Minimax DOCX
poco-ai/poco-claw
Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET).
Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .claude/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .claude/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .agents/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .agents/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .cursor/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .cursor/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/unpacking-protected-binaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .gemini/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .gemini/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills unpacking-protected-binariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .github/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .github/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .opencode/skills/unpacking-protected-binaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "unpacking-protected-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/unpacking-protected-binaries into .opencode/skills/unpacking-protected-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "unpacking-protected-binaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
unpacking-protected-binariesUnpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…
Unpacking Protected Binaries is an agent skill from trilwu/secskills. Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping from memory, and rebuilding the import table with Scylla, pe-sieve, or x64dbg. Use when a binary has high entropy, few imports, unnamed sections, or when analysis tools show almost no code.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with .NET. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Unpacking Protected Binaries loads about 2.1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 869 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 869 words, ~2,126 tokens.
.claude/skills/unpacking-protected-binaries/SKILL.md (or your agent's skills folder).Static unpacking is a trap for anything beyond UPX. The reliable method is to let the program unpack itself, then take the result out of memory. Almost every protector, however sophisticated, must eventually produce executable code in a readable page — that moment is what you are waiting for.
Run protected samples only in a contained environment; see analyzing-malware.
binwalk -E shows uniformly high entropy across most of the fileLoadLibrary, GetProcAddress)UPX0/.themida/.vmp0analyzing-malware for containment,
triage, and IOC output; come back here for the unpacking stepanalyzing-dotnet-assemblies, which covers .NET
packers and managed memory dumping specificallyanalyzing-binariesbinwalk -Me extraction is a different job; see
analyzing-binariesThe response differs enormously between a commodity packer and a commercial protector, so spend a minute here.
diec target.exe # Detect It Easy — the best single identifier
rg -a -o 'UPX|MPRESS|Themida|VMProtect|ASPack|Enigma|Obsidium|PECompact' target.exe
binwalk -E target.exe # entropy profile# Structural tells
readpe target.exe # or: rabin2 -S target.exe
# raw size ≈ 0 with large virtual size → section unpacked at runtime
# section marked writable AND executable → self-modifying
# entry point outside the first section → stub in a later section
# TLS callbacks present → code runs BEFORE the entry pointTLS callbacks matter. They execute before the entry point, so a debugger set to break at the EP has already run the protector's anti-debug checks. Set the debugger to break on TLS callbacks, not on the entry point.
| Identified as | Approach |
|---|---|
| UPX (unmodified) | upx -d — takes seconds |
| UPX (modified header) | Repair the magic, or unpack dynamically |
| Commodity crypter, custom stub | Dynamic dump at OEP |
| Themida, VMProtect, Enigma | Dump plus heavy import repair; expect virtualized functions to stay virtualized |
| .NET packer | analyzing-dotnet-assemblies |
upx -d target.exe -o unpacked.exe # try first, costs nothing1. Break before the stub runs (TLS callbacks, or the EP if none)
2. Run until the unpacked code exists in memory
3. Find the OEP — the original entry point of the real program
4. Dump the process image
5. Rebuild the import table
6. Fix the PE headers and verify the dump loadsFinding the OEP is the part that takes judgment. Reliable signals:
security_init_cookie, a call to __scrt_common_main, or a
standard prologue. When execution lands somewhere that looks like normal
compiled code rather than obfuscated stub code, you have arrived.GetCommandLine / GetModuleHandle calls early in the real program.x64dbg workflow:
Options → Events → break on TLS callbacks and on system breakpoint
Run, then in the Memory Map set "Break on execute" for the target section
When it breaks, confirm the code looks compiler-generated → that is the OEP# Dump from the debugger at OEP: Scylla (built into x64dbg)
# 1. Attach / already broken at OEP
# 2. Scylla → set OEP → IAT Autosearch → Get Imports
# 3. Fix invalid/unresolved entries, then Dump + Fix Dump
# Or dump externally
pe-sieve /pid <pid> /dmode 3 # dumps and repairs; good for automation
# hollows_hunter for scanning a whole system for unpacked/injected modulesImport repair is where most dumps fail. Packers replace the import table with a runtime-resolved stub, so a raw dump has API calls pointing into the packer's own thunk area. Scylla's IAT search finds the resolved table; when it returns unresolved entries, that usually means:
Verify the dump before analyzing it:
readpe dumped.exe | head -30 # sane headers, correct EP
rabin2 -i dumped.exe | head -20 # imports resolve to real API names
# The strongest test: does it run, or does a decompiler produce sane output?Themida, VMProtect, Enigma, and similar do more than pack. Expect:
The practical decision: if only a few functions are virtualized, dump and analyze everything else, then handle those functions dynamically — hook their inputs and outputs rather than reading their logic. That answers "what does it do" without defeating the VM.
Some samples never fully unpack in one place: they decrypt individual functions on demand and re-encrypt after use, or they run entirely from a JIT-style buffer.
upx -d failed, so it isn't UPX." Modified UPX headers are the most
common commodity evasion. Check the section names and stub pattern.analyzing-malware — containment, capability model, IOCs; the workflow this fits intoanalyzing-binaries — post-unpacking analysis and anti-analysis handlinganalyzing-dotnet-assemblies — .NET packers and managed dumping© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/unpacking-protected-binaries of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Unpacking Protected Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Unpacking Protected Binaries this skilltrilwu/secskills | 157 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Minimax DOCXpoco-ai/poco-claw | 1.4k | 7 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Microsoft Skill CreatorMicrosoftDocs/mcp | 1.9k | 3 repos | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | |
| Speckit ConstitutionWeihanLi/WeihanLi.Common | 242 | 12 repos | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Copilot Session Failure Analysisdotnet/maui | 23k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Update .NET OS Packagesdotnet/core | 22k | — | ~2.3k | Automated safety check: Pass | MIT |
poco-ai/poco-claw
Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET).
MicrosoftDocs/mcp
Create agent skills for Microsoft technologies using official documentation.
WeihanLi/WeihanLi.Common
Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.
dotnet/maui
Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.
dotnet/core
Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.
MicrosoftDocs/mcp
Find working code samples, verify API signatures, and fix Microsoft SDK errors using official docs.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…. Unpacking Protected Binaries is an agent skill from trilwu/secskills.NET packers — by finding the original entry point, dumping from memory, and rebuilding the import table with Scylla, pe-sieve, or x64dbg.
Unpacking Protected Binaries fits situations like: A binary has high entropy; unnamed sections; analysis tools show almost no code.
Run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/unpacking-protected-binaries in trilwu/secskills) into .claude/skills/unpacking-protected-binaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a codex`. Or copy the skill folder (secskills-core/skills/unpacking-protected-binaries in trilwu/secskills) into .agents/skills/unpacking-protected-binaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unpacking-protected-binaries, .gemini/skills/unpacking-protected-binaries, .github/skills/unpacking-protected-binaries and .opencode/skills/unpacking-protected-binaries in your project.
Going by SKILL.md and its folder, Unpacking Protected Binaries needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Unpacking Protected Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Unpacking Protected Binaries: Minimax DOCX (poco-ai/poco-claw, 1.4k stars), Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars), Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars) and Copilot Session Failure Analysis (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.