Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

Apache-2.0Auto-check passedSecurity

Install Ghidra Re

skills CLI
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .claude/skills/ghidra-re && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ghidra-re
GitHub stars
216
Token cost
~4.2k tokens
SKILL.md length
772 words
Files
7 (incl. scripts, references)
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

  • Works in 7 steps: Project Setup → Initial Analysis (Stripped Binary Focus) → Target-Specific Analysis → …
  • The agent needs to perform deep static analysis of firmware binaries in Ghidra
  • SKILL.md covers Skill Scope, Analysis Workflow, Provided Scripts and Scripting Patterns, plus 8 more sections
  • Runs Python scripts from its folder

What it does

Ghidra Re is an agent skill from OrbitCurve/firmware-reverse-engineering. Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic detection, and vulnerability hunting. Use when the agent needs to perform deep static analysis of firmware binaries in Ghidra. Covers: (1) Stripped binary analysis techniques (function discovery via prologues, xrefs, string tracing), (2) Type recovery and structure reconstruction, (3) Automated analysis via Python…

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/stripped-analysis.md`, `references/workflow.md` and `scripts/auto_rename.py`).

It sits in Security, covering Reverse engineering and malware. It works with Ghidra and Python. The repository describes itself as: A full claude and codex skillsets for firmware reverse engineering. The licence is Apache-2.0.

When your agent uses it

  • The agent needs to perform deep static analysis of firmware binaries in Ghidra
  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/ghidra-re”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Project Setup
  2. Initial Analysis (Stripped Binary Focus)
  3. Target-Specific Analysis
  4. Deep Function Analysis
  5. Vulnerability Analysis
  6. Type and Structure Recovery
  7. Cross-Referencing

What it can do on your machine

Read from SKILL.md and the folder at commit a047a60. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ghidra Re loads about 4.2k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 251 tokens; SKILL.md has 772 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~251
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from OrbitCurve/firmware-reverse-engineering at commit a047a60, republished under its Apache-2.0 licence (© OrbitCurve). 772 words, ~4,196 tokens.

Download SKILL.mdSave it as .claude/skills/ghidra-re/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
ghidra-re
description
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic detection, and vulnerability hunting. Use when the agent needs to perform deep static analysis of firmware binaries in Ghidra. Covers: (1) Stripped binary analysis techniques (function discovery via prologues, xrefs, string tracing), (2) Type recovery and structure reconstruction, (3) Automated analysis via Python scripting (Ghidra API), (4) Cryptographic function identification (AES, MD5, SHA constants), (5) Authentication and authorization function discovery, (6) Vulnerability detection (buffer overflows, format strings, command injection, manual data-flow verification), (7) Decompiler enhancement and custom type propagation, (8) Integration with emulation workflow. Assumes expert RE knowledge. Complements firmware-static-analysis (basic recon) and firmware-emulation (dynamic analysis).

Ghidra Reverse Engineering for Firmware

Expert-level Ghidra workflows for analyzing stripped firmware binaries, with automation via Python scripting.

Skill Scope

Use this skill for:

  • Deep analysis of individual firmware binaries in Ghidra
  • Stripped binary reverse engineering
  • Automated vulnerability hunting
  • Cryptographic routine identification
  • Authentication logic discovery
  • Custom script development

Prerequisites:

  • Ghidra 12.1.3 with its bundled Jython extension installed (File → Install Extensions → Jython, then restart). Scripts explicitly select # @runtime Jython; they do not run in a standalone Python interpreter.
  • JDK required by the installed Ghidra release (JDK 21 for 12.1.3)
  • Python scripting knowledge
  • Understanding of assembly (ARM/MIPS/x86)
  • Binary already extracted (use firmware-extraction skill)

Integration:

  • After: firmware-extraction, firmware-static-analysis (initial recon)
  • Before/During: firmware-emulation (validate findings dynamically)

The four bundled scripts produce review candidates, not confirmed vulnerabilities. They inspect recovered instructions and resolved references; indirect calls, inlined code and unrecovered data may be missed. They preserve existing names and comments; candidate renames apply only to default symbols. Save the project before running analysis scripts.

