Agent skill

Re

by vgrichina in vgrichina/re-skill

Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web.

MITAuto-check passedSecurity

Install Re

skills CLI
$ npx skills add vgrichina/re-skill --skill re -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vgrichina/re-skill re --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re
GitHub stars
166
Token cost
~2.7k tokens
SKILL.md length
805 words
Files
8
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web.

  • Works in 5 steps: Run 2-3 tool calls → Write findings to REVERSE.md immediately… → Add new addresses to labels.csv… → …
  • Working on a binary RE project with REVERSE.md and tools/ directory
  • SKILL.md covers Live context, Dispatch, Task categories and Knowledge base, plus 9 more sections
  • Runs Shell scripts from its folder; calls python3

What it does

Re is an agent skill from vgrichina/re-skill. Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web. Use when working on a binary RE project with REVERSE.md and tools/ directory.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `README.md`, `dead_ends_template.md` and `install.sh`).

It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Claude Code skill for reverse engineering retro games — disassemble, annotate, extract assets, web port. The licence is MIT.

When your agent uses it

  • Working on a binary RE project with REVERSE.md and tools/ directory
  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re”

Requirements

  • Python 3
  • A Bash shell
  • Pre-approved tools (allowed-tools): Read, Edit, Write, Glob, Grep, Bash(python3 tools/*), Bash(git log*), Bash(git status*), Bash(git diff*), Bash(grep*), Bash(head*), Bash(ls*)

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run 2-3 tool calls
  2. Write findings to REVERSE.md immediately — do NOT batch all investigation before writing
  3. Add new addresses to labels.csv (addr,name,comment)
  4. Repeat: more tool calls -> write, until task fully understood
  5. Mark [x], add new [ ] discoveries

What it can do on your machine

Read from SKILL.md and the folder at commit 64c3bff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Write
    • Glob
    • Grep
    • Bash(python3 tools/*)
    • Bash(git log*)
    • Bash(git status*)
    • Bash(git diff*)
    • Bash(grep*)

    …and 2 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re loads about 2.7k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 805 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vgrichina/re-skill at commit 64c3bff, republished under its MIT licence (© vgrichina). 805 words, ~2,698 tokens.

Download SKILL.mdSave it as .claude/skills/re/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
re
description
Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web. Use when working on a binary RE project with REVERSE.md and tools/ directory.
allowed-tools
Read, Edit, Write, Glob, Grep, Bash(python3 tools/*), Bash(git log*), Bash(git status*), Bash(git diff*), Bash(grep*), Bash(head*), Bash(ls*)
disable-model-invocation
false
argument-hint
[binary-path] or empty to continue

Live context

  • Open tasks: !grep -m 10 '\[ \]' REVERSE.md 2>/dev/null || true
  • Dead ends: !head -50 dead_ends.md 2>/dev/null || true
  • Sessions: !ls re_loop_sessions/ 2>/dev/null | tail -5 || true

Dispatch

$ARGUMENTS given -> bootstrap new project

no $ARGUMENTS -> continue from REVERSE.md

  • Read CLAUDE.md for platform conventions, tool prefix, binary path
  • Pick top unchecked task from ## Next Tasks
  • Skim re_loop_sessions/*.txt (last 3) to avoid repeating work
  • Read dead_ends.md to avoid known dead-end approaches

Task categories

RE investigation (tools/dis.py, xref.py, search_bytes.py, decode_tables.py)

  1. Run 2-3 tool calls
  2. Write findings to REVERSE.md immediately — do NOT batch all investigation before writing
  3. Add new addresses to labels.csv (addr,name,comment)
  4. Repeat: more tool calls -> write, until task fully understood
  5. Mark [x], add new [ ] discoveries

Web port fix (web/ files)

  1. Read the relevant web/ file first
  2. Apply fix — values are already documented in REVERSE.md
  3. Update REVERSE.md to note what changed
  4. If new asset type decoded -> add section to web/catalog.html

Documentation (docs/ directory)

  1. docs/architecture_exe.md — binary layout, segment/bank boundaries, call graph with entry points + file offsets, module map, per-turn execution flow, data flow, shared data regions
  2. docs/architecture_web.md — JS module graph with exports + dependencies, EXE->web mapping table, game loop flow, state machine with transitions Both files must exist before the project is considered complete.

Knowledge base

labels.csv accumulates across sessions. All disasm tools load it automatically.

  • Flat (DOS/unpacked): offset,name,comment — offset with 0x prefix e.g. 0x25DE9,main,entry point
  • Banked ROM (NES/GB): bank,addr,name,comment — addr hex no prefix e.g. 0,C070,Reset,
  • DS-relative (DOS): DS:offset_hex,name,comment e.g. DS:0xCEAC,dt_physics,timestep

The comment column is optional but encouraged for non-obvious addresses.

