Agent skill

Binary Diff

by sickn33 in sickn33/agentic-awesome-skills

Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.

MITAuto-check passed

Install Binary Diff

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill binary-diff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills binary-diff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/binary-diff .claude/skills/binary-diff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
binary-diff
GitHub stars
47k
Used in
1 other repo
Token cost
~2.1k tokens
SKILL.md length
391 words
Files
2 (incl. references)
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.

  • Works in 4 steps: 内核/驱动缺 PDB — 有旧版 ntoskrnl.exe 的符号,新版 PDB… → 程序更新后符号迁移 —… → 保护机制更新 — 旧版有完整逆向结果,新版需要快速定位同一函数的新偏移 → …
  • SKILL.md covers When to Use, 适用范围, 核心原理 and Prompt 模板, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Binary Diff is an agent skill from sickn33/agentic-awesome-skills. Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/prompt-template.md`).

The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

Example prompts

  • “/binary-diff”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 内核/驱动缺 PDB — 有旧版 ntoskrnl.exe 的符号,新版 PDB 被微软下架,需要用旧版符号推导新版非导出函数地址
  2. 程序更新后符号迁移 — 曾经逆向过某个程序,程序更新了,不想重新逆一遍,用旧版结果批量迁移
  3. 保护机制更新 — 旧版有完整逆向结果,新版需要快速定位同一函数的新偏移
  4. 任何"有旧版符号 + 新版无符号"的二进制对比场景

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are c and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Binary Diff loads about 2.1k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 47 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 391 words, ~2,083 tokens.

Download SKILL.mdSave it as .claude/skills/binary-diff/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
binary-diff
description
Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.
risk
safe
source
https://github.com/zhaoxuya520/reverse-skill
source_repo
zhaoxuya520/reverse-skill
source_type
community
date_added
2026-08-25
license
MIT
license_source
https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE

跨版本符号迁移 (Binary Diff)

When to Use

  • A program updated and old annotations/symbols must be migrated to the new build.
  • Recovering changed functions between two versions of a stripped binary.

适用范围

当任务属于以下场景时使用本 skill:

  1. 内核/驱动缺 PDB — 有旧版 ntoskrnl.exe 的符号,新版 PDB 被微软下架,需要用旧版符号推导新版非导出函数地址
  2. 程序更新后符号迁移 — 曾经逆向过某个程序,程序更新了,不想重新逆一遍,用旧版结果批量迁移
  3. 保护机制更新 — 旧版有完整逆向结果,新版需要快速定位同一函数的新偏移
  4. 任何"有旧版符号 + 新版无符号"的二进制对比场景
与其他 skill 的分工
场景用什么
从零开始逆向一个二进制ida-reverse/ 或 radare2/
有旧版结果,迁移到新版本 skill
两个完全不同的二进制对比BinDiff / Diaphora(传统工具)
核心优势

相比传统方案:

方案200 个函数成本时间准确率
人工开两个 IDA 窗口对比免费但耗命数小时高
BinDiff 自动匹配免费快中(结构变化大时失效)
完全交给 Agent(CC/Codex)50-100 元慢高
本 skill(LLM 批量比对)~1 元~10 秒/函数高

核心原理

text
旧版函数(有符号)          新版同一函数(无符号)
    ↓                              ↓
导出反汇编 + 伪代码          导出反汇编 + 伪代码
    ↓                              ↓
    └──────── LLM 结构化比对 ────────┘
                    ↓
         输出 YAML(符号映射表)
                    ↓
         程序化解析 → 批量应用到新版 IDB

关键点:

  • prompt 是固定模板,程序化填充
  • 输入输出格式确定,程序化解析
  • LLM 只负责"看两段代码,找出对应关系"这一步
  • 时间成本和 token 成本极低

Prompt 模板

标准比对 Prompt
text
I have disassembly outputs and procedure code of the same function.

