Agent skill

Decompilation

by vricosti in vricosti/ruzu-emu

A skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…

GPL-3.0Auto-check passed

Install Decompilation

skills CLI
$ npx skills add vricosti/ruzu-emu --skill decompilation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vricosti/ruzu-emu decompilation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vricosti/ruzu-emu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/decompilation .claude/skills/decompilation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
decompilation
GitHub stars
172
Token cost
~1.1k tokens
SKILL.md length
330 words
Files
10 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
GPL-3.0

At a glance

A skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…

  • Investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool
  • SKILL.md covers Critical lesson: ALWAYS verify…, Tools provided in scripts/, Registry (bases.json) and Workflow: identify the symbol…, plus 3 more sections
  • Runs Python and Shell scripts from its folder; calls pip
  • Parsing NSO format (sections

What it does

Decompilation is an agent skill from vricosti/ruzu-emu. Use this skill when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT call address resolves to, computing the correct NSO offset from a runtime PC, or diffing a guest binary's behavior. Trigger phrases include "decompile", "extract NSO", "what symbol is at PC ...", "which function does this PLT call", "Switch / NSP / NCA / NSO", "GOT entry", "find imports", "audio renderer addresses", "PLT[N]"…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts (for example `scripts/_nso_common.py`, `scripts/disasm.py` and `scripts/extract_nsp.sh`).

The repository describes itself as: Switch emulator written in rust and ported with LLMs initally from yuzu/eden. The licence is GPL-3.0.

When your agent uses it

  • Investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool
  • Parsing NSO format (sections
  • Identifying which symbol a PLT call address resolves to
  • Computing the correct NSO offset from a runtime PC

Example prompts

  • “s behavior. Trigger phrases include”
  • “extract NSO”
  • “what symbol is at PC ...”
  • “/decompilation”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit ac8674b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 9 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Decompilation loads about 1.1k tokens when it runs. Until then it costs about 184 tokens; SKILL.md has 330 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~184
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vricosti/ruzu-emu at commit ac8674b, republished under its GPL-3.0 licence (© vricosti). 330 words, ~1,145 tokens.

Download SKILL.mdSave it as .claude/skills/decompilation/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
decompilation
description
Use this skill when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT call address resolves to, computing the correct NSO offset from a runtime PC, or diffing a guest binary's behavior. Trigger phrases include "decompile", "extract NSO", "what symbol is at PC ...", "which function does this PLT call", "Switch / NSP / NCA / NSO", "GOT entry", "find imports", "audio renderer addresses", "PLT[N]". Strongly recommended whenever an investigation needs to map runtime addresses to imported symbol names — manual offset math is error-prone (PLT layout has multiple correct candidates and ARM PC+8 traps).

Decompilation skill — Nintendo Switch NSO

A toolbox for extracting and reverse-engineering Switch binaries (.NSP) so you can identify exactly which library function a runtime address resolves to.

Critical lesson: ALWAYS verify the base address before computing offsets

ARM PLT analysis has 3 separate off-by-N traps:

  • ARM add ip, pc, #N reads PC as current_pc + 8 (pipeline)
  • PLT[0] may be 4 bytes (single LDR) OR 20 bytes (standard stub) depending on toolchain
  • NSO load base is NOT 0x200000 by default — it's determined at runtime and must be measured

Never guess the base address. Always verify by byte-pattern match: dump runtime bytes at a known PC, then locate those exact bytes inside the decompressed NSO sections. The base = runtime_addr - found_offset.

Tools provided in scripts/

ScriptPurpose
extract_nsp.sh <nsp_path> <out_dir>Run hactool to extract NSP → NCAs → ExeFS (main + sdk + subsdk*)
nso_parse.py <nso_path>Print NSO header, sections, dynsym/dynstr/JMPREL info
find_base.py <nso_path> <runtime_addr> <runtime_bytes_hex>Verify NSO load base by byte-pattern search
find_symbol.py <nso_path> --pc <runtime_addr> --base <base>Given a runtime PC of a PLT call, find the resolved symbol name
lookup_imports.py <nso_path> [filter]List imported functions (optional regex filter, e.g. "audio")
disasm.py <bytes_hex> <vma>Capstone-disassemble bytes at VMA

Registry (bases.json)

Per-project file recording each NSO's measured load base. Keep this file in the project root (not in the skill dir) so it lives with the investigation. Example structure:

json
{
  "MK8D 0100152000022000 v0": {
    "_notes": "Mario Kart 8 Deluxe — base addresses verified by byte-pattern match",
    "main":     "0x00206000",
    "_subsdk0": "TBD",
    "_sdk":     "TBD"
  }
}

The scripts accept --base <hex> directly OR --game-key <key> + --registry <path> to look up.

Workflow: identify the symbol behind a PLT call

Given runtime PC of bl <addr> in the JIT trace:

bash
# 1. Extract once (cache in /tmp or under project)
~/.agents/skills/decompilation/scripts/extract_nsp.sh "$NSP" /tmp/<game>_extract

# 2. Dump runtime bytes near a KNOWN PC via ruzu's RUZU_DUMP_MEM_AT_FIRST_SVC knob
#    (or any equivalent process-memory dumper). Get e.g. 16 bytes at the known PC.

