Rea Tool Design
morluto/rea
Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills analyzing-go-binaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .claude/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .claude/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills analyzing-go-binaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .agents/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .agents/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills analyzing-go-binaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .cursor/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .cursor/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/analyzing-go-binaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills analyzing-go-binaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .gemini/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .gemini/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills analyzing-go-binariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .github/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .github/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-go-binaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills analyzing-go-binaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/analyzing-go-binaries .opencode/skills/analyzing-go-binaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-go-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-go-binaries into .opencode/skills/analyzing-go-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-go-binaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-go-binariesReverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
Analyzing Go Binaries is an agent skill from trilwu/secskills. Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention, interface dispatch, and string layout. Use when a binary contains Go runtime strings, when strings show runtime.main or go:buildid, when a stripped binary is unexpectedly large, or when analyzing Go malware or a Go-based service.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware. It works with Ghidra. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gorgjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing Go Binaries loads about 2k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 896 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 896 words, ~1,959 tokens.
.claude/skills/analyzing-go-binaries/SKILL.md (or your agent's skills folder).Go binaries look hostile — statically linked, tens of megabytes, no imports
you recognize, and "stripped" in a way that makes tools show thousands of
sub_ functions. They are not. Go ships its own symbol table for runtime
reflection and panic traces, and strip does not remove it. Recover it and
the binary becomes one of the easiest targets there is.
strings shows runtime.main, go:buildid, go.buildinfo, or
runtime.gopanicanalyzing-rust-binaries; the symbol recovery is
entirely differentanalyzing-dotnet-assembliesanalyzing-malware for the
environment, then come back hereanalyzing-binariesstrings -n 6 target | rg -m5 'go1\.[0-9]+|go:buildid|runtime\.main|GOROOT'
go version target # works on unstripped and many stripped builds
go version -m target # module list and build settings — free SBOMgo version -m is the highest-value first command. It prints the module
dependency graph with versions, which gives you the third-party libraries in
use before you disassemble anything — often answering the question outright
(which HTTP library, which crypto, which C2 framework).
The Go version matters because pclntab layout changed at 1.2, 1.16, 1.18,
and 1.20. Tooling that fails is usually version mismatch, not a hardened
binary.
# GoReSym — extracts pclntab, moduledata, types, and build info
GoReSym -t -d -p target > syms.json
# -t user type metadata
# -d include standard library
# -p paths
# redress — Go-aware analysis, works well when GoReSym struggles
redress info target
redress symbols target
redress types target
# Load into the disassembler
# IDA: AlphaGolang, golang_loader_assist, or the GoReSym IDA script
# Ghidra: GolangAnalyzerExtension, or gotools
# Binja: the Golang loader pluginAfter applying symbols, functions carry their real names —
main.processRequest, crypto/tls.(*Conn).Handshake,
github.com/vendor/pkg.Function. Filter to main.* and to third-party
module paths. Everything under runtime., internal/, and the standard
library is stock and is 90%+ of the function count.
jq -r '.UserFunctions[].FunctionName' syms.json | rg -v '^(runtime|internal|reflect|sync)\.' | head -40Four things make Go listings confusing until you know them:
Strings have no terminator. Go strings are a pointer plus a length, so
strings output runs adjacent literals together and the disassembler shows a
pointer load followed by a length constant. Look for the pair — the constant
next to the pointer is the length, and that is how you slice the correct
substring out of the blob.
Calling convention. Before Go 1.17 all arguments and return values went on the stack, not in registers. From 1.17 a register ABI applies on amd64/arm64. A decompiler configured for the C convention will show wrong arguments; Go-aware plugins fix this, and it is the main reason decompiler output looks nonsensical.
Interface dispatch. Calls through an interface go via an itab — a table
holding the concrete type and its method pointers. To resolve a call target,
find the itab being loaded, then read the concrete type. Type recovery tools
name these, which turns an indirect call into a readable one.