Set these paths for the headless examples (replace with absolute local paths):

bash
export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1.3_PUBLIC
export GHIDRA_SCRIPT_DIR=/path/to/ghidra-re/scripts
mkdir -p /projects

Analysis Workflow

1. Project Setup
bash
# Create project
"$GHIDRA_INSTALL_DIR/ghidraRun"

# Or headless for automation
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects FirmwareProject -scriptPath "$GHIDRA_SCRIPT_DIR" -import /path/to/binary.elf

# Batch import
for bin in extracted/bin/*; do
    "$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import "$bin"
done
2. Initial Analysis (Stripped Binary Focus)

Automated approach:

bash
# Run analysis scripts in sequence
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary.elf \
  -postScript find_crypto.py \
  -postScript find_auth_functions.py \
  -postScript find_buffer_overflows.py

Manual approach:

  1. Run Auto-Analysis (Analysis → Auto Analyze)

    • Enable: Aggressive Instruction Finder, Stack, Decompiler Parameter ID
  2. Find Functions - Stripped binaries need manual function discovery

    • Entry point: Find _start or main
    • Prologue scanning (see references/stripped-analysis.md)
    • Cross-reference analysis
    • String reference tracing
  3. Initial Renaming

    • Run scripts/auto_rename.py for heuristic-based naming
    • Manually rename critical functions
3. Target-Specific Analysis

Choose analysis path based on goal:

Authentication Analysis → Use scripts/find_auth_functions.py

  • Identifies strcmp, password string refs, multi-return patterns
  • Ranks by heuristic score (not a probability)
  • Adds candidate names to highly ranked default symbols

Crypto Analysis → Use scripts/find_crypto.py

  • Searches for AES S-boxes, MD5/SHA constants
  • Labels crypto tables
  • Finds functions referencing crypto constants

Vulnerability Hunting → Use scripts/find_buffer_overflows.py

  • Detects dangerous function calls (strcpy, sprintf, gets)
  • Flags source/sink co-occurrence within a function; does not trace taint
  • Lists large recovered stack objects in functions with risky API calls

Network Protocol Analysis

  • Find socket/recv/send calls
  • Trace data flow from network input
  • Identify protocol parsing functions
4. Deep Function Analysis

For each interesting function:

python
# @runtime Jython
# Decompile and enhance
func = getFunctionAt(toAddr("0x00401000"))

# Set signature (if known)
sig = "int verify_password(char *user_input, char *stored_hash)"
from ghidra.app.cmd.function import ApplyFunctionSignatureCmd
from ghidra.app.util.parser import FunctionSignatureParser
from ghidra.program.model.symbol import SourceType
from ghidra.program.model.listing import Function, ParameterImpl
from ghidra.program.model.data import *
assert func is not None, "Select a valid function entry"
definition = FunctionSignatureParser(currentProgram.getDataTypeManager(), None).parse(func.getSignature(), sig)
assert ApplyFunctionSignatureCmd(func.getEntryPoint(), definition, SourceType.USER_DEFINED).applyTo(currentProgram)

# Define structures
dtm = currentProgram.getDataTypeManager()
struct = StructureDataType("auth_request", 0)
struct.add(DWordDataType(), "session_id", None)
struct.add(PointerDataType(CharDataType()), "username", None)
struct.add(PointerDataType(CharDataType()), "password", None)
dtm.addDataType(struct, DataTypeConflictHandler.REPLACE_HANDLER)

# Apply to function parameters
param = ParameterImpl("request", PointerDataType(struct), currentProgram)
func.replaceParameters(Function.FunctionUpdateType.DYNAMIC_STORAGE_ALL_PARAMS, True, SourceType.USER_DEFINED, param)
5. Vulnerability Analysis

Buffer Overflow Detection:

python
# @runtime Jython
# Manual verification after script identifies candidates
# 1. Check buffer size
# 2. Trace input length
# 3. Verify bounds checking (or lack thereof)
# 4. Confirm exploitability

# Example: strcpy without length check
# Decompiler shows:
#   strcpy(local_buffer, user_input);
# Check local_buffer size in stack frame
# Verify attacker-controlled length exceeds the destination and reaches this call.
# A write beyond the buffer is a vulnerability; code execution needs separate evidence.