This is the function for reference:

**Disassembly for Reference**
```c
{disasm_for_reference}

Procedure code for Reference

c
{procedure_for_reference}

This is the function you need to reverse-engineering:

Disassembly to reverse-engineering

c
{disasm_code}

Procedure code to reverse-engineering

c
{procedure}

What you need to do is to collect all references to "{symbol_name_list}" in the function you need to reverse-engineering and output those references as YAML.

Example:

yaml
found_vcall: # This is for indirect call to virtual function or virtual function pointer fetching.
  - insn_va: '0x180777700' # Always be the instruction with displacement offset
    insn_disasm: call [rax+68h] # Always be the instruction with displacement offset
    vfunc_offset: '0x68'
    func_name: ILoopMode_OnLoopActivate
  - insn_va: '0x180777778' # Always be the instruction with displacement offset
    insn_disasm: mov rax, [rax+80h] # Always be the instruction with displacement offset
    vfunc_offset: '0x80'
    func_name: INetworkMessages_GetNetworkGroupCount

found_call: # This is for direct call to non-virtual regular function.
  - insn_va: '0x180888800'
    insn_disasm: call sub_180999900
    func_name: CLoopMode_RegisterEventMapInternal
  - insn_va: '0x180888880'
    insn_disasm: call sub_180555500
    func_name: CLoopMode_SetSystemState

found_funcptr: # This is for non-virtual regular function pointer.
  - insn_va: '0x180666600' # Must load/reference the function pointer target address
    insn_disasm: lea rdx, sub_15BC910 # Must load/reference the function pointer target address
    funcptr_name: CLoopMode_OnClientPollNetworking

found_gv: # This is for reference to global variable.
  - insn_va: '0x180444400'
    insn_disasm: mov rcx, cs:qword_180666600 # Must load/reference the global variable
    gv_name: g_pNetworkMessages
  - insn_va: '0x180333300'
    insn_disasm: lea rax, unk_180222200 # Must load/reference the global variable
    gv_name: s_EventManager

found_struct_offset: # This is for reference to struct offset. NOTE THAT virtual function pointer should not be here! virtual function pointer should ALWAYS be in found_vcall !
  - insn_va: '0x1801BA12A' # Always be the instruction with displacement offset
    insn_disasm: mov rcx, [r14+58h] # Always be the instruction with displacement offset
    offset: '0x58'
    size: 8
    struct_name: CResourceService
    member_name: m_pEntitySystem

If nothing found, output an empty YAML. DO NOT output anything other than the desired YAML. DO NOT collect unrelated symbols.


### 变量说明

| 变量 | 来源 | 说明 |
|------|------|------|
| `{disasm_for_reference}` | 旧版 IDA 导出 | 有符号的反汇编 |
| `{procedure_for_reference}` | 旧版 IDA 导出 | 有符号的伪代码 |
| `{disasm_code}` | 新版 IDA 导出 | 无符号的反汇编 |
| `{procedure}` | 新版 IDA 导出 | 无符号的伪代码 |
| `{symbol_name_list}` | 从旧版提取 | 需要在新版中定位的符号列表 |

## 工作流

### 完整流程

```text
Step 1: 准备数据
  - 旧版二进制加载到 IDA(有 PDB/符号)
  - 新版二进制加载到 IDA(无符号)
  - 找到两个版本中相同的锚点函数(导出函数、字符串引用等)

Step 2: 批量导出
  - 从旧版导出:锚点函数的反汇编 + 伪代码(含符号名)
  - 从新版导出:同一锚点函数的反汇编 + 伪代码(无符号名)

Step 3: LLM 比对
  - 用 prompt 模板填充数据
  - 调用 LLM API(推荐:deepseek 量大便宜,超大函数切 gpt)
  - 解析返回的 YAML

Step 4: 应用结果
  - 将 YAML 中的符号映射批量应用到新版 IDB
  - 用 idapro_rename 或 IDAPython 脚本批量重命名

Step 5: 迭代
  - 第一轮迁移的函数成为新的锚点
  - 进入这些函数,继续对比内部调用
  - 重复直到覆盖所有目标函数
锚点选择策略
锚点类型可靠性说明
导出函数最高名字不变,地址可能变
字符串引用高字符串内容不变,引用位置可能变
常量/魔数中特征值不变
代码模式中函数结构相似但地址全变
批量处理建议
  • 每次比对 1 个函数(避免 context 爆炸)
  • 中等函数(<200 行)用 deepseek
  • 超大函数(>500 行)切 gpt-4o 或 claude
  • 并发调用提高速度(10-20 并发)
  • 结果缓存,避免重复调用

