, PE mapping, ledger extent, and incomplete decoding; keep deterministic target observations out of inferences; add a target-pinned assertion to --check; then run:

bash
python3 -m compileall -q scripts/typed_re scripts/typed-re.py
python3 scripts/typed-re.py --check

There is no VC7 library scanner yet. Do not create or claim one until SHA-pinned TH08 archives, a relocation allowlist, and comparator replay are configured; never substitute TH07 archives or rules.

Handoff

Report the address and size, exact observations used, recommendation tested, canonical comparison unit and result, and any helper/rule changes.

© N0zoM1z0, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/th08-typed-re of N0zoM1z0/th08.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 67e7e49

Compare with similar skills

TH08 Typed Reconstruction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

TH08 Typed Reconstruction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
TH08 Typed Reconstruction this skillN0zoM1z0/th08105—~2.8kAutomated safety check: PassMIT
Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills185—~826Automated safety check: PassMIT
Ghidra ReOrbitCurve/firmware-reverse-engineering216—~4.2kAutomated safety check: PassApache-2.0
Nuitka Nbc RebuilderDimaReverse/nuitka-static-unpacker132—~2kAutomated safety check: PassMIT
Web Reschlarpc/re-shell532—~1.4kAutomated safety check: PassNone
Electron App Security Analyzerptn1411/skill219—~830Automated safety check: NotesNone

Similar skills

  • Combine Dbc

    CSS-Electronics/can-bus-reverse-engineering-skills

    Combine multiple individual single-signal DBC files into one combined DBC at the application level.

    185 GitHub stars~826 tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    216 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Nuitka Nbc Rebuilder

    DimaReverse/nuitka-static-unpacker

    Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.

    132 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web Re

    schlarpc/re-shell

    Web reverse engineering tools and workflows. An agent skill from schlarpc/re-shell.

    532 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 19 days ago
    SecurityAuto-check: notes
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from N0zoM1z0/th08

  • Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence.

    105 GitHub stars~877 tokensUpdated today
    Auto-check passed
  • Reconstructs bounded functions from the original Japanese TH08 1.00d executable for a source decompilation project, using hash-verified target evidence and labeled corroboration.

    105 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches.

    105 GitHub stars~8.7k tokensUpdated today
    Auto-check passed
  • Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.

    105 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about TH08 Typed Reconstruction

What does TH08 Typed Reconstruction do?

Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison. The helper is a read-only fact extractor that sits below the semantic decompiler layer. It uses only the hash-attested game image and the repository's ledgers, and it never edits source, analysis databases or tracking state.

When should I use TH08 Typed Reconstruction?

TH08 Typed Reconstruction fits situations like: diagnosing stack layout, register homes or access widths in a function being reconstructed; checking direct calls and return cleanup before a strict comparison; working out how to shape source so the VC7 compiler output matches the target.

How do I install TH08 Typed Reconstruction in Claude Code?

Run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a claude-code`. Or copy the skill folder (.agents/skills/th08-typed-re in N0zoM1z0/th08) into .claude/skills/th08-typed-re in your project. Claude Code loads it when a task matches its description.

How do I install TH08 Typed Reconstruction in Codex?

Run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a codex`. Or copy the skill folder (.agents/skills/th08-typed-re in N0zoM1z0/th08) into .agents/skills/th08-typed-re in your project. Codex loads it when a task matches its description.

Can I use TH08 Typed Reconstruction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/th08-typed-re, .gemini/skills/th08-typed-re, .github/skills/th08-typed-re and .opencode/skills/th08-typed-re in your project.

What does TH08 Typed Reconstruction need to run?

Going by SKILL.md and its folder, TH08 Typed Reconstruction needs the command-line tools its instructions call (python3). Our summary lists: Python 3 to run scripts/typed-re.py; The TH08 repository with its attested image and ledgers.

Does TH08 Typed Reconstruction access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is TH08 Typed Reconstruction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does TH08 Typed Reconstruction use?

TH08 Typed Reconstruction is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does TH08 Typed Reconstruction use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to TH08 Typed Reconstruction?

Skills that share tags, products or a category with TH08 Typed Reconstruction: Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 185 stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Nuitka Nbc Rebuilder (DimaReverse/nuitka-static-unpacker, 132 stars) and Web Re (schlarpc/re-shell, 532 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains TH08 Typed Reconstruction?

N0zoM1z0 (a GitHub user) maintains it in N0zoM1z0/th08, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 11, 2026.

Source: N0zoM1z0/th08 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.