Combine Dbc
CSS-Electronics/can-bus-reverse-engineering-skills
Combine multiple individual single-signal DBC files into one combined DBC at the application level.
Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison.
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/th08-typed-re .claude/skills/th08-typed-re && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .claude/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-reType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/th08-typed-re .agents/skills/th08-typed-re && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .agents/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/th08-typed-re .cursor/skills/th08-typed-re && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .cursor/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/N0zoM1z0/th08.git --path .agents/skills/th08-typed-re--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/th08-typed-re .gemini/skills/th08-typed-re && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .gemini/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install N0zoM1z0/th08 th08-typed-reInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/th08-typed-re .github/skills/th08-typed-re && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .github/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add N0zoM1z0/th08 --skill th08-typed-re -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install N0zoM1z0/th08 th08-typed-re --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/N0zoM1z0/th08.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/th08-typed-re .opencode/skills/th08-typed-re && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "th08-typed-re" agent skill from https://github.com/N0zoM1z0/th08/tree/main/.agents/skills/th08-typed-re into .opencode/skills/th08-typed-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "th08-typed-re", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
th08-typed-reGenerates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison.
The helper is a read-only fact extractor that sits below the semantic decompiler layer. It uses only the hash-attested game image and the repository's ledgers, and it never edits source, analysis databases or tracking state. You run `scripts/typed-re.py` on an address with comparison and JSON output, then read `exact_observations` first: target bytes, stack accesses, register homes, saved registers, direct calls, absolute operands and return cleanup. Compiler recommendations are only probes, and a match counts only through the canonical result from `scripts/compare-function.py`.
For shaping source, the guidance prefers a type or lifetime change that explains several observed instructions, keeps signed and unsigned narrow types where the instructions require them, and diagnoses frame differences through declaration order and real lifetimes, never through filler locals or fake behavior. It also covers large dispatchers, branch shapes produced by the VC7 compiler and the effect of the repository's variable-order pragma, where a rename counts as a code-generation change and must be compared again.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 67e7e49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
TH08 Typed Reconstruction loads about 2.8k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 1,540 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from N0zoM1z0/th08 at commit 67e7e49, republished under its MIT licence (© N0zoM1z0). 1,540 words, ~2,841 tokens.
.claude/skills/th08-typed-re/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use the helper as a read-only fact extractor below the semantic decompiler layer. It consumes only the hash-attested TH08 image and repository ledgers; it never edits source, analysis databases, or tracking state.
Follow $th08-re preflight and single-session scope rules.
Run:
python3 scripts/typed-re.py ADDRESS --compare --json \
> build/typed-re-ADDRESS.jsonRead exact_observations first: target bytes, stack accesses, register
homes, saved registers, direct calls, absolute operands, and return cleanup.
Treat inferences.compiler_recommendations only as source-shaping probes.
Accept matching only through the canonical comparison.report.result from
scripts/compare-function.py.
If no match unit owns the address, the packet remains useful for ABI recovery,
but comparison state is not_configured; define and review a canonical unit
before claiming exactness.
