Protocol Reverse Engineering
wshobson/agents
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.
A skill your agent uses when a reverse-engineered table or formula — SBA gauge weights, the damage-cap model, stun values, any per-hit quantity the parser computes — needs verifying against real…
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install villith/relink-logs validating-models-against-logs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .claude/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .claude/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install villith/relink-logs validating-models-against-logs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .agents/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .agents/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install villith/relink-logs validating-models-against-logs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .cursor/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .cursor/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/villith/relink-logs.git --path .claude/skills/validating-models-against-logs--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install villith/relink-logs validating-models-against-logs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .gemini/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .gemini/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install villith/relink-logs validating-models-against-logsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .github/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .github/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add villith/relink-logs --skill validating-models-against-logs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install villith/relink-logs validating-models-against-logs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/villith/relink-logs.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/validating-models-against-logs .opencode/skills/validating-models-against-logs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "validating-models-against-logs" agent skill from https://github.com/villith/relink-logs/tree/dev/.claude/skills/validating-models-against-logs into .opencode/skills/validating-models-against-logs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-models-against-logs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
validating-models-against-logsA skill your agent uses when a reverse-engineered table or formula — SBA gauge weights, the damage-cap model, stun values, any per-hit quantity the parser computes — needs verifying against real…
Validating Models Against Logs is an agent skill from villith/relink-logs. Use when a reverse-engineered table or formula — SBA gauge weights, the damage-cap model, stun values, any per-hit quantity the parser computes — needs verifying against real gameplay; when pricing ids or values the game data does not author; when tempted to trust a fit from one or two samples; or when about to ask for a live capture round to check derived constants.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Relink Logs lets you track damage statistics with a nice overlay DPS meter for Granblue Fantasy: Relink. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8251151. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Validating Models Against Logs loads about 1.7k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 888 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from villith/relink-logs at commit 8251151, republished under its MIT licence (© villith). 888 words, ~1,693 tokens.
.claude/skills/validating-models-against-logs/SKILL.md (or your agent's skills folder).src-tauri/logs.db (the dev copy — the AppData one is empty) is not just
history: it is a labeled measurement corpus. Encounters store the raw
event log, and the hook-read fields in it are ground-truth labels a model can
be scored against offline, hit by hit: captioned SBA gains
(SbaGainCause::Skill(action)), the per-hit damage_cap on every
DamageEvent, buff lists, stun deltas. Core principle: exhaust the corpus
before asking for a live round. The SBA weight table went to 68/68 verified
(character, action) values with zero live play; treat a proposed capture
session as a smell that the corpus hasn't been mined yet.
sba_weights.rs / assets/*.json shape).src-tauri/examples/ that replays
EVERY log and scores model vs ground truth per (character, id). Give it
three modes: corpus-wide sweep, single-log detail dump (--dump-log — for
identifying what an unknown id physically IS from its damage signature and
company), and targeted-id measurement.verified/high/med/low), its source, n, and the log ids it was
measured from — so the next game patch's re-derivation re-verifies
mechanically (the build_final.py MEAS pattern) instead of re-arguing.Encounter::from_blob(&blob) → repopulate_event_log() →
event_log(). Slot→character via
sba_inference::character_aliases(&encounter.player_data) — identity comes
from the roster, NOT the event log, and must alias both raw actor_index and
slot keys. Open sqlite read-only. Copy the gather pattern from
sba_share_check.rs / sba_grant_scan.rs.LOCAL_READ_FRACTION) — measure on captioned local
slots, validate models on them first, then check remotes.--release; run tests as
cargo test -p gbfr-logs --lib <module> in DEBUG — the release test binary
inherits the admin manifest and dies with "requires elevation" (os 740).sba_grant_scan (targeted measurement, --dump-log,
--taken-lag), sba_share_check (sweep + worklist + whole-fight
tracking), sba_infer_score (shipped-pipeline replay scored against
captioned truth), the cap_* family (per-hit damage_cap ground truth).Only when the corpus provably cannot discriminate (both branches of a stack-or-replace hypothesis produce identical stored logs; a character/id appears in no captioned local slot). Then: ONE targeted round with a written checklist, a control measurement on the LOCAL slot first (a failed control voids the experiment), single-variable deltas, and the anchor in view to pin K.
