Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .claude/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .agents/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .cursor/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .gemini/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .github/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "yara-rule-authoring" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/yara-authoring/skills/yara-rule-authoring into .opencode/skills/yara-rule-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "yara-rule-authoring", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
yara-rule-authoring
GitHub stars
7.4k
Token cost
~5.9k tokens
SKILL.md length
2,484 words
Files
22 (incl. scripts, references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0
At a glance
Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.
Works in 5 steps: Strings must generate good atoms — YARA… → Target specific families, not categories… → Test against goodware before deployment… → …
Writing a new YARA-X rule for a malware family
SKILL.md covers Core Principles, When to Use, When NOT to Use and Platform Considerations, plus 15 more sections
Runs Python scripts from its folder; calls uv, brew and cargo
What it does
The skill targets YARA-X, the Rust-based successor to legacy YARA, installed with brew or cargo and run through the yr CLI. Its principles: pick strings that yield good four-byte atoms, aim rules at specific malware families rather than broad categories, test against a goodware corpus before deployment, order cheap checks first (file size, magic bytes, strings, then modules), and treat metadata as documentation of what a rule catches and where the sample came from.
It lists when to use it, such as writing rules, optimizing slow rulesets, turning IOCs into signatures, debugging false positives, migrating legacy rules and analyzing Chrome extensions or Android apps with the crx and dex modules, and when not to, such as disassembly, sandbox analysis, network detection or memory forensics. The folder carries reference notes on strings, performance, style, testing and the two modules, five example rules, and an atom analyzer script.
When your agent uses it
Writing a new YARA-X rule for a malware family
Reviewing or speeding up an existing ruleset
Reducing false positives before putting rules into production
Converting legacy YARA rules to YARA-X
Example prompts
“Write a YARA-X rule for this sample's configuration routine and check that its strings make good atoms.”
“Review rules/remcos.yar for performance problems and false-positive risk.”
“Migrate our legacy YARA ruleset to YARA-X and flag anything that needs manual changes.”
Requirements
YARA-X, installed with brew install yara-x or cargo install yara-x
Workflow steps
5 steps, taken from the first numbered list in SKILL.md.
1Strings must generate good atoms — YARA extracts 4-byte subsequences for fast matching. Strings with repeated bytes, common sequences, or…
2Target specific families, not categories — "Detects ransomware" catches everything and nothing. "Detects LockBit 3.0 configuration…
3Test against goodware before deployment — A rule that fires on Windows system files is useless. Validate against VirusTotal's goodware…
4Short-circuit with cheap checks first — filesize (instant), then magic bytes (nearly instant), then strings (cheap), then modules…
5Metadata is documentation — Future you (and your team) need to know what this catches, why, and where the sample came from.
What it can do on your machine
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 2 files in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
uv
brew
cargo
ssh
From the folder's file list and the shell code blocks in SKILL.md.
Network
Links to these hosts (documentation or services it may open):
github.com
virustotal.github.io
objective-see.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
YARA-X Rule Authoring loads about 5.9k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 2,484 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~97
When it runs· the whole SKILL.md, loaded when a task matches
~5.9k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~21k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/yara-rule-authoring/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.
name
yara-rule-authoring
description
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module.
YARA-X Rule Authoring
Write detection rules that catch malware without drowning in false positives.
This skill targets YARA-X, the Rust-based successor to legacy YARA — 5-10x faster regex, better errors, built-in formatter, stricter validation, new modules (crx, dex), 99% rule compatibility. It powers VirusTotal's production systems. Install with brew install yara-x or cargo install yara-x; the CLI is yr. See Migrating from Legacy YARA for existing rules.
Core Principles
Strings must generate good atoms — YARA extracts 4-byte subsequences for fast matching. Strings with repeated bytes, common sequences, or under 4 bytes force slow bytecode verification on too many files.
Target specific families, not categories — "Detects ransomware" catches everything and nothing. "Detects LockBit 3.0 configuration extraction routine" catches what you want.
Test against goodware before deployment — A rule that fires on Windows system files is useless. Validate against VirusTotal's goodware corpus or your own clean file set.