Goroutines and defers. go f() compiles to runtime.newproc with f as
an argument, so concurrent logic does not appear as a direct call. defer
becomes runtime.deferproc/deferreturn, which scatters cleanup code away
from where it was written. When following control flow, check newproc call
sites for work you would otherwise miss entirely.
Go embeds full type descriptors for reflection. That means struct field names and layouts are recoverable — including the JSON tags that map straight to a wire protocol.
redress types target | rg -A10 'type main\.'
# Struct tags like `json:"api_key"` recover the exact protocol field namesThis is the fastest route to a Go service's API surface or a Go implant's C2 message format: recover the request and response structs, and you have the protocol without reading a single instruction.
If the job is finding bugs rather than understanding behaviour, the Go-specific classes worth targeting:
_ = on a function returning an error, especially
around auth, crypto, and file operations.math/rand for security values. Token, session ID, or nonce generation
using the non-crypto RNG.InsecureSkipVerify: true in a tls.Config.fmt.Sprintf building SQL, shell commands, or URLs.os/exec with a shell, or with an argument built from input.With source available, use auditing-code-for-vulnerabilities and
govulncheck; the above is for when you only have the binary.
Go is common in cross-platform implants, and it leaves useful artifacts:
go version -m identifies the frameworks used —
networking libraries, crypto, and sometimes the C2 project itself.main. package function names frequently survive because stripping does
not remove pclntab, giving you a capability list for free.pclntab deliberately or use tools that mangle
moduledata. When GoReSym and redress both fail on a sample that is
otherwise clearly Go, treat that as an evasion indicator worth reporting —
and fall back to scanning for the type descriptors directly.Hand IOC and detection output to analyzing-malware and
engineering-detections.
strip does not remove
pclntab. Run GoReSym before concluding anything.main.* and vendored modules.pclntab versions first.runtime.newproc call sites and
read the function passed to them.analyzing-binaries — general triage and dynamic analysis around thisanalyzing-malware — containment and IOC extraction for Go samplesauditing-code-for-vulnerabilities — the Go bug-class checklist when source existsgo version -m© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/analyzing-go-binaries of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Analyzing Go Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing Go Binaries this skilltrilwu/secskills | 157 | — | ~2k | Automated safety check: Pass | MIT | |
| Rea Tool Designmorluto/rea | 55k | — | ~239 | Automated safety check: Pass | MIT | |
| Ghidra ReOrbitCurve/firmware-reverse-engineering | 216 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Firmware Security ReportsOrbitCurve/firmware-reverse-engineering | 216 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Bench ExperimentDavidClawson/OpenScope-2C53T | 116 | — | ~1k | Automated safety check: Pass | GPL-3.0 | |
| Go Rust Reversezhaoxuya520/reverse-skill | 41k | 2 repos | ~339 | Automated safety check: Pass | MIT |
morluto/rea
Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.
OrbitCurve/firmware-reverse-engineering
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
OrbitCurve/firmware-reverse-engineering
Evidence-based security report generation for firmware assessments.
DavidClawson/OpenScope-2C53T
Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.
zhaoxuya520/reverse-skill
A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
villith/relink-logs
A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
trilwu/secskills
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
Works with
Categories
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…. Analyzing Go Binaries is an agent skill from trilwu/secskills. Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention, interface dispatch, and string layout.
Analyzing Go Binaries fits situations like: A binary contains Go runtime strings; strings show runtime.main; A stripped binary is unexpectedly large; analyzing Go malware.
Run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-go-binaries in trilwu/secskills) into .claude/skills/analyzing-go-binaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-go-binaries in trilwu/secskills) into .agents/skills/analyzing-go-binaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-go-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-go-binaries, .gemini/skills/analyzing-go-binaries, .github/skills/analyzing-go-binaries and .opencode/skills/analyzing-go-binaries in your project.
Going by SKILL.md and its folder, Analyzing Go Binaries needs the command-line tools its instructions call (go, rg and jq).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing Go Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyzing Go Binaries: Rea Tool Design (morluto/rea, 55k stars), Ghidra Re (OrbitCurve/firmware-reverse-engineering, 216 stars), Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 216 stars) and Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.