Reverse Flow
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
$ npx skills add trilwu/secskills --skill analyzing-binaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills analyzing-binaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .claude/skills/analyzing-binaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .claude/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill analyzing-binaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills analyzing-binaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .agents/skills/analyzing-binaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .agents/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-binaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills analyzing-binaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .cursor/skills/analyzing-binaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .cursor/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/analyzing-binaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill analyzing-binaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills analyzing-binaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .gemini/skills/analyzing-binaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .gemini/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills analyzing-binariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill analyzing-binaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .github/skills/analyzing-binaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .github/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-binaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills analyzing-binaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .opencode/skills/analyzing-binaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-binaries into .opencode/skills/analyzing-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-binaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-binariesReverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
Analyzing Binaries is an agent skill from trilwu/secskills. Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O file, firmware image, or stripped binary, recovering an algorithm or protocol, or working a CTF reversing challenge.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Capture the flag and Reverse engineering and malware. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
attack.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing Binaries loads about 2.9k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,105 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,105 words, ~2,921 tokens.
.claude/skills/analyzing-binaries/SKILL.md (or your agent's skills folder).Reverse engineering is hypothesis testing against a program you cannot read. The cost of the job is dominated by how much code you look at, so the whole discipline is about narrowing: triage first, find the interesting few percent, then read that carefully.
analyzing-malware, which
covers containment and safe detonation. Come back here for the disassembly.analyzing-shellcodeauditing-code-for-vulnerabilitiestesting-mobile-applications;
use this skill for the native .so/Mach-O components inside itreversing-flutter-apps for
libapp.so/Dart snapshots, reversing-unity-il2cpp for libil2cpp.so plus
global-metadata.dat, reversing-react-native-apps for Hermes bytecodeanalyzing-go-binaries
(pclntab survives stripping), analyzing-rust-binaries (panic strings leak
source paths), analyzing-dotnet-assemblies (IL decompiles to C#). Reaching
for generic RE on these wastes most of the effortunpacking-protected-binaries
first; there is nothing to disassemble until it is dumpedanalyzing-firmware-images for binwalk, filesystem carving, and
cross-architecture emulation; return here for an individual binary inside itEvery minute here saves an hour in the decompiler.
file target && du -h target
# Architecture, endianness, PIE, stripped or not — all decide your tooling
readelf -hSd target # ELF: headers, sections, dynamic deps
rabin2 -I target # radare2's normalized summary of any format
objdump -p target # PE/ELF imports and load config
# Protections tell you what the author expected
checksec --file=target # NX, canary, RELRO, PIE, Fortify
# Strings, but read them for structure rather than skimming
strings -n 8 -t x target | less # ASCII with offsets
strings -e l -n 8 target # UTF-16LE, essential on WindowsWhat triage should answer before you disassemble:
| Question | Signal |
|---|---|
| What language/toolchain built this? | Rust/Go runtime strings, libstdc++, __gxx_personality, MSVC RTTI |
| Is it packed? | High entropy, tiny import table, sections named UPX, .themida |
| What does it talk to? | Imports of socket/HTTP APIs, embedded URLs, cert blobs |
| Where is the interesting logic? | Imports of crypto/file/registry/process APIs |
| Is it stripped? | nm -D empty, no .symtab |
# Entropy scan finds packed or embedded-blob regions
binwalk -E target
# Unpack the common case
upx -d target -o target.unpackedGo and Rust binaries are usually not stripped in the ways that matter. Recover symbols before doing anything else — it changes the job from hours to minutes.
# Go: recover function names and types
GoReSym -t -p target > syms.json # or the redress / IDAGolangHelper plugins
# Rust: demangle
nm -C target 2>/dev/null | headPick one tool and go deep; switching tools mid-analysis loses your annotations.
# Ghidra headless: batch import, auto-analyze, run a script
analyzeHeadless /proj MyProj -import target -postScript Decompile.java
# radare2 / rizin interactive
r2 -AA target
# aaa analyze everything
# afl list functions, sorted by size — big ones first
# axt @ sym.f cross-references TO a function (who calls this?)
# pdg @ main decompile with ghidra plugin (r2ghidra)
# iz / izz strings in data / whole binary
# /x deadbeef search for a byte pattern
# Binary Ninja / IDA headless equivalents exist; the workflow is identicalNavigate by evidence, not by address order. The three entry points that find the interesting code fastest:
recv, CreateProcess, fopen,
EVP_EncryptInit to find the code that does the thing you care about.binwalk, findcrypt, and YARA rules locate them.Then read outward from that anchor. Rename every function and variable as you work out what it does — a decompiler listing you have annotated is a completely different artifact from a raw one.
