Binary Re
aiskillstore/marketplace
This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .claude/skills/ghidra-re && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .claude/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-reType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .agents/skills/ghidra-re && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .agents/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .cursor/skills/ghidra-re && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .cursor/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OrbitCurve/firmware-reverse-engineering.git --path plugins/firmware-reverse-engineering/skills/ghidra-re--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .gemini/skills/ghidra-re && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .gemini/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-reInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .github/skills/ghidra-re && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .github/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OrbitCurve/firmware-reverse-engineering ghidra-re --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OrbitCurve/firmware-reverse-engineering.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/firmware-reverse-engineering/skills/ghidra-re .opencode/skills/ghidra-re && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ghidra-re" agent skill from https://github.com/OrbitCurve/firmware-reverse-engineering/tree/main/plugins/firmware-reverse-engineering/skills/ghidra-re into .opencode/skills/ghidra-re/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ghidra-re", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ghidra-reExpert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
Ghidra Re is an agent skill from OrbitCurve/firmware-reverse-engineering. Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic detection, and vulnerability hunting. Use when the agent needs to perform deep static analysis of firmware binaries in Ghidra. Covers: (1) Stripped binary analysis techniques (function discovery via prologues, xrefs, string tracing), (2) Type recovery and structure reconstruction, (3) Automated analysis via Python…
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/stripped-analysis.md`, `references/workflow.md` and `scripts/auto_rename.py`).
It sits in Security, covering Reverse engineering and malware. It works with Ghidra and Python. The repository describes itself as: A full claude and codex skillsets for firmware reverse engineering. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a047a60. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ghidra Re loads about 4.2k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 251 tokens; SKILL.md has 772 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from OrbitCurve/firmware-reverse-engineering at commit a047a60, republished under its Apache-2.0 licence (© OrbitCurve). 772 words, ~4,196 tokens.
.claude/skills/ghidra-re/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Expert-level Ghidra workflows for analyzing stripped firmware binaries, with automation via Python scripting.
Use this skill for:
Prerequisites:
# @runtime Jython; they do not run in a standalone Python interpreter.Integration:
The four bundled scripts produce review candidates, not confirmed vulnerabilities. They inspect recovered instructions and resolved references; indirect calls, inlined code and unrecovered data may be missed. They preserve existing names and comments; candidate renames apply only to default symbols. Save the project before running analysis scripts.
Set these paths for the headless examples (replace with absolute local paths):
export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1.3_PUBLIC
export GHIDRA_SCRIPT_DIR=/path/to/ghidra-re/scripts
mkdir -p /projects# Create project
"$GHIDRA_INSTALL_DIR/ghidraRun"
# Or headless for automation
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects FirmwareProject -scriptPath "$GHIDRA_SCRIPT_DIR" -import /path/to/binary.elf
# Batch import
for bin in extracted/bin/*; do
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import "$bin"
doneAutomated approach:
# Run analysis scripts in sequence
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary.elf \
-postScript find_crypto.py \
-postScript find_auth_functions.py \
-postScript find_buffer_overflows.pyManual approach:
Run Auto-Analysis (Analysis → Auto Analyze)
Find Functions - Stripped binaries need manual function discovery
references/stripped-analysis.md)Initial Renaming
scripts/auto_rename.py for heuristic-based namingChoose analysis path based on goal:
Authentication Analysis → Use scripts/find_auth_functions.py
Crypto Analysis → Use scripts/find_crypto.py
Vulnerability Hunting → Use scripts/find_buffer_overflows.py
Network Protocol Analysis
For each interesting function:
# @runtime Jython
# Decompile and enhance
func = getFunctionAt(toAddr("0x00401000"))
# Set signature (if known)
sig = "int verify_password(char *user_input, char *stored_hash)"
from ghidra.app.cmd.function import ApplyFunctionSignatureCmd
from ghidra.app.util.parser import FunctionSignatureParser
from ghidra.program.model.symbol import SourceType
from ghidra.program.model.listing import Function, ParameterImpl
from ghidra.program.model.data import *
assert func is not None, "Select a valid function entry"
definition = FunctionSignatureParser(currentProgram.getDataTypeManager(), None).parse(func.getSignature(), sig)
assert ApplyFunctionSignatureCmd(func.getEntryPoint(), definition, SourceType.USER_DEFINED).applyTo(currentProgram)
# Define structures
dtm = currentProgram.getDataTypeManager()
struct = StructureDataType("auth_request", 0)
struct.add(DWordDataType(), "session_id", None)
struct.add(PointerDataType(CharDataType()), "username", None)
struct.add(PointerDataType(CharDataType()), "password", None)
dtm.addDataType(struct, DataTypeConflictHandler.REPLACE_HANDLER)
# Apply to function parameters
param = ParameterImpl("request", PointerDataType(struct), currentProgram)
func.replaceParameters(Function.FunctionUpdateType.DYNAMIC_STORAGE_ALL_PARAMS, True, SourceType.USER_DEFINED, param)Buffer Overflow Detection:
