Root Cause Investigation
garrytan/gstack
Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.
A skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…
$ npx skills add vricosti/ruzu-emu --skill decompilation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vricosti/ruzu-emu decompilation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/decompilation .claude/skills/decompilation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .claude/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vricosti/ruzu-emu --skill decompilation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vricosti/ruzu-emu decompilation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/decompilation .agents/skills/decompilation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .agents/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vricosti/ruzu-emu --skill decompilation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vricosti/ruzu-emu decompilation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/decompilation .cursor/skills/decompilation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .cursor/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vricosti/ruzu-emu.git --path .agents/skills/decompilation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vricosti/ruzu-emu --skill decompilation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vricosti/ruzu-emu decompilation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/decompilation .gemini/skills/decompilation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .gemini/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vricosti/ruzu-emu decompilationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vricosti/ruzu-emu --skill decompilation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/decompilation .github/skills/decompilation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .github/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vricosti/ruzu-emu --skill decompilation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vricosti/ruzu-emu decompilation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/decompilation .opencode/skills/decompilation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "decompilation" agent skill from https://github.com/vricosti/ruzu-emu/tree/main/.agents/skills/decompilation into .opencode/skills/decompilation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "decompilation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
decompilationA skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…
Decompilation is an agent skill from vricosti/ruzu-emu. Use this skill when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT call address resolves to, computing the correct NSO offset from a runtime PC, or diffing a guest binary's behavior. Trigger phrases include "decompile", "extract NSO", "what symbol is at PC ...", "which function does this PLT call", "Switch / NSP / NCA / NSO", "GOT entry", "find imports", "audio renderer addresses", "PLT[N]"…
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts (for example `scripts/_nso_common.py`, `scripts/disasm.py` and `scripts/extract_nsp.sh`).
The repository describes itself as: Switch emulator written in rust and ported with LLMs initally from yuzu/eden. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit ac8674b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 9 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Decompilation loads about 1.1k tokens when it runs. Until then it costs about 184 tokens; SKILL.md has 330 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from vricosti/ruzu-emu at commit ac8674b, republished under its GPL-3.0 licence (© vricosti). 330 words, ~1,145 tokens.
.claude/skills/decompilation/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.A toolbox for extracting and reverse-engineering Switch binaries (.NSP) so you can identify exactly which library function a runtime address resolves to.
ARM PLT analysis has 3 separate off-by-N traps:
add ip, pc, #N reads PC as current_pc + 8 (pipeline)Never guess the base address. Always verify by byte-pattern match: dump runtime bytes at a known PC, then locate those exact bytes inside the decompressed NSO sections. The base = runtime_addr - found_offset.
scripts/| Script | Purpose |
|---|---|
extract_nsp.sh <nsp_path> <out_dir> | Run hactool to extract NSP → NCAs → ExeFS (main + sdk + subsdk*) |
nso_parse.py <nso_path> | Print NSO header, sections, dynsym/dynstr/JMPREL info |
find_base.py <nso_path> <runtime_addr> <runtime_bytes_hex> | Verify NSO load base by byte-pattern search |
find_symbol.py <nso_path> --pc <runtime_addr> --base <base> | Given a runtime PC of a PLT call, find the resolved symbol name |
lookup_imports.py <nso_path> [filter] | List imported functions (optional regex filter, e.g. "audio") |
disasm.py <bytes_hex> <vma> | Capstone-disassemble bytes at VMA |
bases.json)Per-project file recording each NSO's measured load base. Keep this file in the project root (not in the skill dir) so it lives with the investigation. Example structure:
{
"MK8D 0100152000022000 v0": {
"_notes": "Mario Kart 8 Deluxe — base addresses verified by byte-pattern match",
"main": "0x00206000",
"_subsdk0": "TBD",
"_sdk": "TBD"
}
}The scripts accept --base <hex> directly OR --game-key <key> + --registry <path> to look up.