输出格式

YAML 输出的 5 种符号类型
类型含义关键字段
found_vcall虚函数调用(间接 call)vfunc_offset, func_name
found_call直接函数调用insn_va, func_name
found_funcptr函数指针引用insn_va, funcptr_name
found_gv全局变量引用insn_va, gv_name
found_struct_offset结构体偏移引用offset, struct_name, member_name
Show full SKILL.md (152 more words)Show less
解析后的应用动作
text
found_call → idapro_rename(addr=call_target, name=func_name)
found_vcall → idapro_set_comments(addr=insn_va, comment="vcall: {func_name} @ +{offset}")
found_funcptr → idapro_rename(addr=funcptr_target, name=funcptr_name)
found_gv → idapro_rename(addr=gv_addr, name=gv_name)
found_struct_offset → idapro_set_comments(addr=insn_va, comment="{struct_name}.{member_name}")

典型场景示例

场景 1:ntoskrnl.exe 缺 PDB
text
已有:ntoskrnl.exe 10.0.26100.2000 + 完整 PDB
目标:ntoskrnl.exe 10.0.26100.2605(PDB 被下架)
需求:定位 PspSetCreateProcessNotifyRoutine 的新地址

步骤:
1. 两个版本都加载到 IDA
2. 找到导出函数 PsSetCreateProcessNotifyRoutine(两个版本都有)
3. 旧版中它调用了 PspSetCreateProcessNotifyRoutine(有符号)
4. 新版中它调用了 sub_140822108(无符号)
5. LLM 一眼看出:sub_140822108 = PspSetCreateProcessNotifyRoutine
6. 批量应用
场景 2:应用更新后迁移
text
已有:target.exe v1.0 的完整逆向结果(200+ 函数已命名)
目标:target.exe v1.1(所有符号丢失)
需求:批量迁移 200 个函数名

步骤:
1. 从旧版导出所有已命名函数的反汇编+伪代码
2. 在新版中通过导出函数/字符串找到对应锚点
3. 批量调用 LLM 比对
4. 解析 YAML,批量 rename
5. 迭代深入

LLM 选择建议

模型适合场景成本速度
DeepSeek V3中小函数(<200 行),批量处理极低快
GPT-4o超大函数,复杂控制流中快
Claude Sonnet中大函数,需要推理中快
Claude Opus极复杂函数,需要深度理解高慢

推荐策略:默认 DeepSeek,遇到 context 超限或结果不准时自动升级。

注意事项

  • 不要把整个二进制丢给 LLM — 一次只比对一个函数
  • 锚点必须可靠 — 如果锚点本身就对错了,后续全部白费
  • 结果需要人工抽检 — LLM 不是 100% 准确,关键符号要验证
  • 缓存中间结果 — 避免重复调用浪费 token
  • 注意 context 限制 — 超大函数(>1000 行反汇编)需要拆分或用大 context 模型

按需自举(On-Demand Bootstrap)

工具依赖
工具用途可自动安装
IDA Pro导出反汇编/伪代码✗(商业软件)
Python脚本执行、API 调用✓
PyYAML解析 LLM 返回的 YAML✓(pip install pyyaml)
LLM API执行比对需要 API key
说明

本 skill 的核心不依赖重型工具安装,主要依赖:

  • IDA Pro 已有(用 ida-reverse/ skill 管理)
  • Python + requests/httpx(调 API)
  • 一个 LLM API endpoint

路由上下文

上游入口: skills/SKILL.md(总控)、routing.md 触发条件: 有旧版符号/逆向结果,需要迁移到新版本 下游出口:

  • 需要先打开二进制 → ida-reverse/
  • 需要快速侦察确认版本差异 → radare2/

同级关联模块: ida-reverse/(数据导出和符号应用都通过 IDA)

任务完成自检(声称完成前 MUST 通过)

  • 我是否执行了工作流中的每一步(而不是只阅读)?
  • 我是否基于 tool-index 使用了真实工具路径?
  • 我是否产出了可复现证据(命令/脚本/截图/报告)?
  • 我是否完成并回写了 RULES 要求的 Checklist 项?

