Agent skill

Firmware Security Reports

by OrbitCurve in OrbitCurve/firmware-reverse-engineering

Evidence-based security report generation for firmware assessments.

Apache-2.0Auto-check passedSecurity

Install Firmware Security Reports

skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OrbitCurve/firmware-reverse-engineering firmware-security-reports --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/firmware-security-reports .claude/skills/firmware-security-reports && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
firmware-security-reports
GitHub stars
214
Token cost
~4.1k tokens
SKILL.md length
659 words
Files
5 (incl. references, assets)
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Evidence-based security report generation for firmware assessments.

  • Works in 7 steps: Full Penetration Test Report → Individual Finding Report → Working Notes → …
  • The agent needs to create technical security reports from firmware analysis
  • SKILL.md covers Skill Scope, Report Types, Workflow and Integration with Firmware…, plus 6 more sections
  • Calls pandoc and curl

What it does

Firmware Security Reports is an agent skill from OrbitCurve/firmware-reverse-engineering. Evidence-based security report generation for firmware assessments. Use when the agent needs to create technical security reports from firmware analysis. Covers: (1) Full penetration test reports with executive summaries and technical details, (2) Individual vulnerability findings with CVSS 3.1 scoring, (3) Working notes for documentation during assessment, (4) Integration with firmware analysis skills (extraction, static analysis, Ghidra RE, emulation). Outputs to markdown and PDF formats. Technical audience…

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/finding_template.md`, `assets/pentest_report_template.md` and `assets/working_notes_template.md`).

It sits in Security, covering Reverse engineering and malware, Summarization and Static analysis and SAST. It works with Ghidra. The repository describes itself as: A full claude and codex skillsets for firmware reverse engineering. The licence is Apache-2.0.

When your agent uses it

  • The agent needs to create technical security reports from firmware analysis
  • Tasks that involve Reverse engineering and malware
  • Tasks that involve Summarization

Example prompts

  • “/firmware-security-reports”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Full Penetration Test Report
  2. Individual Finding Report
  3. Working Notes
  4. Assessment Execution
  5. Finding Documentation
  6. Report Assembly
  7. PDF Generation

What it can do on your machine

Read from SKILL.md and the folder at commit a047a60. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pandoc
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Firmware Security Reports loads about 4.1k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 160 tokens; SKILL.md has 659 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~160
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OrbitCurve/firmware-reverse-engineering at commit a047a60, republished under its Apache-2.0 licence (© OrbitCurve). 659 words, ~4,148 tokens.

Download SKILL.mdSave it as .claude/skills/firmware-security-reports/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
firmware-security-reports
description
Evidence-based security report generation for firmware assessments. Use when the agent needs to create technical security reports from firmware analysis. Covers: (1) Full penetration test reports with executive summaries and technical details, (2) Individual vulnerability findings with CVSS 3.1 scoring, (3) Working notes for documentation during assessment, (4) Integration with firmware analysis skills (extraction, static analysis, Ghidra RE, emulation). Outputs to markdown and PDF formats. Technical audience only. Includes templates for findings, PoC code, remediation guidance, and evidence documentation.

Firmware Security Report Generation

Professional technical security reports for firmware assessments, following industry standards from elite American security firms.

All example findings, products, versions, addresses and scores in this skill and its templates are illustrative. Replace them with verified assessment evidence; do not carry example results into a deliverable.

Skill Scope

Use this skill for:

  • Generating penetration test reports from firmware analysis
  • Documenting individual security findings
  • Creating working notes during assessments
  • Converting analysis results to professional deliverables

Output Formats:

  • Markdown (version-controllable, easy to edit)
  • PDF (via Pandoc, or a separately installed PDF skill if available)

Integration:

  • Consumes outputs from: firmware-extraction, firmware-static-analysis, ghidra-re, firmware-emulation
  • Produces: Professional security reports for clients/stakeholders

Report Types

1. Full Penetration Test Report

Template: assets/pentest_report_template.md

Sections:

  • Executive Summary (key findings, risk summary, priority recommendations)
  • Scope and Methodology (detailed approach, tools used)
  • Findings (with CVSS scores, PoC, remediation)
  • Technical Analysis Details (architecture, security mitigations, network services)
  • Remediation Roadmap (phased approach with timelines)
  • Appendices (CVSS calculations, exploit code, evidence)

Usage:

markdown
# Fill in template placeholders:
[CLIENT_NAME] → Acme Corporation
[PRODUCT_NAME] → IoT Gateway Pro
[FIRMWARE_VERSION] → v2.3.1
[ARCHITECTURE] → ARM Cortex-A9
etc.