Short-circuit with cheap checks first — filesize (instant), then magic bytes (nearly instant), then strings (cheap), then modules (expensive).
Metadata is documentation — Future you (and your team) need to know what this catches, why, and where the sample came from.
When to Use
Writing new YARA-X rules for malware detection
Reviewing existing rules for quality or performance issues
Optimizing slow-running rulesets
Converting IOCs or threat intel into detection signatures
Debugging false positive issues
Preparing rules for production deployment
Migrating legacy YARA rules to YARA-X
Analyzing Chrome extensions (crx module) or Android apps (dex module)
When NOT to Use
Static analysis requiring disassembly → use Ghidra/IDA skills
Dynamic malware analysis → use sandbox analysis skills
Network-based detection → use Suricata/Snort skills
Memory forensics with Volatility → use memory forensics skills
Simple hash-based detection → just use hash lists
Platform Considerations
YARA works on any file type. Adapt patterns to your target:
uintNN() reads little-endian. Write the constant as the bytes reversed, or use uintNNbe() and write them in file order. A ZIP/OOXML file starts with bytes 50 4B 03 04, so it is uint32(0) == 0x04034B50 — uint32(0) == 0x504B0304 compiles cleanly and never matches anything. The same trap catches Mach-O universal binaries: on disk they are CA FE BA BE, so uint32(0) == 0xCAFEBABE is a dead branch; write uint32be(0) == 0xCAFEBABE or uint32(0) == 0xBEBAFECA. Verify with yr scan against one known-good sample before trusting any magic-byte check.
macOS Malware Detection
No dedicated Mach-O module exists yet — use magic bytes plus string patterns. Good indicators:
Unique strings that survive bundling (URLs, magic values); avoid function names — they get mangled
Good JS strings: Ethereum function selectors — { a9 05 9c bb } (transfer(address,uint256)), { 70 a0 82 31 } (balanceOf(address)); zero-width characters for steganography — { E2 80 8B E2 80 8C }; obfuscator signatures — _0x, var _0x; specific C2 domains and webhook URLs.
Bad JS strings:require, fetch, axios (too common); Buffer, crypto (legitimate uses everywhere); process.env alone (need specific env var names).
String Selection
Value ranking: mutex names are gold, C2 paths silver, error messages bronze. Stack strings are almost always unique. If you need more than 6 strings, you're over-fitting.
Reject a candidate string when any of these holds:
Test
Why it fails
Do instead
Under 4 bytes
No atom
Find a longer string
Repeated bytes (0000, 9090)
Weak atom
Add surrounding context
API name (VirtualAlloc, CreateRemoteThread)
Every packer and installer calls it
Hex pattern of the call site plus a unique marker
Appears in Windows system files
Guaranteed FPs
Find something family-specific
Common path (C:\Windows\, cmd.exe)
Ubiquitous
Find malware-specific paths
Appears in other malware families
Not identifying this family
Combine with a family-specific marker
Everything left — unique to this family — is what the rule should rest on.
Choosing a String Type
Need
Use
Exact ASCII/Unicode text
$s = "MutexName" ascii wide
Specific byte sequence
$h = { 4D 5A 90 00 }
Byte sequence with variation
Hex wildcards: { 4D 5A ?? ?? 50 45 }
Pattern with structure (URLs, paths)
Bounded regex: /https:\/\/[a-z]{5,20}\.onion/
Unknown encoding (XOR, base64)
Modifier: $s = "config" xor(0x00-0xFF)
Modifier discipline: never use nocase or wide speculatively — only with confirmed evidence that case or encoding varies across samples. nocase doubles atom generation; wide doubles string matching. "If you don't have a clear reason for using those modifiers, don't do it" — Kaspersky Applied YARA.
Condition Design
Order for short-circuit: filesize <, magic bytes, strings, modules. If the condition runs past 5 lines, split into multiple rules.
all of vs any of
Situation
Use
Strings are individually unique to the malware
any of them — each alone is suspicious
Strings are common but the combination is suspicious
all of them — require the full pattern
Strings have different confidence levels
Group: all of ($core_*) and any of ($variant_*)
Seeing false positives
Tighten: any → all, add more required strings
Lesson from production: rules using any of ($network_*) where the strings included fetch, axios, and http matched virtually all web applications. Switching to require a credential path AND a network call AND an exfil destination eliminated the FPs.