movsx or movzx requires
them.#pragma var_order wrapper, local identifiers
can affect allocation. After a stack layout is proven, treat a rename as a
code-generation change and recompare it; prefer a semantic comment over a
readability-only rename while tuning exact stack homes. Use the pragma only
to express an already-observed lifetime/order: Player::RegisterChain at
0x0044C230 has the resource pointers at EBP-4 and EBP-0xC, with the
g_Player local at EBP-8; the natural preserve-reset-restore flow plus
#pragma var_order(primaryShtFile, player, secondaryShtFile) exactly
reproduces that target layout. It is not a license for inert locals or
arbitrary stack shaping.setter = (field = ReadValue(...)). It preserves the
C++ value flow while allowing VC7 to retain one temporary; a separately
named local can move fastcall parameter homes. Verify the whole function,
since this is a source-shaping hypothesis rather than a byte-forcing device.for loop over the active member. Under this
VC7 /Od profile, for (index = 0; index < limit; index++, slot++) with
if (!slot->active) break; preserves the target's initial jump, increment
block, and split false/continue branches; assigning Float2::x and y
separately preserves two source-address loads and stores. This is evidence
for reusable allocator semantics, not permission to copy the limit, stride,
offsets, or field meanings into another subsystem. TH08 Player slot allocators
at 0x0044DE60..0x0044E0D8 are the exact corpus example.Player::FUN_0044de60 reads only x/y but
is called with Player::position (Float3) by exact 0x0044D2C0./Od counted loop, an early continue can preserve a target's
explicit fall-through body and separate jump back to the increment block
where a positive if scope emits a shorter inverse branch. Use it only when
the target's condition and the skipped work establish the same semantics;
Player::FUN_0044c5b0 at 0x0044C5B0 is the exact corpus example.memcpy has the correct semantics,
size, and rep movsd but schedules its count and source setup differently,
probe the typed address of the first copied field instead of byte-pointer
arithmetic from the parent object. This is a source-shape hypothesis, not a
shortcut around full relocation replay; ReplayManager::SaveReplay at
0x004531F0 is the exact corpus example.global + member_offset, keep
that ownership in source so VC7 emits a DIR32 relocation to the base symbol
with the real addend; a zero-addend alias records the wrong layout even when
it resolves to the same runtime address. RunEcl's enemy ANM pointers at
0x00F54E0C and 0x00F54E10 are the corpus example: both are members of
g_EnemyManager, not independent globals. Likewise,
GameManager::AddToYoukaiGauge at 0x0043C0BB reads 0x017D6ED4; Player
receiver reads and writes establish it as g_Player + 0xFDC. Modelling it
as Player::frameStop produces the required g_Player DIR32 relocation with
addend 0xFDC, whereas a standalone symbol cannot faithfully replay it.address column;
the function/global ledgers place it differently from float/string ledgers.
Keep attested IAT slots, import thunks, and other non-inventory symbols in
config/reccmp-relocations.csv. Never add a fake function or global merely
to make relocation replay pass. A destination being ledgered only removes an
evidence gap: require exact isolated extent and full zero-difference replay
before adding a match. The zwave and AnmManager unblocked batches are the
corpus example (15 functions, 5,259 authored bytes, 146 relocations).$th08-matching.compare_size while keeping size at the authored code extent. Report
and count authored coverage from size only. Normalize compiler-local table
symbols by relocation offset and resolved target, and replay every entry. A
size error is a boundary question before it is a source-shaping instruction.
The four exact AnmVm accessors at 0x0045E650..0x0045E953 are the compact
corpus: 615 authored bytes plus 136 associated table bytes, all 751 compared.AnmManager::ExecuteScript
is the corpus example: 0x366D code plus 0x1A0 bytes of 91+6+7 entries.f32 fields.
An observed default-constructor call is a type/translation-unit fact: test
the candidate type in the affected handler and retain it only if the span
crosswalk improves. In particular, TH08 RunEcl opcode 140's
0x0040B460 construction is not reproduced by substituting SDK
D3DXVECTOR3 or the project Float3: both probes grew the handler by 11
bytes because they moved the vector home from the target's EBP-0x60 to
the object's EBP-0x90. Reconcile the dispatcher stack layout first.DIR32 relocation to its handler start, deduplicate and
sort starts in physical order, then compare adjacent target and object
handler spans. This attributes a size delta to a bounded handler (including
shared/default handlers) without treating Ghidra/IDA extents as compiler
boundaries. It is a diagnostic fact map, not a matching claim; retain full
relocation replay and canonical comparison as the acceptance gate.mov/push but VC7 emits an
fld/fstp argument shuffle, changing only a byte-tail reinterpret cast
into an overlay union can leave the COFF completely unchanged. Reject that
no-op probe; investigate the resolver call expression or ABI instead. TH08
RunEcl opcodes 34 and 39 are the corpus case.RunEcl opcode 39, fusing the two subtraction operands into each resolver
branch shortened the whole object by 42 bytes, yet disagreed with the
target's four independent resolved-value homes followed by two subtractions.
