Agent skill

Reversing Network Protocols

by trilwu in trilwu/secskills

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…

MITAuto-check passedSecurity

Install Reversing Network Protocols

skills CLI
$ npx skills add trilwu/secskills --skill reversing-network-protocols -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills reversing-network-protocols --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/reversing-network-protocols .claude/skills/reversing-network-protocols && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reversing-network-protocols
GitHub stars
157
Token cost
~1.4k tokens
SKILL.md length
727 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…

  • Analyzing a proprietary TCP/UDP protocol
  • SKILL.md covers When to Use, When NOT to Use, Work Both Sides and Build a Parser, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • C2 protocol with no spec

What it does

Reversing Network Protocols is an agent skill from trilwu/secskills. Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums and encryption, and building a Wireshark/Kaitai/scapy parser to replay or fuzz. Use when analyzing a proprietary TCP/UDP protocol, a game or IoT or C2 protocol with no spec, or traffic that Wireshark shows only as raw bytes.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security. It works with Wireshark. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Analyzing a proprietary TCP/UDP protocol
  • C2 protocol with no spec
  • Traffic that Wireshark shows only as raw bytes

Example prompts

  • “/reversing-network-protocols”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reversing Network Protocols loads about 1.4k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 727 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 727 words, ~1,417 tokens.

Download SKILL.mdSave it as .claude/skills/reversing-network-protocols/SKILL.md (or your agent's skills folder).
name
reversing-network-protocols
description
Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums and encryption, and building a Wireshark/Kaitai/scapy parser to replay or fuzz. Use when analyzing a proprietary TCP/UDP protocol, a game or IoT or C2 protocol with no spec, or traffic that Wireshark shows only as raw bytes.
verified
2026-08-07

Reversing Network Protocols

An undocumented binary protocol is reverse-engineered from two sides at once: the wire, which shows you the bytes that actually flow, and the client, which shows you the code that produced them. Neither alone is enough — the capture tells you what varies, the client tells you why — and the deliverable is a parser precise enough to decode, replay, and eventually fuzz the protocol.

When to Use

  • A proprietary or custom TCP/UDP protocol with no public specification
  • Traffic Wireshark displays as raw Data bytes because no dissector matches
  • Game, IoT, industrial, or C2 protocols you must decode from captures plus the client binary
  • Building a Wireshark dissector, a Kaitai Struct spec, or a scapy layer to parse and replay a protocol

When NOT to Use

  • A known/structured protocol — Protobuf or gRPC specifically is attacking-grpc-protobuf; standard protocols have dissectors already.
  • Defensive PCAP investigation — hunting, IOC extraction, incident triage — is analyzing-network-traffic.
  • Reversing the client binary itself (disassembly, decompilation) is analyzing-binaries; do that in service of the protocol, then structure it here.
  • Identifying or breaking the crypto once you find the protocol is encrypted — reviewing-cryptography.

Work Both Sides

From the capture, establish structure by comparing many messages:

  • Framing — how a message knows where it ends: a length prefix (a field that tracks payload size across messages), a delimiter, or fixed-size records. Finding the length field is usually the first breakthrough.
  • Constants and magic — bytes identical across every message mark headers, version fields, or type tags.
  • Opcode / message type — a small field that correlates with different message shapes; group captures by it.
  • Counters and sequence numbers — fields that increment monotonically.
  • Checksums — a trailing field that changes unpredictably with the payload; test CRC variants against the message body.
  • TLV — many custom protocols are type-length-value triplets once you see the pattern.
  • Endianness — confirm from a known length: does a 260-byte message carry 04 01 or 01 04?

From the client, resolve what the capture cannot:

  • Find the serialization/parsing code by reversing the binary (analyzing- binaries), and read how it builds and consumes a message.
  • Hook send/recv (or the app's socket wrapper) with Frida to capture the buffer before encryption and after decryption — this is how you read an encrypted protocol without breaking the crypto.
  • If the protocol is encrypted, hook the plaintext side; identify the cipher and key handling with reviewing-cryptography only if you must operate off-client.
Show full SKILL.md (334 more words)Show less

Build a Parser

Turn the recovered structure into something executable, because a parser is both the proof you understood the protocol and the tool for everything after:

  • Wireshark dissector (Lua) to decode live captures field by field — the fastest way to validate a hypothesis against more traffic.
  • Kaitai Struct to describe the binary format declaratively and generate parsers in several languages.
  • scapy custom layers to both parse and craft messages for replay and fuzzing.