Format String Bugs:

python
# @runtime Jython
# Find printf(user_controlled_string)
# Script pattern:
if "printf" in called_functions:
    # Check if format arg is from user input
    # A variable format is not necessarily attacker-controlled; trace its origin.
    pass  # Manual review, not a complete detector

Command Injection:

python
# @runtime Jython
# Find system/popen with user data
# Pattern: system(cmd) where cmd contains user input
# Look for string concatenation before system() call
6. Type and Structure Recovery

Automated structure inference:

python
# @runtime Jython
# See references/stripped-analysis.md for a sketch, not a complete inference engine
# Analyzes memory access patterns:
# - *(ptr + 0) → field at offset 0
# - *(ptr + 4) → field at offset 4
# Define the structure manually after verifying offsets and field sizes

Manual structure definition:

python
# @runtime Jython
# From decompiler output showing member accesses
struct = StructureDataType("device_state", 0)
struct.add(DWordDataType(), "magic", None)          # offset 0
struct.add(ByteDataType(), "enabled", None)         # offset 4
struct.add(ArrayDataType(CharDataType(), 32, 1), "name", None)  # offset 5
# Apply and watch decompiler improve
7. Cross-Referencing

Find callers:

Right-click function → References → Show References to

Find call sites:

python
# @runtime Jython
func = getFunctionAt(currentAddress)
refs = getReferencesTo(func.getEntryPoint())
for ref in refs:
    if ref.getReferenceType().isCall():
        caller = getFunctionContaining(ref.getFromAddress())
        if caller:
            print("Called from: {}".format(caller.getName()))

Trace data flow:

python
# @runtime Jython
# From source to sink
# 1. Find all calls to source (e.g., recv)
# 2. Track where data goes
# 3. Check if reaches sink (e.g., system)
# See scripts/find_buffer_overflows.py for manual data-flow verification

Provided Scripts

All scripts in scripts/ run in Ghidra with the Jython runtime above:

find_crypto.py

Finds candidate constant prefixes and their direct references; absence is not evidence that crypto is absent:

  • First 16 bytes of the AES S-box
  • First four MD5 / SHA256 constants in either byte order
  • Auto-labels crypto tables
  • Finds functions referencing crypto data

Usage:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_crypto.py
find_auth_functions.py

Discovers authentication logic via heuristics:

  • String analysis (password, login, auth keywords)
  • API calls (strcmp, crypt, verify)
  • Multi-return patterns (success/fail branches)
  • Scores and ranks candidates

Usage:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_auth_functions.py
Show full SKILL.md (313 more words)Show less
find_buffer_overflows.py

Detects potential buffer overflow vulnerabilities:

  • Dangerous function calls (strcpy, sprintf, gets)
  • Source/sink co-occurrence (data flow unverified)
  • Stack buffer identification
  • Appends review notes at candidate locations without deleting analyst comments

Usage:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_buffer_overflows.py

Scripting Patterns

Template Script
python
# @runtime Jython
# my_analysis.py
# Description: Custom analysis for firmware

from ghidra.program.model.symbol import SourceType

currentProgram = getCurrentProgram()
listing = currentProgram.getListing()
fm = currentProgram.getFunctionManager()
mem = currentProgram.getMemory()

# Your analysis logic
for func in fm.getFunctions(True):
    # Process each function
    pass
Common Operations
python
# @runtime Jython
# Navigate
addr = toAddr("0x00400000")
func = getFunctionAt(addr)
func = getFunctionContaining(addr)

# Modify
func.setName("new_name", SourceType.USER_DEFINED)
createFunction(addr, "function_name")
createLabel(addr, "label_name", True)

# Data types
from ghidra.program.model.data import *
DWordDataType()
PointerDataType(CharDataType())
StructureDataType("struct_name", 0)

# Instructions
instr = listing.getInstructionAt(addr)
instr.getMnemonicString()  # "bl", "mov", etc.
instr.getReferencesFrom()

# Decompiler
from ghidra.app.decompiler import DecompInterface
decompiler = DecompInterface()
decompiler.openProgram(currentProgram)
results = decompiler.decompileFunction(func, 30, monitor)
high_func = results.getHighFunction()