Limitations

  • Diff quality degrades with heavy recompilation or obfuscation between versions.
  • Requires local diff tooling (e.g., BinDiff, Diaphora, radiff2).

Adapted from zhaoxuya520/reverse-skill (MIT).

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/binary-diff of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/prompt-template.md

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Binary Diff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Binary Diff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Binary Diff this skillsickn33/agentic-awesome-skills47k1 repos~2.1kAutomated safety check: PassMIT
Update Chrome Binaries Test Regionremotion-dev/remotion62k—~1.3kAutomated safety check: PassCustom licence
Docs Update from DiffQwenLM/qwen-code28k—~1.1kAutomated safety check: PassApache-2.0
Reversible MigrationJuliusBrussee/caveman110k1 repos~196Automated safety check: PassApache-2.0
Database Migrationsaffaan-m/ECC274k4 repos~3kAutomated safety check: PassMIT
Database Migrationsaffaan-m/ECC274k1 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Official

    Publish Remotion Lambda Chrome binaries to the eu-central-1 test region and update hosted layer and Chrome version references.

    62k GitHub stars~1.3k tokensUpdated today
    Media & CreativeAuto-check passed
  • Docs Update from Diff

    QwenLM/qwen-code

    Reads local git changes and updates only the matching docs pages, so documentation stays in sync with uncommitted or recent code changes.

    28k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Reversible Migration

    JuliusBrussee/caveman

    Implement reversible compatibility-safe transitions. Use for schema, data, API, protocol, configuration, or dependency migrations requiring rollback and…

    110k GitHub starsUsed in 1 repo~196 tokens
    DevelopmentAuto-check passed
  • Safe, reversible database migration patterns: forward-only production changes, expand-contract zero-downtime renames, concurrent indexes, batched backfills, and per-tool workflows for PostgreSQL…

    274k GitHub starsUsed in 4 repos~3k tokens
    DatabasesAuto-check passed
  • Şema değişiklikleri, veri migration'ları, rollback'ler ve PostgreSQL, MySQL ve yaygın ORM'ler (Prisma, Drizzle, Django, TypeORM, golang-migrate) arasında sıfır kesinti deployment'ları için…

    274k GitHub starsUsed in 1 repo~2.4k tokens
    DatabasesAuto-check passed
  • Od Code Migration

    nexu-io/open-design

    Default reference pipeline for the code-migration taskKind — code-import → design-extract → token-map → rewrite-plan → patch-edit ↔ build-test devloop → diff-review → handoff.

    100k GitHub stars~378 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Binary Diff

What does Binary Diff do?

Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling. Binary Diff is an agent skill from sickn33/agentic-awesome-skills. Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.

How do I install Binary Diff in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill binary-diff -a claude-code`. Or copy the skill folder (skills/binary-diff in sickn33/agentic-awesome-skills) into .claude/skills/binary-diff in your project. Claude Code loads it when a task matches its description.

How do I install Binary Diff in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill binary-diff -a codex`. Or copy the skill folder (skills/binary-diff in sickn33/agentic-awesome-skills) into .agents/skills/binary-diff in your project. Codex loads it when a task matches its description.

Can I use Binary Diff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill binary-diff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/binary-diff, .gemini/skills/binary-diff, .github/skills/binary-diff and .opencode/skills/binary-diff in your project.

What does Binary Diff need to run?

SKILL.md names no scripts, command-line tools or credentials: Binary Diff is instructions for the agent only. Our summary lists: Python 3.

Does Binary Diff access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Binary Diff safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Binary Diff use?

Binary Diff is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Binary Diff use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Binary Diff?

Skills that share tags, products or a category with Binary Diff: Update Chrome Binaries Test Region (remotion-dev/remotion, 62k stars), Docs Update from Diff (QwenLM/qwen-code, 28k stars), Reversible Migration (JuliusBrussee/caveman, 110k stars) and Database Migrations (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Binary Diff?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.