Iterate: decode a batch, find the message that does not parse, refine the spec. The malformed message is where your model is wrong, not noise.

Then What

A working parser enables the security work: replay to test whether the server validates sequence, session, and authentication; fuzz individual fields (lengths, type tags, counts) to find parser bugs; and reason about protocol-level auth — whether nonces, session tokens, or MACs actually prevent replay and tampering, or are decorative.

Rationalizations to Reject

  • "Wireshark shows it as raw data, so there's nothing to see." No dissector matched — that is the starting point, not a dead end. Diff messages to find framing and fields, or write a dissector.
  • "It's encrypted, so I can't reverse it." Hook the client's send/recv to read plaintext before encryption. You rarely need to break the cipher to understand the protocol.
  • "I'll just eyeball the hex." Structure emerges from comparison across many messages — the field that tracks length, the byte that selects type. One message in isolation hides all of it.
  • "The parser mostly works, one message fails — close enough." The failing message is the counterexample that corrects your model. Chase it; it is where the real structure is.
  • "Replaying it is harmless." Replay against a live service acts on that service. Treat it as testing that needs authorization, and reason about what a replayed message does before sending it.

References

  • analyzing-binaries — reversing the client to read its serialization code
  • attacking-grpc-protobuf — when the protocol is Protobuf/gRPC, not custom
  • analyzing-network-traffic — defensive PCAP investigation, not protocol RE
  • reviewing-cryptography — identifying and assessing the protocol's crypto

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/reversing-network-protocols of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Reversing Network Protocols next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reversing Network Protocols compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reversing Network Protocols this skilltrilwu/secskills157—~1.4kAutomated safety check: PassMIT
Wireshark Analysiszebbern/claude-code-guide4.7k8 repos~3kAutomated safety check: PassMIT
IotnetBrownFineSecurity/iothackbot8591 repos~1kAutomated safety check: NotesMIT
Netzhinkgit/embeddedskills734—~1.1kAutomated safety check: PassMIT
Performing Network Forensics With Wiresharkmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.0
Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Wireshark Analysis

    zebbern/claude-code-guide

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…

    4.7k GitHub starsUsed in 8 repos~3k tokens
    SecurityAuto-check passed
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    859 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Net

    zhinkgit/embeddedskills

    嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.

    734 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Network Forensics With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Performing Network Traffic Analysis With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analyzing Network Traffic With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Reversing Network Protocols

What does Reversing Network Protocols do?

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…. Reversing Network Protocols is an agent skill from trilwu/secskills. Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums and encryption, and building a Wireshark/Kaitai/scapy parser to replay or fuzz.

When should I use Reversing Network Protocols?

Reversing Network Protocols fits situations like: analyzing a proprietary TCP/UDP protocol; C2 protocol with no spec; traffic that Wireshark shows only as raw bytes.

How do I install Reversing Network Protocols in Claude Code?

Run `npx skills add trilwu/secskills --skill reversing-network-protocols -a claude-code`. Or copy the skill folder (secskills-core/skills/reversing-network-protocols in trilwu/secskills) into .claude/skills/reversing-network-protocols in your project. Claude Code loads it when a task matches its description.

How do I install Reversing Network Protocols in Codex?

Run `npx skills add trilwu/secskills --skill reversing-network-protocols -a codex`. Or copy the skill folder (secskills-core/skills/reversing-network-protocols in trilwu/secskills) into .agents/skills/reversing-network-protocols in your project. Codex loads it when a task matches its description.

Can I use Reversing Network Protocols in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill reversing-network-protocols -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reversing-network-protocols, .gemini/skills/reversing-network-protocols, .github/skills/reversing-network-protocols and .opencode/skills/reversing-network-protocols in your project.

What does Reversing Network Protocols need to run?

SKILL.md names no scripts, command-line tools or credentials: Reversing Network Protocols is instructions for the agent only.

Does Reversing Network Protocols access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Reversing Network Protocols safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Reversing Network Protocols use?

Reversing Network Protocols is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reversing Network Protocols use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Reversing Network Protocols?

Skills that share tags, products or a category with Reversing Network Protocols: Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars), Net (zhinkgit/embeddedskills, 734 stars) and Performing Network Forensics With Wireshark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reversing Network Protocols?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.