Ctf Malware
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents anti-reversing-techniques --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .claude/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .claude/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniquesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents anti-reversing-techniques --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .agents/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .agents/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents anti-reversing-techniques --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .cursor/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .cursor/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/reverse-engineering/skills/anti-reversing-techniques--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents anti-reversing-techniques --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .gemini/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .gemini/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents anti-reversing-techniquesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .github/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .github/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill anti-reversing-techniques -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents anti-reversing-techniques --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/reverse-engineering/skills/anti-reversing-techniques .opencode/skills/anti-reversing-techniques && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "anti-reversing-techniques" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques into .opencode/skills/anti-reversing-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-reversing-techniques", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
anti-reversing-techniquesUnderstand anti-reversing, obfuscation, and protection techniques encountered during software analysis.
Anti Reversing Techniques is an agent skill from wshobson/agents. Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.
Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/advanced-techniques.md` and `references/details.md`).
It sits in Security, covering Reverse engineering and malware and Capture the flag. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Anti Reversing Techniques loads about 980 tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 437 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 437 words, ~980 tokens.
.claude/skills/anti-reversing-techniques/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis:
- Verify authorization: Confirm you have explicit written permission from the software owner, or are operating within a legitimate security context (CTF, authorized pentest, malware analysis, security research)
- Document scope: Ensure your activities fall within the defined scope of your authorization
- Legal compliance: Understand that unauthorized bypassing of software protection may violate laws (CFAA, DMCA anti-circumvention, etc.)
Legitimate use cases: Malware analysis, authorized penetration testing, CTF competitions, academic security research, analyzing software you own/have rights to
Understanding protection mechanisms encountered during authorized software analysis, security research, and malware analysis. This knowledge helps analysts bypass protections to complete legitimate analysis tasks.
For advanced techniques, see references/advanced-techniques.md
What you provide:
What this skill produces:
Detailed pattern documentation lives in references/details.md. Read that file when the navigation tier above is insufficient.
Detection technique works on x86 but not ARM
RDTSC and CPUID are x86-only. On ARM, use MRS x0, PMCCNTR_EL0 (requires kernel PMU access) or clock_gettime(CLOCK_MONOTONIC). PEB/TEB do not exist on ARM — replace with /proc/self/status (Linux) or task_info (macOS). Rebuild detection logic with platform-specific APIs.
False positive on legitimate debugger or analysis tool
Timing checks fire when Process Monitor or AV hooks inflate syscall latency. Calibrate the threshold at startup: measure the guarded path 3 times and use mean + 3*stddev. For ptrace checks, verify the TracerPid comm name via /proc/<pid>/comm before exiting — it may be an unrelated monitoring tool, not a debugger.
Bypass patch causes crash instead of continuing execution
Before NOPing a conditional jump, trace the "detected" branch fully. If it initializes or frees heap state needed later, patching the jump skips that setup and corrupts state. Instead, patch the comparison operand to the expected "clean" value, or use x64dbg's "Set condition to always false" on the breakpoint rather than modifying bytes.
binary-analysis-patterns — static and dynamic analysis workflows for ELF/PE/Mach-Omemory-forensics — process memory acquisition, artifact extraction, and live analysisprotocol-reverse-engineering — decoding custom binary protocols and encrypted network traffic© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/reverse-engineering/skills/anti-reversing-techniques of wshobson/agents.
Open the folder on GitHubat commit 46891e7
Anti Reversing Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Anti Reversing Techniques this skillwshobson/agents | 40k | — | ~980 | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | |
| Symbolic Execution Toolsyaklang/hack-skills | 2.4k | — | ~3k | Automated safety check: Pass | MIT | |
| Analyzing Binariestrilwu/secskills | 157 | — | ~2.9k | Automated safety check: Pass | MIT | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 |
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
yaklang/hack-skills
Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
TracecatHQ/tracecat
Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
wshobson/agents
Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.
wshobson/agents
Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.
Categories
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Anti Reversing Techniques is an agent skill from wshobson/agents. Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.
Anti Reversing Techniques fits situations like: analyzing malware evasion techniques; implementing anti-debugging protections for CTF challenges; reverse engineering packed binaries; building security research tools that need to detect virtualized environments.
Run `npx skills add wshobson/agents --skill anti-reversing-techniques -a claude-code`. Or copy the skill folder (plugins/reverse-engineering/skills/anti-reversing-techniques in wshobson/agents) into .claude/skills/anti-reversing-techniques in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill anti-reversing-techniques -a codex`. Or copy the skill folder (plugins/reverse-engineering/skills/anti-reversing-techniques in wshobson/agents) into .agents/skills/anti-reversing-techniques in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill anti-reversing-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anti-reversing-techniques, .gemini/skills/anti-reversing-techniques, .github/skills/anti-reversing-techniques and .opencode/skills/anti-reversing-techniques in your project.
SKILL.md names no scripts, command-line tools or credentials: Anti Reversing Techniques is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Anti Reversing Techniques is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 980 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Anti Reversing Techniques: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Symbolic Execution Tools (yaklang/hack-skills, 2.4k stars), Analyzing Binaries (trilwu/secskills, 157 stars) and vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.