# Add findings from analysis:
FW-001: Remote Command Injection
FW-002: Hardcoded Cryptographic Keys
FW-003: MD5 Password Hashing
2. Individual Finding Report

Template: assets/finding_template.md

Sections:

  • Finding metadata (severity, CVSS, CWE)
  • Technical description
  • Impact analysis
  • Proof of concept with exploit code
  • Evidence (screenshots, PCAPs, logs)
  • Remediation guidance with code fixes
  • Verification steps

Usage:

markdown
# Create one file per finding:
FW-001-command-injection.md
FW-002-hardcoded-keys.md
FW-003-weak-hashing.md

# Compile into main report
3. Working Notes

Template: assets/working_notes_template.md

Sections:

  • Daily activity log
  • Vulnerability tracking table
  • Technical details and file system map
  • Exploitation notes
  • Evidence file inventory
  • Time tracking

Usage:

markdown
# Update daily during assessment
# Track progress and findings
# Reference when writing final report
# Internal documentation only (not for client)

Workflow

Phase 1: Assessment Execution

Use your firmware analysis skills to find vulnerabilities:

bash
# 1. Extract firmware
binwalk -e firmware.bin

# 2. Static analysis
readelf -h binary
strings binary | grep password

# 3. Ghidra RE (set GHIDRA_INSTALL_DIR/GHIDRA_SCRIPT_DIR as in ghidra-re)
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /proj Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary \
  -postScript find_auth_functions.py \
  -postScript find_buffer_overflows.py

# 4. Emulation & testing
qemu-arm -L ./rootfs/ ./binary
curl -X POST http://192.168.1.1/vuln.cgi -d "param=;id"

# 5. Document in working notes
Phase 2: Finding Documentation

For each vulnerability discovered:

Step 1: Copy finding template

bash
cp assets/finding_template.md findings/FW-001-command-injection.md

Step 2: Fill in details

markdown
## FW-001: Remote Command Injection in Diagnostic Interface

**Severity:** Critical
**CVSS v3.1 Score:** 9.8 (Critical)
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Affected Component:** /cgi-bin/diagnostic.cgi
**Location:** /www/cgi-bin/diagnostic.cgi, line 42

### Description

The diagnostic.cgi script accepts a 'target' parameter for network ping
functionality. User input is passed directly to system() without validation,
allowing arbitrary command execution.

[Continue filling template...]

Step 3: Calculate CVSS

Use references/cvss-scoring.md for guidance:

Remote command injection, no auth:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8

Step 4: Create PoC

python
#!/usr/bin/env python3
import requests

target = "http://192.168.1.1"
payload = {"target": "127.0.0.1;id"}

r = requests.post(f"{target}/cgi-bin/diagnostic.cgi", data=payload)
print(r.text)  # uid=0(root)

Step 5: Collect evidence

bash
mkdir -p evidence/
# Screenshot exploitation
# Save PCAP
tcpdump -i tap0 -w evidence/fw-001-exploit.pcap
# Save exploit script
cp exploit.py evidence/fw-001-exploit.py
Phase 3: Report Assembly

Step 1: Start with template

bash
cp assets/pentest_report_template.md final_report.md

Step 2: Fill metadata

markdown
**Client:** Acme Corporation
**Product:** IoT Gateway Pro
**Firmware Version:** v2.3.1
**Assessment Period:** January 1-15, 2024
**Report Date:** January 20, 2024
**Assessed By:** [Your Name]

Step 3: Add findings summary

markdown
**Critical Issues:** 2
**High Severity:** 3
**Medium Severity:** 5
**Low Severity:** 2
**Informational:** 1

| ID | Title | Severity | CVSS |
|----|-------|----------|------|
| FW-001 | Remote Command Injection | Critical | 9.8 |
| FW-002 | Authentication Bypass | Critical | 9.1 |
| FW-003 | Hardcoded Crypto Keys | High | 7.5 |

Step 4: Import individual findings

markdown
# Copy full finding details from FW-001-command-injection.md
# Paste into Findings section
# Repeat for each finding

Step 5: Add technical analysis

From your assessment notes:

markdown
### Architecture Analysis
- ARM Cortex-A9 (32-bit, little-endian)
- Entry Point: 0x00400000
- Base Address: 0x00400000

### Security Mitigations
| Mitigation | Status | Notes |
|------------|--------|-------|
| PIE | No | Example ET_EXEC executable |
| ASLR | Not tested | Verify runtime policy and mappings |
| Stack Canaries | Enabled | Present in httpd |
| NX Stack | Enabled | Non-executable stack |