Given runtime PC of bl <addr> in the JIT trace:
# 1. Extract once (cache in /tmp or under project)
~/.agents/skills/decompilation/scripts/extract_nsp.sh "$NSP" /tmp/<game>_extract
# 2. Dump runtime bytes near a KNOWN PC via ruzu's RUZU_DUMP_MEM_AT_FIRST_SVC knob
# (or any equivalent process-memory dumper). Get e.g. 16 bytes at the known PC.
# 3. Verify base — REQUIRED before any offset math
~/.agents/skills/decompilation/scripts/find_base.py \
/tmp/<game>_extract/exefs/main 0x71EE40 "00009fe701a080e00a00a0e1f50215eb"
# → prints: base = 0x00206000
# 4. Look up the symbol behind the PLT call
~/.agents/skills/decompilation/scripts/find_symbol.py \
/tmp/<game>_extract/exefs/main --pc 0xc6064c --base 0x00206000
# → prints: PLT call at runtime 0xc6064c → GOT slot 0xCCC6A4 → JMPREL[323] → sym[455]
# = _ZN2nn5audio6AddAuxEPNS0_19AudioRendererConfigEPNS0_7AuxTypeE...
# = nn::audio::AddAux(...)# List all `nn::audio::*` imports
~/.agents/skills/decompilation/scripts/lookup_imports.py \
/tmp/<game>_extract/exefs/main 'nn::audio'hactool from /usr/local/bin)hactool binary (apt install — see /home/vricosti/Dev/emulators/hactool_*.deb if reinstalling)~/.switch/prod.keys (symlink from ruzu's keys location: ~/.local/share/ruzu/keys/prod.keys)lz4, capstone (install via pip install --user --break-system-packages lz4 capstone if missing)© vricosti, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (scripts) in .agents/skills/decompilation of vricosti/ruzu-emu.
Open the folder on GitHubat commit ac8674b
Decompilation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Decompilation this skillvricosti/ruzu-emu | 172 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | |
| Root Cause Investigationgarrytan/gstack | 136k | — | ~12k | Automated safety check: Notes | MIT | |
| Osint Investigationaffaan-m/ECC | 276k | — | ~5.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Binary Diffsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Binary Analysis Patternswshobson/agents | 40k | 8 repos | ~2k | Automated safety check: Pass | MIT | |
| Investigate CIClickHouse/ClickHouse | 50k | — | ~11k | Automated safety check: Notes | Apache-2.0 |
garrytan/gstack
Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.
affaan-m/ECC
Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.
sickn33/agentic-awesome-skills
Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.
wshobson/agents
Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition.
ClickHouse/ClickHouse
Investigate a ClickHouse CI failure end-to-end from a PR or S3 report URL.
ClickHouse/ClickHouse
Extract the inner ELF from a ClickHouse self-extracting clickhouse binary, including when its architecture differs from the host (e.g.
A skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…. Decompilation is an agent skill from vricosti/ruzu-emu. Use this skill when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT call address resolves to, computing the correct NSO offset from a runtime PC, or diffing a guest binary's behavior.
Decompilation fits situations like: investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool; parsing NSO format (sections; identifying which symbol a PLT call address resolves to; computing the correct NSO offset from a runtime PC.
Run `npx skills add vricosti/ruzu-emu --skill decompilation -a claude-code`. Or copy the skill folder (.agents/skills/decompilation in vricosti/ruzu-emu) into .claude/skills/decompilation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vricosti/ruzu-emu --skill decompilation -a codex`. Or copy the skill folder (.agents/skills/decompilation in vricosti/ruzu-emu) into .agents/skills/decompilation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vricosti/ruzu-emu --skill decompilation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/decompilation, .gemini/skills/decompilation, .github/skills/decompilation and .opencode/skills/decompilation in your project.
Going by SKILL.md and its folder, Decompilation needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (pip). Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Decompilation is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Decompilation: Root Cause Investigation (garrytan/gstack, 136k stars), Osint Investigation (affaan-m/ECC, 276k stars), Binary Diff (sickn33/agentic-awesome-skills, 47k stars) and Binary Analysis Patterns (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vricosti (a GitHub user) maintains it in vricosti/ruzu-emu, which has 172 GitHub stars. The repository was last updated on October 7, 2026.
Source: vricosti/ruzu-emu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.