# @runtime Jython
# Manual verification after script identifies candidates
# 1. Check buffer size
# 2. Trace input length
# 3. Verify bounds checking (or lack thereof)
# 4. Confirm exploitability
# Example: strcpy without length check
# Decompiler shows:
# strcpy(local_buffer, user_input);
# Check local_buffer size in stack frame
# Verify attacker-controlled length exceeds the destination and reaches this call.
# A write beyond the buffer is a vulnerability; code execution needs separate evidence.Format String Bugs:
# @runtime Jython
# Find printf(user_controlled_string)
# Script pattern:
if "printf" in called_functions:
# Check if format arg is from user input
# A variable format is not necessarily attacker-controlled; trace its origin.
pass # Manual review, not a complete detectorCommand Injection:
# @runtime Jython
# Find system/popen with user data
# Pattern: system(cmd) where cmd contains user input
# Look for string concatenation before system() callAutomated structure inference:
# @runtime Jython
# See references/stripped-analysis.md for a sketch, not a complete inference engine
# Analyzes memory access patterns:
# - *(ptr + 0) → field at offset 0
# - *(ptr + 4) → field at offset 4
# Define the structure manually after verifying offsets and field sizesManual structure definition:
# @runtime Jython
# From decompiler output showing member accesses
struct = StructureDataType("device_state", 0)
struct.add(DWordDataType(), "magic", None) # offset 0
struct.add(ByteDataType(), "enabled", None) # offset 4
struct.add(ArrayDataType(CharDataType(), 32, 1), "name", None) # offset 5
# Apply and watch decompiler improveFind callers:
Right-click function → References → Show References toFind call sites:
# @runtime Jython
func = getFunctionAt(currentAddress)
refs = getReferencesTo(func.getEntryPoint())
for ref in refs:
if ref.getReferenceType().isCall():
caller = getFunctionContaining(ref.getFromAddress())
if caller:
print("Called from: {}".format(caller.getName()))Trace data flow:
# @runtime Jython
# From source to sink
# 1. Find all calls to source (e.g., recv)
# 2. Track where data goes
# 3. Check if reaches sink (e.g., system)
# See scripts/find_buffer_overflows.py for manual data-flow verificationAll scripts in scripts/ run in Ghidra with the Jython runtime above:
Finds candidate constant prefixes and their direct references; absence is not evidence that crypto is absent:
Usage:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_crypto.pyDiscovers authentication logic via heuristics:
Usage:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_auth_functions.pyDetects potential buffer overflow vulnerabilities:
Usage:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Project -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary -postScript find_buffer_overflows.py# @runtime Jython
# my_analysis.py
# Description: Custom analysis for firmware
from ghidra.program.model.symbol import SourceType
currentProgram = getCurrentProgram()
listing = currentProgram.getListing()
fm = currentProgram.getFunctionManager()
mem = currentProgram.getMemory()
# Your analysis logic
for func in fm.getFunctions(True):
# Process each function
pass# @runtime Jython
# Navigate
addr = toAddr("0x00400000")
func = getFunctionAt(addr)
func = getFunctionContaining(addr)
# Modify
func.setName("new_name", SourceType.USER_DEFINED)
createFunction(addr, "function_name")
createLabel(addr, "label_name", True)
# Data types
from ghidra.program.model.data import *
DWordDataType()
PointerDataType(CharDataType())
StructureDataType("struct_name", 0)
# Instructions
instr = listing.getInstructionAt(addr)
instr.getMnemonicString() # "bl", "mov", etc.
instr.getReferencesFrom()
# Decompiler
from ghidra.app.decompiler import DecompInterface
decompiler = DecompInterface()
decompiler.openProgram(currentProgram)
results = decompiler.decompileFunction(func, 30, monitor)
high_func = results.getHighFunction()Method 1: Prologue Scanning
# @runtime Jython
# ARM: push {r11, lr} = 0xe92d4800
# MIPS: addiu sp,sp,-XX
# x86: push ebp; mov ebp,esp
# Search for patterns in executable memory
# See references/stripped-analysis.md for complete implementationMethod 2: Cross-Reference Analysis
# @runtime Jython
# Find all call instructions
# Target addresses likely are function starts
# See references/stripped-analysis.mdMethod 3: String References
# @runtime Jython
# Functions that reference strings
# Use string content to infer function purpose
# See references/stripped-analysis.md# @runtime Jython
# Pattern-based naming
def infer_name(func):
strings = get_function_strings(func)
called = get_called_functions(func)
# Authentication
if any("password" in s.lower() for s in strings):
if "strcmp" in called:
return "check_password"
# Network
if "socket" in called or "recv" in called:
return "network_handler"
# Crypto
if "aes" in "".join(strings).lower():
return "crypto_aes"
return NoneWorkflow:
Example:
# @runtime Jython
# In Ghidra: Find auth function
auth_func = getFunctionAt(toAddr("0x00401234"))