### Network Services
- Port 23/tcp: Telnet (CRITICAL - enabled by default)
- Port 80/tcp: HTTP (Multiple vulnerabilities)
- Port 443/tcp: HTTPS (Self-signed certificate)

Step 6: Create remediation roadmap

markdown
### Phase 1: Critical Issues (0-30 days)
1. Disable telnet service
2. Patch command injection (FW-001, FW-004)
3. Fix authentication bypass (FW-002)
4. Remove default credentials

### Phase 2: High Severity (30-60 days)
1. Replace hardcoded keys
2. Implement input validation framework
3. Build supported executables as PIE and verify runtime ASLR

Step 7: Review and polish

  • Verify all placeholders filled
  • Check CVSS calculations
  • Ensure evidence files referenced
  • Proofread technical content
Phase 4: PDF Generation

Option 1: Use a separately installed PDF skill, if available

bash
# Read pdf skill for conversion
# Convert markdown to professional PDF

Option 2: Use Pandoc with XeLaTeX installed

Choose fonts that cover the report characters, replace unsupported symbols and review the rendered pages for clipping and missing glyphs before delivery.

bash
pandoc final_report.md -o final_report.pdf \
  --pdf-engine=xelatex \
  --toc \
  --number-sections \
  -V geometry:margin=1in \
  --highlight-style=tango

Integration with Firmware Analysis Skills

From firmware-extraction
markdown
## Filesystem Analysis

**Root Filesystem:** SquashFS (extracted at offset 0x40000)
**Filesystems Found:**
- 0x0 - TRX header
- 0x1C - LZMA compressed kernel
- 0x40000 - SquashFS root filesystem
- 0x2C0000 - JFFS2 configuration partition

**Extraction Method:** binwalk -e firmware.bin
**Total Files Extracted:** 1,247
From firmware-static-analysis
markdown
## Binary Security Analysis

**Binaries Analyzed:** 15 (in /usr/sbin/)

**Key Findings:**
- /usr/sbin/httpd: No PIE, stack canaries present
- /usr/sbin/telnetd: No security mitigations
- /usr/lib/libcrypto.so: AES implementation uses OpenSSL 1.0.2k

**Architecture:** ARM 32-bit, little-endian
**Calling Convention:** ARM EABI
From ghidra-re
markdown
## Reverse Engineering Findings

**Authentication Function Analysis:**

Function: `check_password` at 0x00401234
- Uses strcmp(); assess whether a remotely measurable secret-dependent timing difference exists
- Rate limiting and empty-password acceptance require separate verification; the snippet alone does not establish them

Decompiled code:
```c
int check_password(char *username, char *password) {
    char stored_hash[32];
    load_user_hash(username, stored_hash);
    
    if (strcmp(password_hash(password), stored_hash) == 0) {
        return AUTH_SUCCESS;
    }
    return AUTH_FAIL;
}
```

**Cryptographic Analysis:**
- AES S-box found at 0x0040A000
- MD5 constants in auth_daemon
- Hardcoded key: `0x0123456789ABCDEF0123456789ABCDEF`
From firmware-emulation
markdown
## Dynamic Analysis Results

**Emulation Environment:**
- QEMU system-mode (ARM versatilepb)
- Kernel: Extracted from firmware (Linux 4.9.118)
- Network: TAP interface (192.168.100.1/24)

**Runtime Behavior:**
- Firmware boots successfully in 45 seconds
- All services start automatically
- Debug logging enabled (sensitive data in logs)

**Network Traffic Analysis:**
```
tcpdump capture: evidence/network_traffic.pcap
Key findings:
- Cleartext credentials in HTTP POST
- No TLS for admin interface
- API keys in HTTP headers: X-API-Key: 0x123456...
```

**Exploitation:**
```bash
# Successful RCE via command injection
$ curl -X POST http://192.168.100.2/cgi-bin/admin.cgi \
  -d "cmd=;id"

Response: uid=0(root) gid=0(root)
```

Best Practices

Show full SKILL.md (277 more words)Show less
Writing Technical Findings

DO: Use precise technical language Include addresses, file paths, line numbers Provide working proof-of-concept code Show before/after code for remediation Calculate accurate CVSS scores Include evidence (screenshots, PCAPs) Explain impact clearly

DON'T: Use vague descriptions ("security issue found") Over-hype severity without justification Provide theoretical exploits without validation Skip remediation guidance Forget to include CWE/OWASP references

CVSS Scoring

Always justify your scores. Use references/cvss-scoring.md for guidance.

