Agent skill

Anti Reversing Techniques

by wshobson in wshobson/agents

Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.

MITAuto-check passedSecurity

Install Anti Reversing Techniques

skills CLI
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents anti-reversing-techniques --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .claude/skills/anti-reversing-techniques && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anti-reversing-techniques
GitHub stars
40k
Token cost
~980 tokens
SKILL.md length
437 words
Files
3 (incl. references)
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.

  • Analyzing malware evasion techniques
  • SKILL.md covers Input / Output, Detailed patterns and worked…, Troubleshooting and Related Skills
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Implementing anti-debugging protections for CTF challenges

What it does

Anti Reversing Techniques is an agent skill from wshobson/agents. Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/advanced-techniques.md` and `references/details.md`).

It sits in Security, covering Reverse engineering and malware and Capture the flag. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.

When your agent uses it

  • Analyzing malware evasion techniques
  • Implementing anti-debugging protections for CTF challenges
  • Reverse engineering packed binaries
  • Building security research tools that need to detect virtualized environments

Example prompts

  • “/anti-reversing-techniques”

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Anti Reversing Techniques loads about 980 tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 437 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~980
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 437 words, ~980 tokens.

Download SKILL.mdSave it as .claude/skills/anti-reversing-techniques/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
anti-reversing-techniques
description
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.

AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis:

  1. Verify authorization: Confirm you have explicit written permission from the software owner, or are operating within a legitimate security context (CTF, authorized pentest, malware analysis, security research)
  2. Document scope: Ensure your activities fall within the defined scope of your authorization
  3. Legal compliance: Understand that unauthorized bypassing of software protection may violate laws (CFAA, DMCA anti-circumvention, etc.)

Legitimate use cases: Malware analysis, authorized penetration testing, CTF competitions, academic security research, analyzing software you own/have rights to

Anti-Reversing Techniques

Understanding protection mechanisms encountered during authorized software analysis, security research, and malware analysis. This knowledge helps analysts bypass protections to complete legitimate analysis tasks.

For advanced techniques, see references/advanced-techniques.md


Input / Output

What you provide:

  • Binary path or sample: the executable, DLL, or firmware image under analysis
  • Platform: Windows x86/x64, Linux, macOS, ARM — affects which checks apply
  • Goal: bypass for dynamic analysis, identify protection type, build detection code, implement for CTF

What this skill produces:

  • Protection identification: named technique (e.g., RDTSC timing check, PEB BeingDebugged) with location in binary
  • Bypass strategy: specific patch addresses, hook points, or tool commands to neutralize each check
  • Analysis report: structured findings listing each protection layer, severity, and recommended bypass
  • Code artifacts: Python/IDAPython scripts, GDB command sequences, or C stubs for bypassing or implementing checks

Detailed patterns and worked examples

Detailed pattern documentation lives in references/details.md. Read that file when the navigation tier above is insufficient.

Show full SKILL.md (191 more words)Show less

Troubleshooting

Detection technique works on x86 but not ARM

RDTSC and CPUID are x86-only. On ARM, use MRS x0, PMCCNTR_EL0 (requires kernel PMU access) or clock_gettime(CLOCK_MONOTONIC). PEB/TEB do not exist on ARM — replace with /proc/self/status (Linux) or task_info (macOS). Rebuild detection logic with platform-specific APIs.

False positive on legitimate debugger or analysis tool

Timing checks fire when Process Monitor or AV hooks inflate syscall latency. Calibrate the threshold at startup: measure the guarded path 3 times and use mean + 3*stddev. For ptrace checks, verify the TracerPid comm name via /proc/<pid>/comm before exiting — it may be an unrelated monitoring tool, not a debugger.

Bypass patch causes crash instead of continuing execution

Before NOPing a conditional jump, trace the "detected" branch fully. If it initializes or frees heap state needed later, patching the jump skips that setup and corrupts state. Instead, patch the comparison operand to the expected "clean" value, or use x64dbg's "Set condition to always false" on the breakpoint rather than modifying bytes.


  • binary-analysis-patterns — static and dynamic analysis workflows for ELF/PE/Mach-O
  • memory-forensics — process memory acquisition, artifact extraction, and live analysis
  • protocol-reverse-engineering — decoding custom binary protocols and encrypted network traffic

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/reverse-engineering/skills/anti-reversing-techniques of wshobson/agents.

  • SKILL.md
  • references/advanced-techniques.md
  • references/details.md

Open the folder on GitHubat commit 46891e7

Compare with similar skills

Anti Reversing Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anti Reversing Techniques compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anti Reversing Techniques this skillwshobson/agents40k—~980Automated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Symbolic Execution Toolsyaklang/hack-skills2.4k—~3kAutomated safety check: PassMIT
Analyzing Binariestrilwu/secskills157—~2.9kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0

Similar skills

  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Symbolic Execution Tools

    yaklang/hack-skills

    Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3k tokensUpdated 27 days ago
    SecurityAuto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Create Sigma Rule

    TracecatHQ/tracecat

    Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…

    3.8k GitHub stars~16k tokensUpdated today
    SecurityAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Anti Reversing Techniques

What does Anti Reversing Techniques do?

Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Anti Reversing Techniques is an agent skill from wshobson/agents. Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.

When should I use Anti Reversing Techniques?

Anti Reversing Techniques fits situations like: analyzing malware evasion techniques; implementing anti-debugging protections for CTF challenges; reverse engineering packed binaries; building security research tools that need to detect virtualized environments.

How do I install Anti Reversing Techniques in Claude Code?

Run `npx skills add wshobson/agents --skill anti-reversing-techniques -a claude-code`. Or copy the skill folder (plugins/reverse-engineering/skills/anti-reversing-techniques in wshobson/agents) into .claude/skills/anti-reversing-techniques in your project. Claude Code loads it when a task matches its description.

How do I install Anti Reversing Techniques in Codex?

Run `npx skills add wshobson/agents --skill anti-reversing-techniques -a codex`. Or copy the skill folder (plugins/reverse-engineering/skills/anti-reversing-techniques in wshobson/agents) into .agents/skills/anti-reversing-techniques in your project. Codex loads it when a task matches its description.

Can I use Anti Reversing Techniques in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill anti-reversing-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anti-reversing-techniques, .gemini/skills/anti-reversing-techniques, .github/skills/anti-reversing-techniques and .opencode/skills/anti-reversing-techniques in your project.

What does Anti Reversing Techniques need to run?

SKILL.md names no scripts, command-line tools or credentials: Anti Reversing Techniques is instructions for the agent only.

Does Anti Reversing Techniques access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Anti Reversing Techniques safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Anti Reversing Techniques use?

Anti Reversing Techniques is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anti Reversing Techniques use?

About 980 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Anti Reversing Techniques?

Skills that share tags, products or a category with Anti Reversing Techniques: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Symbolic Execution Tools (yaklang/hack-skills, 2.4k stars), Analyzing Binaries (trilwu/secskills, 157 stars) and vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anti Reversing Techniques?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.