Stripped Binary Techniques

Function Discovery

Method 1: Prologue Scanning

python
# @runtime Jython
# ARM: push {r11, lr} = 0xe92d4800
# MIPS: addiu sp,sp,-XX
# x86: push ebp; mov ebp,esp

# Search for patterns in executable memory
# See references/stripped-analysis.md for complete implementation

Method 2: Cross-Reference Analysis

python
# @runtime Jython
# Find all call instructions
# Target addresses likely are function starts
# See references/stripped-analysis.md

Method 3: String References

python
# @runtime Jython
# Functions that reference strings
# Use string content to infer function purpose
# See references/stripped-analysis.md
Automatic Renaming Heuristics
python
# @runtime Jython
# Pattern-based naming
def infer_name(func):
    strings = get_function_strings(func)
    called = get_called_functions(func)
    
    # Authentication
    if any("password" in s.lower() for s in strings):
        if "strcmp" in called:
            return "check_password"
    
    # Network
    if "socket" in called or "recv" in called:
        return "network_handler"
    
    # Crypto
    if "aes" in "".join(strings).lower():
        return "crypto_aes"
    
    return None

Integration with Emulation

Workflow:

  1. Static analysis in Ghidra (this skill)
  2. Identify interesting functions
  3. Set breakpoints in GDB at those addresses
  4. Run in QEMU (firmware-emulation skill)
  5. Observe behavior at breakpoints
  6. Return to Ghidra with insights

Example:

python
# @runtime Jython
# In Ghidra: Find auth function
auth_func = getFunctionAt(toAddr("0x00401234"))

# Note address: 0x00401234. For PIE/shared objects, translate using the actual
# runtime load bias; do not use a static address unchanged.

# In QEMU with GDB:
# gdb-multiarch binary
# (gdb) target remote :1234
# (gdb) break *0x00401234
# (gdb) continue
# ... trigger auth ...
# (gdb) info registers  # See actual values

# Return to Ghidra with understanding of runtime behavior

Best Practices

  1. Start Automated - Run scripts before manual analysis
  2. Name Incrementally - Don't try to name everything at once
  3. Trust Decompiler, Verify Assembly - Decompiler is good but not perfect
  4. Document Assumptions - Use comments liberally
  5. Version Control - Use a shared Ghidra Server project for program versioning; use Git for exported scripts and notes
  6. Cross-Reference Constantly - Understand call graphs
  7. Type Everything - Proper types improve decompilation dramatically
  8. Script Repetitive Tasks - Don't do the same thing 100 times manually

Keyboard Shortcuts

G                Go to address
L                Label/rename
;                EOL comment
Ctrl-;           Pre-comment
D                Disassemble
P                Create function
X                Show references to
Ctrl-Shift-E     Edit function signature
T                Set data type

Troubleshooting

Decompiler fails:

  • Check for unimplemented instructions
  • Simplify function (may be too complex)
  • Try different decompiler options

Auto-analysis misses functions:

  • Use scripts from scripts/ folder
  • Manual prologue search (see references/stripped-analysis.md)

Poor decompilation quality:

  • Set proper function signatures
  • Define structures for complex data types
  • Add type information to variables

References

  • Stripped Analysis: references/stripped-analysis.md - Complete techniques for analyzing stripped binaries, type recovery, function discovery
  • Workflow: references/workflow.md - Expert workflow patterns, scripting examples, integration tips

Quick Command Reference

bash
# Headless analysis with scripts
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary.elf \
  -postScript find_crypto.py -postScript find_auth_functions.py

# Import without auto-analysis (manual control)
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary.elf -noanalysis

# Export analysis results (first save the JSON example in references/workflow.md
# as export_results.py in GHIDRA_SCRIPT_DIR; it is not a bundled script)
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary.elf \
  -postScript export_results.py
python
# @runtime Jython
# Essential Ghidra Python APIs
currentProgram                              # Program object
getFunctionAt(addr)                         # Get function
createFunction(addr, name)                  # Create function
toAddr("0x00400000")                        # String to address
listing.getInstructions(body, True)         # Iterate instructions
getReferencesTo(addr)                       # Get xrefs to
func.setName(name, SourceType.USER_DEFINED) # Rename function

Next Steps After Ghidra Analysis

  1. Document findings - Create analysis report with key functions, vulnerabilities
  2. Test hypotheses - Use firmware-emulation to verify static findings
  3. Develop exploits - If vulnerabilities found, create PoCs
  4. Report - Prepare comprehensive security assessment

This skill assumes expert RE knowledge and focuses on firmware-specific analysis patterns. For general Ghidra basics, consult official documentation.

