Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .claude/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .agents/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .cursor/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .gemini/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .github/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "firmware-security-reports" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/firmware-security-reports into .opencode/skills/firmware-security-reports/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firmware-security-reports", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
firmware-security-reports
GitHub stars
214
Token cost
~4.1k tokens
SKILL.md length
659 words
Files
5 (incl. references, assets)
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0
At a glance
Evidence-based security report generation for firmware assessments.
Works in 7 steps: Full Penetration Test Report → Individual Finding Report → Working Notes → …
The agent needs to create technical security reports from firmware analysis
SKILL.md covers Skill Scope, Report Types, Workflow and Integration with Firmware…, plus 6 more sections
Calls pandoc and curl
What it does
Firmware Security Reports is an agent skill from OrbitCurve/firmware-reverse-engineering. Evidence-based security report generation for firmware assessments. Use when the agent needs to create technical security reports from firmware analysis. Covers: (1) Full penetration test reports with executive summaries and technical details, (2) Individual vulnerability findings with CVSS 3.1 scoring, (3) Working notes for documentation during assessment, (4) Integration with firmware analysis skills (extraction, static analysis, Ghidra RE, emulation). Outputs to markdown and PDF formats. Technical audience…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/finding_template.md`, `assets/pentest_report_template.md` and `assets/working_notes_template.md`).
It sits in Security, covering Reverse engineering and malware, Summarization and Static analysis and SAST. It works with Ghidra. The repository describes itself as: A full claude and codex skillsets for firmware reverse engineering. The licence is Apache-2.0.
When your agent uses it
The agent needs to create technical security reports from firmware analysis
Tasks that involve Reverse engineering and malware
Tasks that involve Summarization
Example prompts
“/firmware-security-reports”
Requirements
Python 3
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a047a60. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
pandoc
curl
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Firmware Security Reports loads about 4.1k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 160 tokens; SKILL.md has 659 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~160
When it runs· the whole SKILL.md, loaded when a task matches
~4.1k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~6.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/firmware-security-reports/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
firmware-security-reports
description
Evidence-based security report generation for firmware assessments. Use when the agent needs to create technical security reports from firmware analysis. Covers: (1) Full penetration test reports with executive summaries and technical details, (2) Individual vulnerability findings with CVSS 3.1 scoring, (3) Working notes for documentation during assessment, (4) Integration with firmware analysis skills (extraction, static analysis, Ghidra RE, emulation). Outputs to markdown and PDF formats. Technical audience only. Includes templates for findings, PoC code, remediation guidance, and evidence documentation.
Firmware Security Report Generation
Professional technical security reports for firmware assessments, following industry standards from elite American security firms.
All example findings, products, versions, addresses and scores in this skill
and its templates are illustrative. Replace them with verified assessment
evidence; do not carry example results into a deliverable.
Skill Scope
Use this skill for:
Generating penetration test reports from firmware analysis
Documenting individual security findings
Creating working notes during assessments
Converting analysis results to professional deliverables
Output Formats:
Markdown (version-controllable, easy to edit)
PDF (via Pandoc, or a separately installed PDF skill if available)
Option 1: Use a separately installed PDF skill, if available
bash
# Read pdf skill for conversion
# Convert markdown to professional PDF
Option 2: Use Pandoc with XeLaTeX installed
Choose fonts that cover the report characters, replace unsupported symbols and
review the rendered pages for clipping and missing glyphs before delivery.