# Note address: 0x00401234. For PIE/shared objects, translate using the actual
# runtime load bias; do not use a static address unchanged.
# In QEMU with GDB:
# gdb-multiarch binary
# (gdb) target remote :1234
# (gdb) break *0x00401234
# (gdb) continue
# ... trigger auth ...
# (gdb) info registers # See actual values
# Return to Ghidra with understanding of runtime behaviorG Go to address
L Label/rename
; EOL comment
Ctrl-; Pre-comment
D Disassemble
P Create function
X Show references to
Ctrl-Shift-E Edit function signature
T Set data typeDecompiler fails:
Auto-analysis misses functions:
scripts/ folderreferences/stripped-analysis.md)Poor decompilation quality:
references/stripped-analysis.md - Complete techniques for analyzing stripped binaries, type recovery, function discoveryreferences/workflow.md - Expert workflow patterns, scripting examples, integration tips# Headless analysis with scripts
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary.elf \
-postScript find_crypto.py -postScript find_auth_functions.py
# Import without auto-analysis (manual control)
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -import binary.elf -noanalysis
# Export analysis results (first save the JSON example in references/workflow.md
# as export_results.py in GHIDRA_SCRIPT_DIR; it is not a bundled script)
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /projects Firmware -scriptPath "$GHIDRA_SCRIPT_DIR" -process binary.elf \
-postScript export_results.py# @runtime Jython
# Essential Ghidra Python APIs
currentProgram # Program object
getFunctionAt(addr) # Get function
createFunction(addr, name) # Create function
toAddr("0x00400000") # String to address
listing.getInstructions(body, True) # Iterate instructions
getReferencesTo(addr) # Get xrefs to
func.setName(name, SourceType.USER_DEFINED) # Rename functionThis skill assumes expert RE knowledge and focuses on firmware-specific analysis patterns. For general Ghidra basics, consult official documentation.
© OrbitCurve, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in plugins/firmware-reverse-engineering/skills/ghidra-re of OrbitCurve/firmware-reverse-engineering.
Open the folder on GitHubat commit a047a60
Ghidra Re next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ghidra Re this skillOrbitCurve/firmware-reverse-engineering | 216 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Binary Reaiskillstore/marketplace | 433 | 1 repos | ~2.6k | Automated safety check: Pass | None | |
| TH08 Exact Function MatchingN0zoM1z0/th08 | 105 | — | ~8.7k | Automated safety check: Pass | MIT | |
| Rea Tool Designmorluto/rea | 80k | — | ~239 | Automated safety check: Pass | MIT | |
| Combine DbcCSS-Electronics/can-bus-reverse-engineering-skills | 185 | — | ~826 | Automated safety check: Pass | MIT | |
| Nuitka Nbc RebuilderDimaReverse/nuitka-static-unpacker | 132 | — | ~2k | Automated safety check: Pass | MIT |
aiskillstore/marketplace
This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.
N0zoM1z0/th08
Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches.
morluto/rea
Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.
CSS-Electronics/can-bus-reverse-engineering-skills
Combine multiple individual single-signal DBC files into one combined DBC at the application level.
DimaReverse/nuitka-static-unpacker
Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py.
ptn1411/skill
Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.
OrbitCurve/firmware-reverse-engineering
Evidence-based security report generation for firmware assessments.
OrbitCurve/firmware-reverse-engineering
Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd).
Categories
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…. Ghidra Re is an agent skill from OrbitCurve/firmware-reverse-engineering. Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic detection, and vulnerability hunting.
Ghidra Re fits situations like: the agent needs to perform deep static analysis of firmware binaries in Ghidra; tasks that involve Reverse engineering and malware.
Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a claude-code`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/ghidra-re in OrbitCurve/firmware-reverse-engineering) into .claude/skills/ghidra-re in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a codex`. Or copy the skill folder (plugins/firmware-reverse-engineering/skills/ghidra-re in OrbitCurve/firmware-reverse-engineering) into .agents/skills/ghidra-re in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OrbitCurve/firmware-reverse-engineering --skill ghidra-re -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ghidra-re, .gemini/skills/ghidra-re, .github/skills/ghidra-re and .opencode/skills/ghidra-re in your project.
Going by SKILL.md and its folder, Ghidra Re needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Ghidra Re is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ghidra Re: Binary Re (aiskillstore/marketplace, 433 stars), TH08 Exact Function Matching (N0zoM1z0/th08, 105 stars), Rea Tool Design (morluto/rea, 80k stars) and Combine Dbc (CSS-Electronics/can-bus-reverse-engineering-skills, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OrbitCurve (a GitHub organization) maintains it in OrbitCurve/firmware-reverse-engineering, which has 216 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 7, 2026.
Source: OrbitCurve/firmware-reverse-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.