Grouping by Confidence
Different indicator types carry different weight — a C2 domain might be definitive while library imports need corroboration. Grouping by prefix lets you express graduated requirements:
yara
strings:
$a1 = "SRWebSocket" ascii // Category A: library indicators
$a2 = "SocketRocket" ascii
$b1 = "SSH tunnel" ascii // Category B: behavioral
$b2 = "keylogger" ascii nocase
$c1 = /https:\/\/[a-z0-9]{8,16}\.onion/ // Category C: C2
condition:
filesize < 10MB and
any of ($a*) and any of ($b*) // Evidence from BOTH categories
Modules vs Byte Checks
Need
Use
imphash, rich header, authenticode
PE module — too complex to replicate
Magic bytes or simple offsets
uint16/uint32 — faster, no module overhead
Section names/sizes
PE module, but put the magic-byte filter FIRST
Chrome extension permissions
crx module — string parsing is fragile
LNK target paths
lnk module — the format is complex
"Avoid the magic module — use explicit hex checks instead" — Neo23x0. Generalize it: if uint32() can do the job, don't load a module.
Performance
Regex must be anchored to a 4+ byte literal. Without one it evaluates at every file offset — catastrophic. Write /mshta\.exe http:\/\/.../, not /http:\/\/.../. If you can't anchor, use a hex pattern with wildcards.
Bound every regex quantifier — .{0,30}, never .*. Unbounded regex is both a performance disaster and a memory explosion.
Bound loops with filesize — filesize < 100KB and for all i in (1..#a) : .... Unbounded #a can reach thousands in large files.
Prefer hex over regex where the bytes are fixed.
Before Writing: Is the Sample Packed?
Signal
What to do
Entropy > 7.0
Likely packed — find the unpacked layer first
Few or no readable strings
Likely packed — use entropy, PE structure, or packer signatures
UPX/MPRESS/custom packer detected
Target the unpacked payload OR detect the packer itself
Readable strings available
Proceed with string-based detection
Don't write rules against packed layers. The packing changes; the payload doesn't.
When Strings Fail, Pivot to Structure
If extraction returns only API names and generic paths:
Available signal
Use
High entropy sections
math.entropy() on specific sections
Unusual import pattern
pe.imphash() for import-hash clustering
PE structure anomalies
Section names, sizes, characteristics
Metadata present
Version info, timestamps, resources
Nothing unique
This sample may not be detectable with YARA alone
"One can try to use other file properties, such as metadata, entropy, import hashes or other data which stays constant." — Kaspersky Applied YARA Training
Debugging False Positives
Which string matched? — yr scan -s rule.yar false_positive.exe
In a legitimate library? — add a not $fp_vendor_string exclusion
A common development pattern? — replace the string with something more specific
Multiple generic strings matching together? — tighten to require all, plus a unique marker
Malware using a common technique? — target its specific implementation details, not the technique
Extract obfuscated/stack strings: floss sample.exe — when yarGen comes up empty
signature-base
Study quality examples
YARA-CI
Goodware corpus testing before deployment
Master these five. Don't get distracted by tool catalogs.
Development cycle:
bash
yr check rule.yar # syntax, with precise line numbers
yr fmt -w rule.yar # standardize formatting
yr dump -m pe sample.exe --output-format yaml # inspect structure, no dummy rule needed
time yr scan -s rule.yar corpus/ # scan with timing
Reach for yr dump when investigating which module fields are available, debugging why a module condition isn't matching, or exploring a new module (crx, lnk, dotnet) before writing against it. YARA-X error messages carry precise source locations — if yr check says line 15, the problem is on line 15.
Version-gated features:private $helper = "pattern" matches but stays out of output (v1.3.0+); // suppress: slow_pattern silences a specific warning inline (v1.4.0+); filesize < 10_000_000 numeric underscores (v1.5.0+). $_unused also suppresses unused-string warnings.