Example:

markdown
**CVSS v3.1 Score:** 9.8 (Critical)
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Justification:**
- AV:N - Exploitable remotely over network
- AC:L - No special conditions required, reliable exploitation
- PR:N - No authentication required
- UI:N - No user interaction needed
- S:U - Impact contained to vulnerable component
- C:H - Full file system access as root
- I:H - Complete system modification possible
- A:H - Can crash or brick device
Evidence Organization
project/
├── final_report.md
├── findings/
│   ├── FW-001-command-injection.md
│   ├── FW-002-auth-bypass.md
│   └── FW-003-hardcoded-keys.md
├── evidence/
│   ├── screenshots/
│   │   ├── fw-001-ghidra-analysis.png
│   │   ├── fw-001-exploitation.png
│   │   └── fw-002-admin-access.png
│   ├── pcaps/
│   │   ├── fw-001-exploit.pcap
│   │   └── full-session.pcap
│   ├── exploits/
│   │   ├── fw-001-exploit.py
│   │   └── fw-002-bypass.py
│   └── binaries/
│       ├── httpd
│       └── auth_daemon
└── working_notes.md
Report Quality Checklist

Before delivery:

  • All placeholders filled in
  • CVSS scores calculated correctly
  • Evidence files referenced and included
  • PoC code tested and working
  • Remediation guidance is actionable
  • Technical details are accurate
  • Grammar and spelling checked
  • Sensitive client data redacted (if sharing publicly)
  • PDF generated and reviewed
  • Executive summary tells coherent story

Common Report Sections

Executive Summary

Purpose: High-level overview for decision-makers

Template:

markdown
This assessment of [PRODUCT] version [VERSION] identified [COUNT] security
vulnerabilities, including [COUNT] critical issues that allow remote attackers
to [PRIMARY_IMPACT].

The most severe finding is [FW-ID]: [TITLE], which enables [ATTACK_SCENARIO].
Immediate remediation is recommended for all critical findings.

Key recommendations:
1. [ACTION_1] - Addresses FW-001, FW-002
2. [ACTION_2] - Addresses FW-003, FW-004
3. [ACTION_3] - Improves overall security posture
Methodology

Purpose: Establish credibility, explain approach

Template:

markdown
The assessment followed a structured methodology:

1. **Firmware Acquisition** - [How firmware was obtained]
2. **Extraction** - Tools: binwalk, jefferson, sasquatch
3. **Static Analysis** - Binary analysis, configuration review
4. **Reverse Engineering** - Ghidra-based deep analysis
5. **Dynamic Analysis** - QEMU emulation, runtime testing
6. **Exploitation** - PoC development and validation
7. **Documentation** - Report generation and evidence collection

Time invested: [HOURS] over [DAYS] days
Risk Summary

Purpose: Quantify overall risk

Template:

markdown
### Risk Distribution

[Chart showing Critical/High/Medium/Low distribution]

**Critical Risks (9.0-10.0):** 2 findings
- Enable remote code execution without authentication
- Full device compromise possible

**High Risks (7.0-8.9):** 3 findings
- Require authentication but lead to privilege escalation
- Sensitive data disclosure

**Overall Risk:** HIGH
The device is vulnerable to remote compromise. Immediate action required.

Templates Reference

All templates located in assets/ directory:

  1. pentest_report_template.md - Complete assessment report
  2. finding_template.md - Individual vulnerability documentation
  3. working_notes_template.md - Assessment tracking and notes

Additional reference:

  1. references/cvss-scoring.md - CVSS 3.1 calculation guide with examples

Quick Start

bash
# 1. During assessment - keep working notes
cp assets/working_notes_template.md working_notes.md
# Update daily with findings

# 2. For each vulnerability - create finding
cp assets/finding_template.md findings/FW-001-vuln-name.md
# Fill in technical details, PoC, remediation

# 3. At end - assemble full report
cp assets/pentest_report_template.md final_report.md
# Import findings, add analysis, create roadmap

# 4. Generate PDF (use pdf skill or pandoc)
# pandoc final_report.md -o final_report.pdf --pdf-engine=xelatex

Integration Example

Complete workflow from analysis to report:

bash
# Day 1-3: Analysis
binwalk -e firmware.bin
readelf -h binary
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /proj Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary -postScript find_crypto.py
qemu-arm -g 1234 -L ./rootfs/ ./binary

# Day 3-5: Documentation
cp assets/finding_template.md findings/FW-001-cmdinj.md
# Fill in details from Ghidra/QEMU analysis

# Day 5-7: Report Writing
cp assets/pentest_report_template.md acme_iot_gateway_report.md
# Compile all findings into main report

# Day 7: Delivery
pandoc acme_iot_gateway_report.md -o acme_iot_gateway_report.pdf --pdf-engine=xelatex
# Send to client

Professional Standards

Reports should distinguish verified findings, unverified candidates, test limitations and informational observations. This repository does not claim endorsement or certification by a security consultancy. Use the agreed assessment methodology and the applicable FIRST CVSS specification.