## Binary Security Analysis
**Binaries Analyzed:** 15 (in /usr/sbin/)
**Key Findings:**
- /usr/sbin/httpd: No PIE, stack canaries present
- /usr/sbin/telnetd: No security mitigations
- /usr/lib/libcrypto.so: AES implementation uses OpenSSL 1.0.2k
**Architecture:** ARM 32-bit, little-endian
**Calling Convention:** ARM EABI
From ghidra-re
markdown
## Reverse Engineering Findings
**Authentication Function Analysis:**
Function: `check_password` at 0x00401234
- Uses strcmp(); assess whether a remotely measurable secret-dependent timing difference exists
- Rate limiting and empty-password acceptance require separate verification; the snippet alone does not establish them
Decompiled code:
```c
int check_password(char *username, char *password) {
char stored_hash[32];
load_user_hash(username, stored_hash);
if (strcmp(password_hash(password), stored_hash) == 0) {
return AUTH_SUCCESS;
}
return AUTH_FAIL;
}
```
**Cryptographic Analysis:**
- AES S-box found at 0x0040A000
- MD5 constants in auth_daemon
- Hardcoded key: `0x0123456789ABCDEF0123456789ABCDEF`
From firmware-emulation
markdown
## Dynamic Analysis Results
**Emulation Environment:**
- QEMU system-mode (ARM versatilepb)
- Kernel: Extracted from firmware (Linux 4.9.118)
- Network: TAP interface (192.168.100.1/24)
**Runtime Behavior:**
- Firmware boots successfully in 45 seconds
- All services start automatically
- Debug logging enabled (sensitive data in logs)
**Network Traffic Analysis:**
```
tcpdump capture: evidence/network_traffic.pcap
Key findings:
- Cleartext credentials in HTTP POST
- No TLS for admin interface
- API keys in HTTP headers: X-API-Key: 0x123456...
```
**Exploitation:**
```bash
# Successful RCE via command injection
$ curl -X POST http://192.168.100.2/cgi-bin/admin.cgi \
-d "cmd=;id"
Response: uid=0(root) gid=0(root)
```
Best Practices
Show full SKILL.md (277 more words)Show less
Writing Technical Findings
DO:
Use precise technical language
Include addresses, file paths, line numbers
Provide working proof-of-concept code
Show before/after code for remediation
Calculate accurate CVSS scores
Include evidence (screenshots, PCAPs)
Explain impact clearly
DON'T:
Use vague descriptions ("security issue found")
Over-hype severity without justification
Provide theoretical exploits without validation
Skip remediation guidance
Forget to include CWE/OWASP references
CVSS Scoring
Always justify your scores. Use references/cvss-scoring.md for guidance.
Example:
markdown
**CVSS v3.1 Score:** 9.8 (Critical)
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
**Justification:**
- AV:N - Exploitable remotely over network
- AC:L - No special conditions required, reliable exploitation
- PR:N - No authentication required
- UI:N - No user interaction needed
- S:U - Impact contained to vulnerable component
- C:H - Full file system access as root
- I:H - Complete system modification possible
- A:H - Can crash or brick device
Sensitive client data redacted (if sharing publicly)
PDF generated and reviewed
Executive summary tells coherent story
Common Report Sections
Executive Summary
Purpose: High-level overview for decision-makers
Template:
markdown
This assessment of [PRODUCT] version [VERSION] identified [COUNT] security
vulnerabilities, including [COUNT] critical issues that allow remote attackers
to [PRIMARY_IMPACT].
The most severe finding is [FW-ID]: [TITLE], which enables [ATTACK_SCENARIO].
Immediate remediation is recommended for all critical findings.
Key recommendations:
1. [ACTION_1] - Addresses FW-001, FW-002
2. [ACTION_2] - Addresses FW-003, FW-004
3. [ACTION_3] - Improves overall security posture
Methodology
Purpose: Establish credibility, explain approach
Template:
markdown
The assessment followed a structured methodology:
1. **Firmware Acquisition** - [How firmware was obtained]
2. **Extraction** - Tools: binwalk, jefferson, sasquatch
3. **Static Analysis** - Binary analysis, configuration review
4. **Reverse Engineering** - Ghidra-based deep analysis
5. **Dynamic Analysis** - QEMU emulation, runtime testing
6. **Exploitation** - PoC development and validation
7. **Documentation** - Report generation and evidence collection
Time invested: [HOURS] over [DAYS] days
Risk Summary
Purpose: Quantify overall risk
Template:
markdown
### Risk Distribution
[Chart showing Critical/High/Medium/Low distribution]
**Critical Risks (9.0-10.0):** 2 findings
- Enable remote code execution without authentication
- Full device compromise possible
**High Risks (7.0-8.9):** 3 findings
- Require authentication but lead to privilege escalation
- Sensitive data disclosure
**Overall Risk:** HIGH
The device is vulnerable to remote compromise. Immediate action required.