Chrome Extension Analysis (crx module)
Requires YARA-X v1.5.0+, or v1.11.0+ for permhash().
Every rule needs description (starting with "Detects"), author, reference, and date:
yara
meta:
description = "Detects Example malware via unique mutex and C2 path"
author = "Your Name <email@example.com>"
reference = "https://example.com/analysis"
date = "2025-01-29"
Validate quality — apply the string selection tests; expect to discard 80% of yarGen output
Write the rule — proper metadata, cheap checks first
Lint and test — yr check, yr fmt, the linter script
Goodware validation — VirusTotal corpus or local clean files
Deploy — full metadata, then monitor for FPs
Quality signals along the way: a rule matching under 50% of known variants is too narrow; one matching goodware is too broad.
Reviewing a rule someone else wrote — run both scripts before reading the rule by eye, and quote the codes they emit:
bash
uv run {baseDir}/scripts/yara_lint.py suspect.yar # style, metadata, YARA-X compatibility
uv run {baseDir}/scripts/atom_analyzer.py suspect.yar # atom quality per string
They catch the mechanical faults — short strings, FP-prone substrings, unbounded quantifiers, expensive terms ahead of cheap ones — so your attention goes to the judgement calls they cannot make: whether the strings identify this family, and whether the condition can fire on generic strings alone. Report findings by code (E002, W009) so the author can look each one up in style-guide.md.
macOS specifics: Apple's own production rules ship at /System/Library/CoreServices/XProtect.bundle/; objective-see publishes macOS malware research and samples.
YARA-X Rule Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
YARA-X Rule Authoring compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
YARA-X Rule Authoring this skilltrailofbits/skills
Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and…
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. The skill targets YARA-X, the Rust-based successor to legacy YARA, installed with brew or cargo and run through the yr CLI. Its principles: pick strings that yield good four-byte atoms, aim rules at specific malware families rather than broad categories, test against a goodware corpus before deployment, order cheap checks first (file size, magic bytes, strings, then modules), and treat metadata as documentation of what a rule catches and where the sample came from.
When should I use YARA-X Rule Authoring?
YARA-X Rule Authoring fits situations like: writing a new YARA-X rule for a malware family; reviewing or speeding up an existing ruleset; reducing false positives before putting rules into production; converting legacy YARA rules to YARA-X.
How do I install YARA-X Rule Authoring in Claude Code?
Run `npx skills add trailofbits/skills --skill yara-rule-authoring -a claude-code`. Or copy the skill folder (plugins/yara-authoring/skills/yara-rule-authoring in trailofbits/skills) into .claude/skills/yara-rule-authoring in your project. Claude Code loads it when a task matches its description.
How do I install YARA-X Rule Authoring in Codex?
Run `npx skills add trailofbits/skills --skill yara-rule-authoring -a codex`. Or copy the skill folder (plugins/yara-authoring/skills/yara-rule-authoring in trailofbits/skills) into .agents/skills/yara-rule-authoring in your project. Codex loads it when a task matches its description.
Can I use YARA-X Rule Authoring in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill yara-rule-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yara-rule-authoring, .gemini/skills/yara-rule-authoring, .github/skills/yara-rule-authoring and .opencode/skills/yara-rule-authoring in your project.
What does YARA-X Rule Authoring need to run?
Going by SKILL.md and its folder, YARA-X Rule Authoring needs Python for the scripts in its folder and the command-line tools its instructions call (uv, brew, cargo and ssh). Our summary lists: YARA-X, installed with brew install yara-x or cargo install yara-x.
Does YARA-X Rule Authoring access the network?
SKILL.md names 3 domains. As links in the text: github.com, virustotal.github.io and objective-see.org. This is read from the text; nothing was executed.
Is YARA-X Rule Authoring safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does YARA-X Rule Authoring use?
YARA-X Rule Authoring is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does YARA-X Rule Authoring use?
About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
What are the alternatives to YARA-X Rule Authoring?
Skills that share tags, products or a category with YARA-X Rule Authoring: Building Automated Malware Submission Pipeline (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Incident Response Network (LeoYeAI/openclaw-master-skills, 2.2k stars), vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains YARA-X Rule Authoring?
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.