Stuck rule

After 10 tool calls with no progress on a single task:

  1. Append entry to dead_ends.md: tried / why-failed / better-approach / session number
  2. Split stuck task into 2-3 smaller sub-tasks in REVERSE.md Next Tasks
  3. Mark original [x] "Split into sub-tasks" — move on

If the same task is attempted across 3+ sessions without progress, escalate: the task decomposition is wrong, rethink the approach entirely.

Common gotchas (from past projects)

  • MZ relocations break byte-pattern searches: raw search_bytes.py misses far calls/jumps because segment values are patched at load time. Use xref.py which understands relocation tables.
  • Decompress before disassembly: compressed binaries are opaque. Always identify and unpack first (Ph2). All subsequent work uses the unpacked image.
  • Two-level pointer tables: flat decode shows pointer values, not the data they point to. Use decode_tables.py --follow to chase pointers to sub-tables.
  • Tile index ≠ VRAM address: many platforms use attribute/remapping tables between tile indices and actual video memory. Validate tile rendering against emulator, don't assume direct mapping.
  • Don't search for composed text: menu text, scores, and dialog are often built at runtime from format strings + data tables. Trace from code control flow, not string patterns.
  • Bank-aware xref: on banked ROMs (NES/GB), cross-bank byte matches are false positives. Always pass the bank filter to xref.py.
  • WRAM tilemap stride varies: Game Boy WRAM buffers may use 20-col stride, not the standard 32-col VRAM stride. Verify actual layout.
  • Struct stride off-by-one: a wrong stride corrupts every subsequent struct in the table. Cross-check decoded fields against emulator memory dump.
Show full SKILL.md (272 more words)Show less

Tool rules

  • Read not cat · Grep not grep · Glob not ls/find
  • Write a .py file first, then run it — never inline python3 -c
  • No third-party disassemblers (no radare2, Ghidra, ndisasm, mgbdis)
  • All tool scripts live in tools/ — invoke as python3 tools/dis.py ...

Tool CLI reference

All tools auto-load labels.csv for annotation. Prefix is python3 tools/.

Core tools (signatures adapt per platform):

dis.py <addr> [lines]                      # flat binary: file offset (hex)
dis.py <bank> <addr> [nbytes]              # banked ROM: bank + addr
dis.py <file> <addr> [nbytes] --hunk N     # Amiga hunk: target specific hunk
xref.py <addr>                             # find all refs (calls, jumps, loads, stores)
xref.py <addr> [bank]                      # banked: optional bank filter
xref.py <addr> --code                      # scan known code segments only (faster)
xref.py <addr> -r START END                # restrict scan to file range
xref.py <addr> -c N                        # show N bytes of context
search_bytes.py <hex> [--context N] [--disasm [N]]  # hex can be spaced or not
decode_tables.py <addr> <count> <fmt>      # fmt: u8/s8/u16/s16/u32/ptr16/farptr/q8/b8/nullstr
decode_tables.py <addr> <count> struct:<n>:<f,f,...>  # struct with field layout
decode_tables.py <addr> <count> <fmt> --follow N FMT  # two-level pointer tables
extract_tiles.py                           # decode tiles/sprites to gfx/ PNGs
render_screen.py                           # composite screen to gfx/screen_NNN.png

Platform extras (built as needed):

decompress.py                   # reverse-engineered decompressor (Ph2)
seg_offset.py                   # convert between SEG:OFF and file/DS offsets (DOS)
ds_lookup.py <exe> <addr> [-n N] [-s|-w|-d|-f32|-f64]  # DS-relative memory viewer
strings_dump.py [-g "pattern"] [-r START END]           # string scanner with grep/range
struct_dump.py                  # pre-configured struct dumper
find_callers.py <addr>          # find all callers (near+far), complements xref.py
palette_dump.py [--accent] [--scan]                     # palette extractor
a4resolve.py <file> [--dump | -- <offset>]              # Amiga A4-relative library resolver
hunk_scan.py / hunk_loader.py   # Amiga hunk executable parser
adf_extract.py / adf_debug.py   # Amiga ADF disk image tools
check_bank_refs.py              # verify far references point to valid banks (NES/GB)
extract_rom_banks.py            # split MBC1/3 ROM banks (GB)
render_sprites.py               # render sprite sheets with palette/scale options
render_level.py                 # full level/map renderer (Ph6)
render_compare.py IMG1 IMG2 [--diff]  # side-by-side pixel comparison
compare_frames.py               # pixel-diff emulator vs web port (Ph6)

Scriptable emulator (Ph5.5, python3 -m tools.emu or python3 tools/emu):

--dump-regs                     # load binary, print initial state
--boot-test                     # run until first OS call or N instructions
--run-func LABEL                # jump to labeled function with pre-set state
--break ADDR                    # breakpoint, dump registers + stack
--trace                         # print each instruction
--keys STEP:SCANCODE:ASCII      # inject key input at step N
--dump-screen FILE.png          # screen capture
--compare                       # export CSV for diffing against web port

