Agent skill

Analyzing Go Binaries

by trilwu in trilwu/secskills

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

MITAuto-check passedSecurity

Install Analyzing Go Binaries

skills CLI
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills analyzing-go-binaries --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .claude/skills/analyzing-go-binaries && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-go-binaries
GitHub stars
157
Token cost
~2k tokens
SKILL.md length
896 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

  • A binary contains Go runtime strings
  • SKILL.md covers When to Use, When NOT to Use, Confirm It Is Go, and Which… and Recover Symbols, plus 6 more sections
  • Calls go, rg and jq
  • Strings show runtime.main

What it does

Analyzing Go Binaries is an agent skill from trilwu/secskills. Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention, interface dispatch, and string layout. Use when a binary contains Go runtime strings, when strings show runtime.main or go:buildid, when a stripped binary is unexpectedly large, or when analyzing Go malware or a Go-based service.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. It works with Ghidra. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A binary contains Go runtime strings
  • Strings show runtime.main
  • A stripped binary is unexpectedly large
  • Analyzing Go malware

Example prompts

  • “/analyzing-go-binaries”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • rg
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Go Binaries loads about 2k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 896 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 896 words, ~1,959 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-go-binaries/SKILL.md (or your agent's skills folder).
name
analyzing-go-binaries
description
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention, interface dispatch, and string layout. Use when a binary contains Go runtime strings, when strings show runtime.main or go:buildid, when a stripped binary is unexpectedly large, or when analyzing Go malware or a Go-based service.
verified
2026-07-27

Analyzing Go Binaries

Go binaries look hostile — statically linked, tens of megabytes, no imports you recognize, and "stripped" in a way that makes tools show thousands of sub_ functions. They are not. Go ships its own symbol table for runtime reflection and panic traces, and strip does not remove it. Recover it and the binary becomes one of the easiest targets there is.

When to Use

  • strings shows runtime.main, go:buildid, go.buildinfo, or runtime.gopanic
  • A "stripped" binary is 5–50 MB with almost no dynamic imports
  • The disassembler shows thousands of unnamed functions and unreadable strings
  • Analyzing Go malware, a Go CLI tool, or a compiled Go service

When NOT to Use

  • Rust binaries — use analyzing-rust-binaries; the symbol recovery is entirely different
  • .NET assemblies — use analyzing-dotnet-assemblies
  • Suspected malware, before containment — use analyzing-malware for the environment, then come back here
  • General native RE — use analyzing-binaries

Confirm It Is Go, and Which Version

bash
strings -n 6 target | rg -m5 'go1\.[0-9]+|go:buildid|runtime\.main|GOROOT'
go version target                     # works on unstripped and many stripped builds
go version -m target                  # module list and build settings — free SBOM

go version -m is the highest-value first command. It prints the module dependency graph with versions, which gives you the third-party libraries in use before you disassemble anything — often answering the question outright (which HTTP library, which crypto, which C2 framework).

The Go version matters because pclntab layout changed at 1.2, 1.16, 1.18, and 1.20. Tooling that fails is usually version mismatch, not a hardened binary.

Recover Symbols

bash
# GoReSym — extracts pclntab, moduledata, types, and build info
GoReSym -t -d -p target > syms.json
#   -t  user type metadata
#   -d  include standard library
#   -p  paths

# redress — Go-aware analysis, works well when GoReSym struggles
redress info target
redress symbols target
redress types target

# Load into the disassembler
#   IDA:    AlphaGolang, golang_loader_assist, or the GoReSym IDA script
#   Ghidra: GolangAnalyzerExtension, or gotools
#   Binja:  the Golang loader plugin

After applying symbols, functions carry their real names — main.processRequest, crypto/tls.(*Conn).Handshake, github.com/vendor/pkg.Function. Filter to main.* and to third-party module paths. Everything under runtime., internal/, and the standard library is stock and is 90%+ of the function count.

bash
jq -r '.UserFunctions[].FunctionName' syms.json | rg -v '^(runtime|internal|reflect|sync)\.' | head -40

Reading Go Code in a Disassembler

Four things make Go listings confusing until you know them:

Strings have no terminator. Go strings are a pointer plus a length, so strings output runs adjacent literals together and the disassembler shows a pointer load followed by a length constant. Look for the pair — the constant next to the pointer is the length, and that is how you slice the correct substring out of the blob.

Calling convention. Before Go 1.17 all arguments and return values went on the stack, not in registers. From 1.17 a register ABI applies on amd64/arm64. A decompiler configured for the C convention will show wrong arguments; Go-aware plugins fix this, and it is the main reason decompiler output looks nonsensical.

Interface dispatch. Calls through an interface go via an itab — a table holding the concrete type and its method pointers. To resolve a call target, find the itab being loaded, then read the concrete type. Type recovery tools name these, which turns an indirect call into a readable one.

Goroutines and defers. go f() compiles to runtime.newproc with f as an argument, so concurrent logic does not appear as a direct call. defer becomes runtime.deferproc/deferreturn, which scatters cleanup code away from where it was written. When following control flow, check newproc call sites for work you would otherwise miss entirely.