| Mistake | Reality |
|---|---|
| "We need a capture session to verify this" | 1,800+ logs already hold labeled per-hit ground truth. Mine them first; live time is the scarcest resource. |
| Trusting an n=1/n=2 solve | Small-n indirect fits have been off by ∞ (0.16 vs true 0). Worklist it; measure it from captioned locals. |
| Widening tolerance / fitting a fudge factor to make numbers pass | Every mismatch is a missing input, wrong constant, or capture bug. Resolve by RE or mark unsupported — never curve-fit. |
| Reporting "no signal → value unknown" | Absence over stated-N hits IS the measurement: the value is 0. |
| Reading sum-based statistics as model drift | Unobservable contamination inflates sums, not medians. Compare both; investigate the gap before blaming the model. |
| A scan's null result reported as "not in the data" | Say what you searched and what that method cannot see (case/spelling-insensitive sweeps: spartsGageRate hid from every spArtsRate grep). |
| One-off scratch scripts for scoring | Commit the example. It is the patch-day regression gate and the next id's curation tool. |
© villith, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/validating-models-against-logs of villith/relink-logs.
Open the folder on GitHubat commit 8251151
Validating Models Against Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Validating Models Against Logs this skillvillith/relink-logs | 157 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Protocol Reverse Engineeringwshobson/agents | 40k | 8 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Reverse Engineering Malware With Ghidramukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Dsl Vm Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Protocol Reversezhaoxuya520/reverse-skill | 40k | 2 repos | ~620 | Automated safety check: Warn | MIT | |
| macOS Reversezhaoxuya520/reverse-skill | 40k | 2 repos | ~366 | Automated safety check: Pass | MIT |
wshobson/agents
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.
mukul975/Anthropic-Cybersecurity-Skills
Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to study internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C…
sickn33/agentic-awesome-skills
Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
sickn33/agentic-awesome-skills
Authorized reverse engineering of custom binary protocols, Protobuf/gRPC schemas, WebSocket frames, and PCAP-driven protocol recovery.
villith/relink-logs
A skill your agent uses when building, compiling, packaging, or producing an installer/MSI for the GBFR Logs Tauri app, or when a build fails with "path matching hook.dll not found" or build.rs…
villith/relink-logs
A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…
villith/relink-logs
A skill your agent uses when working on, discussing, reviewing or debugging the Relink Logs analysis view (the log viewer's Analysis mode) — pins, drilling, grouping, the table/timeline/events…
A skill your agent uses when a reverse-engineered table or formula — SBA gauge weights, the damage-cap model, stun values, any per-hit quantity the parser computes — needs verifying against real…. Validating Models Against Logs is an agent skill from villith/relink-logs. Use when a reverse-engineered table or formula — SBA gauge weights, the damage-cap model, stun values, any per-hit quantity the parser computes — needs verifying against real gameplay; when pricing ids or values the game data does not author; when tempted to trust a fit from one or two samples; or when about to ask for a live capture round to check derived constants.
Validating Models Against Logs fits situations like: A reverse-engineered table; formula — SBA gauge weights; the damage-cap model; any per-hit quantity the parser computes — needs verifying against real gameplay.
Run `npx skills add villith/relink-logs --skill validating-models-against-logs -a claude-code`. Or copy the skill folder (.claude/skills/validating-models-against-logs in villith/relink-logs) into .claude/skills/validating-models-against-logs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add villith/relink-logs --skill validating-models-against-logs -a codex`. Or copy the skill folder (.claude/skills/validating-models-against-logs in villith/relink-logs) into .agents/skills/validating-models-against-logs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add villith/relink-logs --skill validating-models-against-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-models-against-logs, .gemini/skills/validating-models-against-logs, .github/skills/validating-models-against-logs and .opencode/skills/validating-models-against-logs in your project.
Going by SKILL.md and its folder, Validating Models Against Logs needs the command-line tools its instructions call (cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Validating Models Against Logs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Validating Models Against Logs: Protocol Reverse Engineering (wshobson/agents, 40k stars), Reverse Engineering Malware With Ghidra (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Dsl Vm Reverse (sickn33/agentic-awesome-skills, 47k stars) and Protocol Reverse (zhaoxuya520/reverse-skill, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
villith (a GitHub user) maintains it in villith/relink-logs, which has 157 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 25, 2026.
Source: villith/relink-logs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.