Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .claude/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add wshobson/agents --skill protocol-reverse-engineering -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .agents/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add wshobson/agents --skill protocol-reverse-engineering -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .cursor/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add wshobson/agents --skill protocol-reverse-engineering -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .gemini/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add wshobson/agents --skill protocol-reverse-engineering -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .github/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add wshobson/agents --skill protocol-reverse-engineering -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "protocol-reverse-engineering" agent skill from https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering into .opencode/skills/protocol-reverse-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "protocol-reverse-engineering", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
protocol-reverse-engineering
GitHub stars
40k
Used in
7 other repos
Token cost
~3.2k tokens
SKILL.md length
184 words
Files
1
Skills in repo
142
Repo updated
First seen
Licence
MIT
At a glance
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.
SKILL.md covers Traffic Capture, Protocol Analysis, Protocol Identification and Binary Protocol Analysis, plus 4 more sections
Calls ssh and mysql
What it does
Protocol Reverse Engineering is an agent skill from wshobson/agents. Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware and Network security. It works with Wireshark. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.
When your agent uses it
Analyzing network traffic
Understanding proprietary protocols
Debugging network communication
Example prompts
“/protocol-reverse-engineering”
Requirements
Python 3
Workflow steps
7 steps, taken from the first numbered list in SKILL.md.
1Capture traffic: Multiple sessions, different scenarios
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
ssh
mysql
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Protocol Reverse Engineering loads about 3.2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 184 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~66
When it runs· the whole SKILL.md, loaded when a task matches
~3.2k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
def hexdump(data: bytes, width: int = 16):
"""Format binary data as hex dump."""
lines = []
for i in range(0, len(data), width):
chunk = data[i:i+width]
hex_part = ' '.join(f'{b:02x}' for b in chunk)
ascii_part = ''.join(
chr(b) if 32 <= b < 127 else '.'
for b in chunk
)
lines.append(f'{i:08x} {hex_part:<{width*3}} {ascii_part}')
return '\n'.join(lines)
# Example output:
# 00000000 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d HTTP/1.1 200 OK.
# 00000010 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 74 .Content-Type: t
Encryption Analysis
Identifying Encryption
python
# Entropy analysis - high entropy suggests encryption/compression
import math
from collections import Counter
def entropy(data: bytes) -> float:
if not data:
return 0.0
counter = Counter(data)
probs = [count / len(data) for count in counter.values()]
return -sum(p * math.log2(p) for p in probs)
# Entropy thresholds:
# < 6.0: Likely plaintext or structured data
# 6.0-7.5: Possibly compressed
# > 7.5: Likely encrypted or random
# Common encryption indicators
# - High, uniform entropy
# - No obvious structure or patterns
# - Length often multiple of block size (16 for AES)
# - Possible IV at start (16 bytes for AES-CBC)
Client -> Server: HELLO (ClientID=0x12345678)
Server -> Client: HELLO_ACK (Status=OK)
Client -> Server: DATA (payload)
Wireshark Dissector (Lua)
lua
-- custom_protocol.lua
local proto = Proto("custom", "Custom Protocol")
-- Define fields
local f_magic = ProtoField.string("custom.magic", "Magic")
local f_version = ProtoField.uint16("custom.version", "Version")
local f_type = ProtoField.uint16("custom.type", "Type")
local f_length = ProtoField.uint32("custom.length", "Length")
local f_payload = ProtoField.bytes("custom.payload", "Payload")
proto.fields = { f_magic, f_version, f_type, f_length, f_payload }
-- Message type names
local msg_types = {
[0x01] = "HELLO",
[0x02] = "HELLO_ACK",
[0x03] = "DATA",
[0x04] = "CLOSE"
}
function proto.dissector(buffer, pinfo, tree)
pinfo.cols.protocol = "CUSTOM"
local subtree = tree:add(proto, buffer())
-- Parse header
subtree:add(f_magic, buffer(0, 4))
subtree:add(f_version, buffer(4, 2))
local msg_type = buffer(6, 2):uint()
subtree:add(f_type, buffer(6, 2)):append_text(
" (" .. (msg_types[msg_type] or "Unknown") .. ")"
)
local length = buffer(8, 4):uint()
subtree:add(f_length, buffer(8, 4))
if length > 0 then
subtree:add(f_payload, buffer(12, length))
end
end
-- Register for TCP port
local tcp_table = DissectorTable.get("tcp.port")
tcp_table:add(8888, proto)
Active Testing
Fuzzing with Boofuzz
python
from boofuzz import *
def main():
session = Session(
target=Target(
connection=TCPSocketConnection("target", 8888)
)
)
# Define protocol structure
s_initialize("HELLO")
s_static(b"\x50\x52\x4f\x54") # Magic
s_word(1, name="version") # Version
s_word(0x01, name="type") # Type (HELLO)
s_size("payload", length=4) # Length field
s_block_start("payload")
s_dword(0x12345678, name="client_id")
s_word(0, name="flags")
s_block_end()
session.connect(s_get("HELLO"))
session.fuzz()
if __name__ == "__main__":
main()
Replay and Modification
python
from scapy.all import *
# Replay captured traffic
packets = rdpcap("capture.pcap")
for pkt in packets:
if pkt.haslayer(TCP) and pkt[TCP].dport == 8888:
send(pkt)
# Modify and replay
for pkt in packets:
if pkt.haslayer(Raw):
# Modify payload
original = pkt[Raw].load
modified = original.replace(b"client", b"CLIENT")
pkt[Raw].load = modified
# Recalculate checksums
del pkt[IP].chksum
del pkt[TCP].chksum
send(pkt)
Best Practices
Analysis Workflow
Capture traffic: Multiple sessions, different scenarios
We found 16 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in wshobson/agents, which our catalogue first saw on October 7, 2026.
Protocol Reverse Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Protocol Reverse Engineering compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Protocol Reverse Engineering this skillwshobson/agents
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and…
Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement…
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
How do I install Protocol Reverse Engineering in Claude Code?
Run `npx skills add wshobson/agents --skill protocol-reverse-engineering -a claude-code`. Or copy the skill folder (plugins/reverse-engineering/skills/protocol-reverse-engineering in wshobson/agents) into .claude/skills/protocol-reverse-engineering in your project. Claude Code loads it when a task matches its description.
How do I install Protocol Reverse Engineering in Codex?
Run `npx skills add wshobson/agents --skill protocol-reverse-engineering -a codex`. Or copy the skill folder (plugins/reverse-engineering/skills/protocol-reverse-engineering in wshobson/agents) into .agents/skills/protocol-reverse-engineering in your project. Codex loads it when a task matches its description.
Can I use Protocol Reverse Engineering in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill protocol-reverse-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protocol-reverse-engineering, .gemini/skills/protocol-reverse-engineering, .github/skills/protocol-reverse-engineering and .opencode/skills/protocol-reverse-engineering in your project.
What does Protocol Reverse Engineering need to run?
Going by SKILL.md and its folder, Protocol Reverse Engineering needs the command-line tools its instructions call (ssh and mysql). Our summary lists: Python 3.
Does Protocol Reverse Engineering access the network?
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Protocol Reverse Engineering safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Protocol Reverse Engineering use?
Protocol Reverse Engineering is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Protocol Reverse Engineering use?
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Protocol Reverse Engineering?
Skills that share tags, products or a category with Protocol Reverse Engineering: Performing Network Packet Capture Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Arp Poisoning In Network Traffic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Network Traffic For Incidents (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Network Traffic Of Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Protocol Reverse Engineering?
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,254 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.