Key principles:

  1. Accuracy - Support claims with reproducible evidence; state what a PoC actually demonstrates
  2. Reproducibility - Clear exploitation steps
  3. Actionability - Specific remediation guidance
  4. Evidence - Screenshots, PCAPs, code samples
  5. Professionalism - Technical depth without fluff

Review all generated reports against the engagement scope and evidence before delivery.

© OrbitCurve, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references, assets) in plugins/firmware-reverse-engineering/skills/firmware-security-reports of OrbitCurve/firmware-reverse-engineering.

  • SKILL.md
  • assets/finding_template.md
  • assets/pentest_report_template.md
  • assets/working_notes_template.md
  • references/cvss-scoring.md

Open the folder on GitHubat commit a047a60

Compare with similar skills

Firmware Security Reports next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Firmware Security Reports compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Firmware Security Reports this skillOrbitCurve/firmware-reverse-engineering214—~4.1kAutomated safety check: PassApache-2.0
Analyzing Packed Malware With Upx Unpackermukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Analyzing Linux Elf Malwaremukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: WarnApache-2.0
Binary Reaiskillstore/marketplace4301 repos~2.6kAutomated safety check: PassNone
Bench ExperimentDavidClawson/OpenScope-2C53T116—~1kAutomated safety check: PassGPL-3.0
Go Rust Reversezhaoxuya520/reverse-skill40k2 repos~339Automated safety check: PassMIT

Similar skills

  • Analyzing Packed Malware With Upx Unpacker

    mukul975/Anthropic-Cybersecurity-Skills

    Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Linux Elf Malware

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Binary Re

    aiskillstore/marketplace

    This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

    430 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Bench Experiment

    DavidClawson/OpenScope-2C53T

    Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.

    116 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    40k GitHub starsUsed in 2 repos~339 tokens
    SecurityAuto-check passed
  • A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…

    157 GitHub stars~7.5k tokensUpdated 13 days ago
    SecurityAuto-check passed

More from OrbitCurve/firmware-reverse-engineering

  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    214 GitHub stars~4.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Firmware Static Analysis

    OrbitCurve/firmware-reverse-engineering

    Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd).

    214 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Firmware Security Reports

What does Firmware Security Reports do?

Evidence-based security report generation for firmware assessments. Firmware Security Reports is an agent skill from OrbitCurve/firmware-reverse-engineering. Evidence-based security report generation for firmware assessments.

When should I use Firmware Security Reports?

Firmware Security Reports fits situations like: the agent needs to create technical security reports from firmware analysis; tasks that involve Reverse engineering and malware; tasks that involve Summarization.

How do I install Firmware Security Reports in Claude Code?

Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a claude-code`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/firmware-security-reports in OrbitCurve/firmware-reverse-engineering) into .claude/skills/firmware-security-reports in your project. Claude Code loads it when a task matches its description.

How do I install Firmware Security Reports in Codex?

Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a codex`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/firmware-security-reports in OrbitCurve/firmware-reverse-engineering) into .agents/skills/firmware-security-reports in your project. Codex loads it when a task matches its description.

Can I use Firmware Security Reports in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OrbitCurve/firmware-reverse-engineering --skill firmware-security-reports -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firmware-security-reports, .gemini/skills/firmware-security-reports, .github/skills/firmware-security-reports and .opencode/skills/firmware-security-reports in your project.

What does Firmware Security Reports need to run?

Going by SKILL.md and its folder, Firmware Security Reports needs the command-line tools its instructions call (pandoc and curl). Our summary lists: Python 3.

Does Firmware Security Reports access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Firmware Security Reports safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Firmware Security Reports use?

Firmware Security Reports is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Firmware Security Reports use?

About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Firmware Security Reports?

Skills that share tags, products or a category with Firmware Security Reports: Analyzing Packed Malware With Upx Unpacker (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Linux Elf Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Binary Re (aiskillstore/marketplace, 430 stars) and Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Firmware Security Reports?

OrbitCurve (a GitHub organization) maintains it in OrbitCurve/firmware-reverse-engineering, which has 214 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 7, 2026.

Source: OrbitCurve/firmware-reverse-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.