working_notes_template.md - Assessment tracking and notes
Additional reference:
references/cvss-scoring.md - CVSS 3.1 calculation guide with examples
Quick Start
bash
# 1. During assessment - keep working notes
cp assets/working_notes_template.md working_notes.md
# Update daily with findings
# 2. For each vulnerability - create finding
cp assets/finding_template.md findings/FW-001-vuln-name.md
# Fill in technical details, PoC, remediation
# 3. At end - assemble full report
cp assets/pentest_report_template.md final_report.md
# Import findings, add analysis, create roadmap
# 4. Generate PDF (use pdf skill or pandoc)
# pandoc final_report.md -o final_report.pdf --pdf-engine=xelatex
Integration Example
Complete workflow from analysis to report:
bash
# Day 1-3: Analysis
binwalk -e firmware.bin
readelf -h binary
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /proj Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary -postScript find_crypto.py
qemu-arm -g 1234 -L ./rootfs/ ./binary
# Day 3-5: Documentation
cp assets/finding_template.md findings/FW-001-cmdinj.md
# Fill in details from Ghidra/QEMU analysis
# Day 5-7: Report Writing
cp assets/pentest_report_template.md acme_iot_gateway_report.md
# Compile all findings into main report
# Day 7: Delivery
pandoc acme_iot_gateway_report.md -o acme_iot_gateway_report.pdf --pdf-engine=xelatex
# Send to client
Professional Standards
Reports should distinguish verified findings, unverified candidates, test
limitations and informational observations. This repository does not claim
endorsement or certification by a security consultancy. Use the agreed
assessment methodology and the applicable FIRST CVSS specification.
Key principles:
Accuracy - Support claims with reproducible evidence; state what a PoC actually demonstrates
Reproducibility - Clear exploitation steps
Actionability - Specific remediation guidance
Evidence - Screenshots, PCAPs, code samples
Professionalism - Technical depth without fluff
Review all generated reports against the engagement scope and evidence before delivery.
SKILL.md and 4 other files (references, assets) in plugins/firmware-reverse-engineering/skills/firmware-security-reports of OrbitCurve/firmware-reverse-engineering.
Firmware Security Reports next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Firmware Security Reports compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Firmware Security Reports this skillOrbitCurve/firmware-reverse-engineering
Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…
A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…
Evidence-based security report generation for firmware assessments. Firmware Security Reports is an agent skill from OrbitCurve/firmware-reverse-engineering. Evidence-based security report generation for firmware assessments.
When should I use Firmware Security Reports?
Firmware Security Reports fits situations like: the agent needs to create technical security reports from firmware analysis; tasks that involve Reverse engineering and malware; tasks that involve Summarization.
How do I install Firmware Security Reports in Claude Code?
Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a claude-code`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/firmware-security-reports in OrbitCurve/firmware-reverse-engineering) into .claude/skills/firmware-security-reports in your project. Claude Code loads it when a task matches its description.
How do I install Firmware Security Reports in Codex?
Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a codex`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/firmware-security-reports in OrbitCurve/firmware-reverse-engineering) into .agents/skills/firmware-security-reports in your project. Codex loads it when a task matches its description.
Can I use Firmware Security Reports in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firmware-security-reports, .gemini/skills/firmware-security-reports, .github/skills/firmware-security-reports and .opencode/skills/firmware-security-reports in your project.
What does Firmware Security Reports need to run?
Going by SKILL.md and its folder, Firmware Security Reports needs the command-line tools its instructions call (pandoc and curl). Our summary lists: Python 3.
Does Firmware Security Reports access the network?
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Firmware Security Reports safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Firmware Security Reports use?
Firmware Security Reports is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Firmware Security Reports use?
About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.
What are the alternatives to Firmware Security Reports?
Skills that share tags, products or a category with Firmware Security Reports: Analyzing Packed Malware With Upx Unpacker (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Linux Elf Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Binary Re (aiskillstore/marketplace, 430 stars) and Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Firmware Security Reports?
OrbitCurve (a GitHub organization) maintains it in OrbitCurve/firmware-reverse-engineering, which has 214 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 7, 2026.