Restore such a probe unless its target handler sequence improves. TH07 may
suggest an expression form, but it is corroboration only; modelling TH08's
operand tail as i32[1] rather than a byte tail did not alter this COFF.The stable CLI is scripts/typed-re.py; implementation modules live under
scripts/typed_re/. Changes to this automation, its rules, regressions, or
skill need a dedicated reviewed commit.
For a new extractor or rule, fail closed on target identity, PE mapping,
ledger extent, and incomplete decoding; keep deterministic target observations
out of inferences; add a target-pinned assertion to --check; then run:
python3 -m compileall -q scripts/typed_re scripts/typed-re.py
python3 scripts/typed-re.py --checkThere is no VC7 library scanner yet. Do not create or claim one until SHA-pinned TH08 archives, a relocation allowlist, and comparator replay are configured; never substitute TH07 archives or rules.
Report the address and size, exact observations used, recommendation tested, canonical comparison unit and result, and any helper/rule changes.
© N0zoM1z0, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/th08-typed-re of N0zoM1z0/th08.
Open the folder on GitHubat commit 67e7e49
TH08 Typed Reconstruction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| TH08 Typed Reconstruction this skillN0zoM1z0/th08 | 105 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills | 185 | — | ~826 | Automated safety check: Pass | MIT | |
| Ghidra ReOrbitCurve/firmware-reverse-engineering | 216 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Nuitka Nbc RebuilderDimaReverse/nuitka-static-unpacker | 132 | — | ~2k | Automated safety check: Pass | MIT | |
| Web Reschlarpc/re-shell | 532 | — | ~1.4k | Automated safety check: Pass | None | |
| Electron App Security Analyzerptn1411/skill | 219 | — | ~830 | Automated safety check: Notes | None |
CSS-Electronics/can-bus-reverse-engineering-skills
Combine multiple individual single-signal DBC files into one combined DBC at the application level.
OrbitCurve/firmware-reverse-engineering
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
DimaReverse/nuitka-static-unpacker
Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.
schlarpc/re-shell
Web reverse engineering tools and workflows. An agent skill from schlarpc/re-shell.
ptn1411/skill
Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
N0zoM1z0/th08
Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence.
N0zoM1z0/th08
Reconstructs bounded functions from the original Japanese TH08 1.00d executable for a source decompilation project, using hash-verified target evidence and labeled corroboration.
N0zoM1z0/th08
Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches.
N0zoM1z0/th08
Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior.
Works with
Categories
Generates and reads target-pinned instruction and ABI fact packets for a source reconstruction project, to guide source shaping before a strict comparison. The helper is a read-only fact extractor that sits below the semantic decompiler layer. It uses only the hash-attested game image and the repository's ledgers, and it never edits source, analysis databases or tracking state.
TH08 Typed Reconstruction fits situations like: diagnosing stack layout, register homes or access widths in a function being reconstructed; checking direct calls and return cleanup before a strict comparison; working out how to shape source so the VC7 compiler output matches the target.
Run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a claude-code`. Or copy the skill folder (.agents/skills/th08-typed-re in N0zoM1z0/th08) into .claude/skills/th08-typed-re in your project. Claude Code loads it when a task matches its description.
Run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a codex`. Or copy the skill folder (.agents/skills/th08-typed-re in N0zoM1z0/th08) into .agents/skills/th08-typed-re in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add N0zoM1z0/th08 --skill th08-typed-re -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/th08-typed-re, .gemini/skills/th08-typed-re, .github/skills/th08-typed-re and .opencode/skills/th08-typed-re in your project.
Going by SKILL.md and its folder, TH08 Typed Reconstruction needs the command-line tools its instructions call (python3). Our summary lists: Python 3 to run scripts/typed-re.py; The TH08 repository with its attested image and ledgers.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
TH08 Typed Reconstruction is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with TH08 Typed Reconstruction: Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 185 stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Nuitka Nbc Rebuilder (DimaReverse/nuitka-static-unpacker, 132 stars) and Web Re (schlarpc/re-shell, 532 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
N0zoM1z0 (a GitHub user) maintains it in N0zoM1z0/th08, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 11, 2026.
Source: N0zoM1z0/th08 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.