Scaffolded project structure

REVERSE.md            # data-range map, findings, task list, verification checklist
labels.csv            # addr,name,comment — grows across sessions
dead_ends.md          # stuck log — avoids repeating failed approaches
re_loop.sh            # autonomous session driver
re_loop_sessions/     # session logs
tools/
  instruction_set.py  # CPU opcode database (built per platform)
  dis.py              # targeted disassembler (auto-loads labels.csv)
  search_bytes.py     # byte pattern search
  xref.py             # cross-reference finder
  decode_tables.py    # struct/table decoder
  extract_tiles.py    # graphics decoder
  render_screen.py    # screen compositor
  emu/                # scriptable emulator (Ph5.5, optional)
gfx/                  # extracted graphics
web/
  index.html          # game reimplementation
  catalog.html        # asset browser for visual validation
docs/
  architecture_exe.md # binary layout, call graph, data flow
  architecture_web.md # JS modules, EXE-to-web mapping

Platform conventions

Address notation and labels.csv format vary by platform. Set in CLAUDE.md during bootstrap.

  • DOS flat/MZ: file offsets 0xXXXXX, DS-relative DS:0xXXXX, segment:offset SEG:OFF. Tools: seg_offset.py, ds_lookup.py. FPU emulation (INT 34h-3Dh) if Borland.
  • NES/GB banked ROM: bank,addr (addr hex no prefix). WRAM/HRAM labels use bank='*'. Tools: check_bank_refs.py, extract_rom_banks.py.
  • Amiga hunk: hunk-relative offsets, A4-relative library calls. Tools: hunk_scan.py, a4resolve.py, adf_extract.py.

re_loop.sh (scaffolded for user, not agent-invoked)

Scaffolded into the project from re_loop_template.sh during bootstrap. The user runs it from the terminal to drive autonomous sessions — the agent never invokes it directly.

The ALLOWED_TOOLS in re_loop.sh should include wildcard patterns for on-the-fly scripts: Bash(python3 tools/analyze_*), Bash(python3 tools/audit_*), Bash(python3 tools/check_*), Bash(python3 tools/gen_*), Bash(python3 tools/dump_*).

Verification checkpoints

Mark these in REVERSE.md as validation happens:

  • Ph3: 3+ functions traced and cross-checked against emulator trace
  • Ph4: 5+ sprites/tiles extracted and visually compared to emulator
  • Ph5: key data struct confirmed in emulator memory dump, all fields match
  • Ph6: full game session played, no major logic gaps found
  • Ph7: web port pixel-compared against emulator screenshots

End of session

  • Mark completed task [x]
  • Add newly discovered unknowns as [ ] in the appropriate ### sub-section
  • Last line: SESSION_SUMMARY: <one line>

See phases.md when bootstrapping a new project.

© vgrichina, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in the repository root of vgrichina/re-skill.

  • SKILL.md
  • LICENSE
  • README.md
  • dead_ends_template.md
  • install.sh
  • phases.md
  • re_loop_template.sh
  • reverse_template.md

Open the folder on GitHubat commit 64c3bff

Compare with similar skills

Re next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re this skillvgrichina/re-skill166—~2.7kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated today
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

Categories

Questions about Re

What does Re do?

Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web. Re is an agent skill from vgrichina/re-skill. Reverse engineering session: disassemble, annotate, extract assets, build emulator, port to web.

When should I use Re?

Re fits situations like: working on a binary RE project with REVERSE.md and tools/ directory; tasks that involve Reverse engineering and malware.

How do I install Re in Claude Code?

Run `npx skills add vgrichina/re-skill --skill re -a claude-code`. Or copy the skill folder (the vgrichina/re-skill repository) into .claude/skills/re in your project. Claude Code loads it when a task matches its description.

How do I install Re in Codex?

Run `npx skills add vgrichina/re-skill --skill re -a codex`. Or copy the skill folder (the vgrichina/re-skill repository) into .agents/skills/re in your project. Codex loads it when a task matches its description.

Can I use Re in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vgrichina/re-skill --skill re -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re, .gemini/skills/re, .github/skills/re and .opencode/skills/re in your project.

What does Re need to run?

Going by SKILL.md and its folder, Re needs a shell for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Read, Edit, Write, Glob, Grep, Bash(python3 tools/*), Bash(git log*), Bash(git status*), Bash(git diff*), Bash(grep*), Bash(head*), Bash(ls*).

Does Re access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re use?

Re is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re?

Skills that share tags, products or a category with Re: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re?

vgrichina (a GitHub user) maintains it in vgrichina/re-skill, which has 166 GitHub stars. The repository was last updated on March 5, 2026.

Source: vgrichina/re-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.