© OrbitCurve, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in plugins/firmware-reverse-engineering/skills/ghidra-re of OrbitCurve/firmware-reverse-engineering.

  • SKILL.md
  • references/stripped-analysis.md
  • references/workflow.md
  • scripts/auto_rename.py
  • scripts/find_auth_functions.py
  • scripts/find_buffer_overflows.py
  • scripts/find_crypto.py

Open the folder on GitHubat commit a047a60

Compare with similar skills

Ghidra Re next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ghidra Re compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ghidra Re this skillOrbitCurve/firmware-reverse-engineering216—~4.2kAutomated safety check: PassApache-2.0
Binary Reaiskillstore/marketplace4331 repos~2.6kAutomated safety check: PassNone
TH08 Exact Function MatchingN0zoM1z0/th08105—~8.7kAutomated safety check: PassMIT
Rea Tool Designmorluto/rea80k—~239Automated safety check: PassMIT
Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills185—~826Automated safety check: PassMIT
Nuitka Nbc RebuilderDimaReverse/nuitka-static-unpacker132—~2kAutomated safety check: PassMIT

Similar skills

  • Binary Re

    aiskillstore/marketplace

    This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

    433 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches.

    105 GitHub stars~8.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Rea Tool Design

    morluto/rea

    Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.

    80k GitHub stars~239 tokensUpdated today
    SecurityAuto-check passed
  • Combine Dbc

    CSS-Electronics/can-bus-reverse-engineering-skills

    Combine multiple individual single-signal DBC files into one combined DBC at the application level.

    185 GitHub stars~826 tokensUpdated today
    SecurityAuto-check passed
  • Nuitka Nbc Rebuilder

    DimaReverse/nuitka-static-unpacker

    Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.

    132 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 19 days ago
    SecurityAuto-check: notes

More from OrbitCurve/firmware-reverse-engineering

  • Firmware Security Reports

    OrbitCurve/firmware-reverse-engineering

    Evidence-based security report generation for firmware assessments.

    216 GitHub stars~4.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Firmware Static Analysis

    OrbitCurve/firmware-reverse-engineering

    Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd).

    216 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Ghidra Re

What does Ghidra Re do?

Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…. Ghidra Re is an agent skill from OrbitCurve/firmware-reverse-engineering. Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic detection, and vulnerability hunting.

When should I use Ghidra Re?

Ghidra Re fits situations like: the agent needs to perform deep static analysis of firmware binaries in Ghidra; tasks that involve Reverse engineering and malware.

How do I install Ghidra Re in Claude Code?

Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a claude-code`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/ghidra-re in OrbitCurve/firmware-reverse-engineering) into .claude/skills/ghidra-re in your project. Claude Code loads it when a task matches its description.

How do I install Ghidra Re in Codex?

Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a codex`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/ghidra-re in OrbitCurve/firmware-reverse-engineering) into .agents/skills/ghidra-re in your project. Codex loads it when a task matches its description.

Can I use Ghidra Re in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ghidra-re, .gemini/skills/ghidra-re, .github/skills/ghidra-re and .opencode/skills/ghidra-re in your project.

What does Ghidra Re need to run?

Going by SKILL.md and its folder, Ghidra Re needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Ghidra Re access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ghidra Re safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ghidra Re use?

Ghidra Re is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ghidra Re use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Ghidra Re?

Skills that share tags, products or a category with Ghidra Re: Binary Re (aiskillstore/marketplace, 433 stars), TH08 Exact Function Matching (N0zoM1z0/th08, 105 stars), Rea Tool Design (morluto/rea, 80k stars) and Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ghidra Re?

OrbitCurve (a GitHub organization) maintains it in OrbitCurve/firmware-reverse-engineering, which has 216 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 7, 2026.

Source: OrbitCurve/firmware-reverse-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.