The decompiler gives you C-shaped noise. What you are looking for:
memcpy with a length that came from the input — start of a memory
safety review; see auditing-code-for-vulnerabilities.[rax + 8*n] accesses on the same base — a struct. Define it in
the tool; the listing collapses to readable code.Static tells you what the code can do; dynamic tells you what it does. Run
untrusted binaries only in an isolated VM with no host shares and networking
under your control — see analyzing-malware for the containment procedure.
# Syscall and API-level behaviour
strace -f -e trace=network,file,process -o trace.log ./target
ltrace -f ./target
# Windows equivalents: API Monitor, Procmon, drltrace
# Debugging
gdb -q ./target # with pwndbg/GEF: `checksec`, `vmmap`, `heap`, `telescope`
lldb ./target # macOS
x64dbg / WinDbg # Windows
# Instrumentation — the highest-leverage dynamic technique
frida-trace -f ./target -i 'recv*' -i 'EVP_*'
# then edit the generated JS handlers to dump buffers and patch return valuesFrida is the fastest route through anti-debugging, custom crypto, and license checks: hook the function after decryption rather than defeating the obfuscation that protects it.
Emulation for firmware and isolated routines:
qemu-arm -L /usr/arm-linux-gnueabi ./target # user-mode
# Unicorn for a single function: map memory, set registers, run, read result
# angr for symbolic execution when you need an input that reaches a statebinwalk -Me firmware.bin # extract recursively
# Identify the filesystem before extracting: squashfs, jffs2, cramfs, ubifs
unsquashfs -d rootfs squashfs-root.bin
# Then treat the rootfs as a Linux system
rg -n 'password|admin|BEGIN (RSA|OPENSSH) PRIVATE KEY|api[_-]?key' -i rootfs/
find rootfs -name '*.pem' -o -name 'shadow' -o -name '*.conf'
# Web interface and startup scripts are where the bugs are
ls rootfs/etc/init.d rootfs/www rootfs/usr/sbinFor a bootloader or bare-metal image with no filesystem, find the load address (often in the vendor SDK or derivable from absolute-pointer clustering) before disassembling — a wrong base address makes the whole listing meaningless.
Recognize it, then decide whether to defeat it or route around it.
| Technique | Recognition | Response |
|---|---|---|
| Packing | High entropy, stub + one big section | Unpack, or dump from memory after the OEP |
| Anti-debug | IsDebuggerPresent, ptrace(PTRACE_TRACEME), timing checks | Patch the check, or hook it with Frida |
| VM detection | CPUID checks, MAC OUI, registry artifacts | Harden the VM, or patch the detector |
| String obfuscation | No readable strings but obvious decode loops | Emulate the decoder over all call sites |
| Control-flow flattening | Giant switch on a state variable | Symbolic deobfuscation, or ignore and work dynamically |
Routing around is usually cheaper. If a check is defeating you statically, hook the function that consumes its result.
bindiff against a compiled reference), and Go/Rust metadata
usually survives.An RE report should let a reader act without repeating your work:
<!-- attack:start -->
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Defense Evasion (TA0005)
analyzing-malware, analyzing-shellcodeanalyzing-malwareanalyzing-malware, analyzing-shellcodeanalyzing-malwareanalyzing-malwareDetection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
analyzing-malware — containment, detonation, and IOC extractiontesting-mobile-applications — APK/IPA workflows around native components© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/analyzing-binaries of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Analyzing Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing Binaries this skilltrilwu/secskills | 157 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | |
| Anti Reversing Techniqueswshobson/agents | 40k | — | ~980 | Automated safety check: Pass | MIT | |
| Symbolic Execution Toolsyaklang/hack-skills | 2.4k | — | ~3k | Automated safety check: Pass | MIT |
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
wshobson/agents
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.
yaklang/hack-skills
Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
trilwu/secskills
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
Categories
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Analyzing Binaries is an agent skill from trilwu/secskills. Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
Analyzing Binaries fits situations like: analyzing an executable; ELF/PE/Mach-O file; stripped binary; recovering an algorithm.
Run `npx skills add trilwu/secskills --skill analyzing-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-binaries in trilwu/secskills) into .claude/skills/analyzing-binaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill analyzing-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-binaries in trilwu/secskills) into .agents/skills/analyzing-binaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-binaries, .gemini/skills/analyzing-binaries, .github/skills/analyzing-binaries and .opencode/skills/analyzing-binaries in your project.
Going by SKILL.md and its folder, Analyzing Binaries needs the command-line tools its instructions call (rg and python3). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyzing Binaries: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and Anti Reversing Techniques (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.