PlotJuggler 4 Perf Profiling
PlotJuggler/PlotJuggler
Guides CPU profiling of PlotJuggler 4 on Linux with perf: count first, record cheaply with LBR, then read per-thread, flat, flamegraph or time-window views.
Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yaklang/hack-skills anti-debugging-techniques --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/anti-debugging-techniques .claude/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .claude/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniquesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yaklang/hack-skills anti-debugging-techniques --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/anti-debugging-techniques .agents/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .agents/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yaklang/hack-skills anti-debugging-techniques --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/anti-debugging-techniques .cursor/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .cursor/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yaklang/hack-skills.git --path skills/anti-debugging-techniques--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yaklang/hack-skills anti-debugging-techniques --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/anti-debugging-techniques .gemini/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .gemini/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yaklang/hack-skills anti-debugging-techniquesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/anti-debugging-techniques .github/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .github/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yaklang/hack-skills anti-debugging-techniques --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/anti-debugging-techniques .opencode/skills/anti-debugging-techniques && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "anti-debugging-techniques" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/anti-debugging-techniques into .opencode/skills/anti-debugging-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anti-debugging-techniques", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
anti-debugging-techniquesAnti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.
Anti Debugging Techniques is an agent skill from yaklang/hack-skills. Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `ANTI_DEBUG_MATRIX.md`).
It sits in Development, covering Debugging. It works with Linux. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are c, asm, bash and javascript).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Anti Debugging Techniques loads about 3.4k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 1,003 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 1,003 words, ~3,411 tokens.
.claude/skills/anti-debugging-techniques/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.AI LOAD INSTRUCTION: Expert anti-debug techniques across Linux and Windows. Covers ptrace, PEB flags, NtQueryInformationProcess, timing attacks, signal-based detection, TLS callbacks, VEH tricks, and all corresponding bypass methods. Base models often miss the distinction between user-mode and kernel-mode detection and the correct patching strategy for each.
Also load ANTI_DEBUG_MATRIX.md when you need:
| Detection Class | First Bypass | Backup |
|---|---|---|
| ptrace-based (Linux) | LD_PRELOAD hook ptrace() → return 0 | Kernel module to hide tracer |
| PEB.BeingDebugged (Windows) | Patch PEB byte at fs:[0x30]+0x2 | ScyllaHide auto-patch |
| Timing check (rdtsc) | Conditional BP after rdtsc, fix registers | Frida hook rdtsc return |
| IsDebuggerPresent | NOP the call / hook return 0 | x64dbg built-in hide |
| INT 2D / UD2 exception | Set VEH to handle gracefully | TitanHide driver |
The classic self-attach: a process calls ptrace(PTRACE_TRACEME, 0, 0, 0). If a debugger is already attached, the call fails (returns -1).
if (ptrace(PTRACE_TRACEME, 0, 0, 0) == -1) {
exit(1); // debugger detected
}Bypass methods:
| Method | How |
|---|---|
LD_PRELOAD shim | Compile shared lib: long ptrace(int r, ...) { return 0; } and set LD_PRELOAD |
| Binary patch | NOP the ptrace call or patch return value check |
| GDB catch | catch syscall ptrace → modify $rax to 0 on return |
| Kernel module | Hook sys_ptrace to allow multiple tracers |
FILE *f = fopen("/proc/self/status", "r");
// parse TracerPid: if non-zero → debugger attachedBypass: Mount a FUSE filesystem over /proc/self, or LD_PRELOAD hook fopen/fread to filter TracerPid to 0.
Measures elapsed time between two points; debugger single-stepping causes noticeable delay.
rdtsc
mov ebx, eax ; save low 32 bits
; ... protected code ...
rdtsc
sub eax, ebx
cmp eax, 0x1000 ; threshold
ja debugger_detectedBypass: Set hardware breakpoint after second rdtsc, modify eax to pass the comparison. Or use Frida to replace the timing function.
volatile int caught = 0;
void handler(int sig) { caught = 1; }
signal(SIGTRAP, handler);
raise(SIGTRAP);
if (!caught) exit(1); // debugger swallowed the signalWhen a debugger is attached, SIGTRAP is consumed by the debugger rather than delivered to the handler. Bypass: In GDB, use handle SIGTRAP nostop pass to forward the signal.
Checks for injected libraries or memory regions characteristic of debuggers/instrumentation.
FILE *f = fopen("/proc/self/maps", "r");
while (fgets(buf, sizeof(buf), f)) {
if (strstr(buf, "frida") || strstr(buf, "LD_PRELOAD"))
exit(1);
}Bypass: Hook fopen("/proc/self/maps") to return a filtered version, or rename Frida's agent library.
Some protections check for LD_PRELOAD, LINES, COLUMNS (set by GDB's terminal), or debugger-specific env vars.