Type Recovery

Go embeds full type descriptors for reflection. That means struct field names and layouts are recoverable — including the JSON tags that map straight to a wire protocol.

bash
redress types target | rg -A10 'type main\.'
# Struct tags like `json:"api_key"` recover the exact protocol field names

This is the fastest route to a Go service's API surface or a Go implant's C2 message format: recover the request and response structs, and you have the protocol without reading a single instruction.

Show full SKILL.md (357 more words)Show less

Go-Specific Security Review

If the job is finding bugs rather than understanding behaviour, the Go-specific classes worth targeting:

  • Ignored errors. _ = on a function returning an error, especially around auth, crypto, and file operations.
  • math/rand for security values. Token, session ID, or nonce generation using the non-crypto RNG.
  • InsecureSkipVerify: true in a tls.Config.
  • fmt.Sprintf building SQL, shell commands, or URLs.
  • Data races on shared maps and structs — often the source of authorization bugs under load.
  • os/exec with a shell, or with an argument built from input.

With source available, use auditing-code-for-vulnerabilities and govulncheck; the above is for when you only have the binary.

Go Malware Notes

Go is common in cross-platform implants, and it leaves useful artifacts:

  • Module list from go version -m identifies the frameworks used — networking libraries, crypto, and sometimes the C2 project itself.
  • Build paths in the symbol table leak developer usernames, project names, and directory structures.
  • main. package function names frequently survive because stripping does not remove pclntab, giving you a capability list for free.
  • Some samples strip pclntab deliberately or use tools that mangle moduledata. When GoReSym and redress both fail on a sample that is otherwise clearly Go, treat that as an evasion indicator worth reporting — and fall back to scanning for the type descriptors directly.

Hand IOC and detection output to analyzing-malware and engineering-detections.

Rationalizations to Reject

  • "It's stripped, so there are no symbols." strip does not remove pclntab. Run GoReSym before concluding anything.
  • "The decompiler output is garbage." It is using the wrong calling convention. Apply a Go-aware plugin.
  • "Thousands of functions, this will take weeks." Almost all are runtime and stdlib. Filter to main.* and vendored modules.
  • "The strings are all mashed together." Go strings are pointer+length. Slice by the length constant.
  • "The tool failed, this binary is protected." Check the Go version against the tool's supported pclntab versions first.
  • "I need to trace every goroutine." Find runtime.newproc call sites and read the function passed to them.

References

  • analyzing-binaries — general triage and dynamic analysis around this
  • analyzing-malware — containment and IOC extraction for Go samples
  • auditing-code-for-vulnerabilities — the Go bug-class checklist when source exists
  • GoReSym, redress, AlphaGolang, GolangAnalyzerExtension, go version -m

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/analyzing-go-binaries of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Analyzing Go Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Go Binaries compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Go Binaries this skilltrilwu/secskills157—~2kAutomated safety check: PassMIT
Rea Tool Designmorluto/rea55k—~239Automated safety check: PassMIT
Ghidra ReOrbitCurve/firmware-reverse-engineering216—~4.2kAutomated safety check: PassApache-2.0
Firmware Security ReportsOrbitCurve/firmware-reverse-engineering216—~4.1kAutomated safety check: PassApache-2.0
Bench ExperimentDavidClawson/OpenScope-2C53T116—~1kAutomated safety check: PassGPL-3.0
Go Rust Reversezhaoxuya520/reverse-skill41k2 repos~339Automated safety check: PassMIT

Similar skills

  • Rea Tool Design

    morluto/rea

    Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.

    55k GitHub stars~239 tokensUpdated today
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    216 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Firmware Security Reports

    OrbitCurve/firmware-reverse-engineering

    Evidence-based security report generation for firmware assessments.

    216 GitHub stars~4.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Bench Experiment

    DavidClawson/OpenScope-2C53T

    Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.

    116 GitHub stars~1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    41k GitHub starsUsed in 2 repos~339 tokens
    SecurityAuto-check passed
  • A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…

    156 GitHub stars~7.5k tokensUpdated 14 days ago
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Malware

    trilwu/secskills

    Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

    157 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Analyzing Go Binaries

What does Analyzing Go Binaries do?

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…. Analyzing Go Binaries is an agent skill from trilwu/secskills. Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention, interface dispatch, and string layout.

When should I use Analyzing Go Binaries?

Analyzing Go Binaries fits situations like: A binary contains Go runtime strings; strings show runtime.main; A stripped binary is unexpectedly large; analyzing Go malware.

How do I install Analyzing Go Binaries in Claude Code?

Run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-go-binaries in trilwu/secskills) into .claude/skills/analyzing-go-binaries in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Go Binaries in Codex?

Run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-go-binaries in trilwu/secskills) into .agents/skills/analyzing-go-binaries in your project. Codex loads it when a task matches its description.

Can I use Analyzing Go Binaries in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-go-binaries, .gemini/skills/analyzing-go-binaries, .github/skills/analyzing-go-binaries and .opencode/skills/analyzing-go-binaries in your project.

What does Analyzing Go Binaries need to run?

Going by SKILL.md and its folder, Analyzing Go Binaries needs the command-line tools its instructions call (go, rg and jq).

Does Analyzing Go Binaries access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyzing Go Binaries safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyzing Go Binaries use?

Analyzing Go Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Go Binaries use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analyzing Go Binaries?

Skills that share tags, products or a category with Analyzing Go Binaries: Rea Tool Design (morluto/rea, 55k stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 216 stars) and Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Go Binaries?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.