# 3. Verify base — REQUIRED before any offset math
~/.agents/skills/decompilation/scripts/find_base.py \
    /tmp/<game>_extract/exefs/main 0x71EE40 "00009fe701a080e00a00a0e1f50215eb"
# → prints: base = 0x00206000

# 4. Look up the symbol behind the PLT call
~/.agents/skills/decompilation/scripts/find_symbol.py \
    /tmp/<game>_extract/exefs/main --pc 0xc6064c --base 0x00206000
# → prints: PLT call at runtime 0xc6064c → GOT slot 0xCCC6A4 → JMPREL[323] → sym[455]
#           = _ZN2nn5audio6AddAuxEPNS0_19AudioRendererConfigEPNS0_7AuxTypeE...
#           = nn::audio::AddAux(...)

Workflow: identify imports by pattern

bash
# List all `nn::audio::*` imports
~/.agents/skills/decompilation/scripts/lookup_imports.py \
    /tmp/<game>_extract/exefs/main 'nn::audio'

When NOT to use this skill

  • Reverse-engineering host-side (x86) code — use objdump directly
  • Pure black-box behavioural debugging where the function name is already known
  • Tool installation problems — call hactool directly first to confirm it works (hactool from /usr/local/bin)

Dependencies

  • hactool binary (apt install — see /home/vricosti/Dev/emulators/hactool_*.deb if reinstalling)
  • Switch prod.keys at ~/.switch/prod.keys (symlink from ruzu's keys location: ~/.local/share/ruzu/keys/prod.keys)
  • Python: lz4, capstone (install via pip install --user --break-system-packages lz4 capstone if missing)

© vricosti, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts) in .agents/skills/decompilation of vricosti/ruzu-emu.

  • SKILL.md
  • scripts/.gitignore
  • scripts/_nso_common.py
  • scripts/disasm.py
  • scripts/extract_nsp.sh
  • scripts/find_base.py
  • scripts/find_callers.py
  • scripts/find_symbol.py
  • scripts/lookup_imports.py
  • scripts/nso_parse.py

Open the folder on GitHubat commit ac8674b

Compare with similar skills

Decompilation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Decompilation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Decompilation this skillvricosti/ruzu-emu172—~1.1kAutomated safety check: PassGPL-3.0
Root Cause Investigationgarrytan/gstack136k—~12kAutomated safety check: NotesMIT
Osint Investigationaffaan-m/ECC276k—~5.7kAutomated safety check: PassCC-BY-SA-4.0
Binary Diffsickn33/agentic-awesome-skills47k1 repos~2.1kAutomated safety check: PassMIT
Binary Analysis Patternswshobson/agents40k8 repos~2kAutomated safety check: PassMIT
Investigate CIClickHouse/ClickHouse50k—~11kAutomated safety check: NotesApache-2.0

Similar skills

  • Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.

    136k GitHub stars~12k tokensUpdated today
    DevelopmentAuto-check: notes
  • Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.

    276k GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed
  • Binary Diff

    sickn33/agentic-awesome-skills

    Cross-version binary symbol migration: diff updated binaries, recover function names without PDBs, and propagate annotations after software updates using BinDiff-style tooling.

    47k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition.

    40k GitHub starsUsed in 8 repos~2k tokens
    SecurityAuto-check passed
  • Investigate CI

    ClickHouse/ClickHouse

    Investigate a ClickHouse CI failure end-to-end from a PR or S3 report URL.

    50k GitHub stars~11k tokensUpdated today
    DatabasesAuto-check: notes
  • Decompress Binary

    ClickHouse/ClickHouse

    Extract the inner ELF from a ClickHouse self-extracting clickhouse binary, including when its architecture differs from the host (e.g.

    50k GitHub stars~1.1k tokensUpdated today
    DatabasesAuto-check passed

Questions about Decompilation

What does Decompilation do?

A skill your agent uses when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT…. Decompilation is an agent skill from vricosti/ruzu-emu. Use this skill when investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool, parsing NSO format (sections, dynsym, dynstr, JMPREL), identifying which symbol a PLT call address resolves to, computing the correct NSO offset from a runtime PC, or diffing a guest binary's behavior.

When should I use Decompilation?

Decompilation fits situations like: investigating Nintendo Switch binaries (NSP/NCA/NSO) — extracting code via hactool; parsing NSO format (sections; identifying which symbol a PLT call address resolves to; computing the correct NSO offset from a runtime PC.

How do I install Decompilation in Claude Code?

Run `npx skills add vricosti/ruzu-emu --skill decompilation -a claude-code`. Or copy the skill folder (.agents/skills/decompilation in vricosti/ruzu-emu) into .claude/skills/decompilation in your project. Claude Code loads it when a task matches its description.

How do I install Decompilation in Codex?

Run `npx skills add vricosti/ruzu-emu --skill decompilation -a codex`. Or copy the skill folder (.agents/skills/decompilation in vricosti/ruzu-emu) into .agents/skills/decompilation in your project. Codex loads it when a task matches its description.

Can I use Decompilation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vricosti/ruzu-emu --skill decompilation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/decompilation, .gemini/skills/decompilation, .github/skills/decompilation and .opencode/skills/decompilation in your project.

What does Decompilation need to run?

Going by SKILL.md and its folder, Decompilation needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (pip). Our summary lists: Python 3; A Bash shell.

Does Decompilation access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Decompilation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Decompilation use?

Decompilation is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Decompilation use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Decompilation?

Skills that share tags, products or a category with Decompilation: Root Cause Investigation (garrytan/gstack, 136k stars), Osint Investigation (affaan-m/ECC, 276k stars), Binary Diff (sickn33/agentic-awesome-skills, 47k stars) and Binary Analysis Patterns (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Decompilation?

vricosti (a GitHub user) maintains it in vricosti/ruzu-emu, which has 172 GitHub stars. The repository was last updated on October 7, 2026.

Source: vricosti/ruzu-emu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.