Bypass: Unset suspicious env vars before launch, or hook getenv().
if (IsDebuggerPresent()) ExitProcess(1);
BOOL debugged = FALSE;
CheckRemoteDebuggerPresent(GetCurrentProcess(), &debugged);
if (debugged) ExitProcess(1);Bypass: Hook kernel32!IsDebuggerPresent to return 0, or patch PEB directly.
| Field | Offset (x64) | Debugged Value | Normal Value |
|---|---|---|---|
BeingDebugged | PEB+0x02 | 1 | 0 |
NtGlobalFlag | PEB+0xBC | 0x70 (FLG_HEAP_*) | 0 |
ProcessHeap.Flags | Heap+0x40 | 0x40000062 | 0x00000002 |
ProcessHeap.ForceFlags | Heap+0x44 | 0x40000060 | 0 |
mov rax, gs:[0x60] ; PEB
movzx eax, byte [rax+0x02] ; BeingDebugged
test eax, eax
jnz debugger_detectedBypass: Zero all four fields. ScyllaHide does this automatically.
| InfoClass | Value | Debugged Return |
|---|---|---|
ProcessDebugPort | 0x07 | Non-zero port |
ProcessDebugObjectHandle | 0x1E | Valid handle |
ProcessDebugFlags | 0x1F | 0 (inverted!) |
Bypass: Hook ntdll!NtQueryInformationProcess to return clean values per info class.
CONTEXT ctx;
ctx.ContextFlags = CONTEXT_DEBUG_REGISTERS;
GetThreadContext(GetCurrentThread(), &ctx);
if (ctx.Dr0 || ctx.Dr1 || ctx.Dr2 || ctx.Dr3)
ExitProcess(1);Bypass: Hook GetThreadContext to zero DR0–DR3, or use NtSetInformationThread(ThreadHideFromDebugger) preemptively (ironically, the anti-debug technique itself).
INT 2D is the kernel debug service interrupt. Without a debugger, it raises STATUS_BREAKPOINT; with a debugger, behavior differs (byte skipping).
xor eax, eax
int 2dh
nop ; debugger may skip this byte
; ... divergent execution path ...Bypass: Handle in VEH or patch the interrupt instruction.
TLS callbacks execute before main() / WinMain(). Anti-debug checks placed here run before the debugger's initial break.
Bypass: In x64dbg, set "Break on TLS Callbacks" option. In WinDbg, use sxe ld to break on module load.
NtSetInformationThread(GetCurrentThread(), ThreadHideFromDebugger, NULL, 0);After this call, the thread becomes invisible to the debugger — breakpoints and single-stepping stop working silently.
Bypass: Hook NtSetInformationThread to NOP when ThreadInfoClass == 0x11.
Registers a Vectored Exception Handler that checks EXCEPTION_RECORD for debugger-specific behavior (single-step flag, guard page violations with debugger semantics).
Bypass: Understand the VEH logic and ensure the exception chain behaves identically to non-debugged execution.
The process forks a child that attaches to the parent via ptrace. If an external debugger is already attached, the child's ptrace fails.
pid_t child = fork();
if (child == 0) {
if (ptrace(PTRACE_ATTACH, getppid(), 0, 0) == -1)
kill(getppid(), SIGKILL);
else
ptrace(PTRACE_DETACH, getppid(), 0, 0);
_exit(0);
}
wait(NULL);Bypass: Patch the fork() return or kill/detach the watchdog child.
Parent and child cooperatively check each other's debug state, creating a mutual-watch pattern.
Bypass: Attach to both processes (GDB follow-fork-mode, or two debugger instances).
Distributes timing checks across multiple functions, comparing cumulative drift. Single patches fail because the total still exceeds threshold.
Bypass: Frida Interceptor.replace all timing sources (rdtsc, clock_gettime, QueryPerformanceCounter) to return controlled values.
Original conditional jumps are replaced with INT3 (0xCC). A parent debugger process handles each INT3, evaluates the condition, and sets the child's EIP accordingly.
Bypass: Reconstruct the original jump table by tracing all INT3 handlers, then patch the binary.
| Tool | Platform | Capability |
|---|---|---|
| ScyllaHide | Windows (x64dbg/IDA/OllyDbg) | Auto-patches PEB, hooks NtQuery*, hides threads, fixes timing |
| TitanHide | Windows (kernel driver) | Kernel-level hiding for all user-mode checks |
| Frida | Cross-platform | Script-based hooking of any function, timing spoofing |
| LD_PRELOAD shims | Linux | Replace ptrace, getenv, fopen at load time |
| GDB scripts | Linux | catch syscall, conditional BP, register fixup |
| Qiling | Cross-platform | Full-system emulation, bypass all hardware checks |
Step 1: Static analysis — identify anti-debug calls
└─ Search for: ptrace, IsDebuggerPresent, NtQuery, rdtsc,
GetTickCount, SIGTRAP, INT 2D, TLS directory entries
Step 2: Classify each check
├─ API-based → hook or patch the call
├─ Flag-based → patch PEB/proc fields
├─ Timing-based → spoof time source
├─ Exception-based → forward/handle exception correctly
└─ Multi-process → handle both processes
Step 3: Apply bypass (order matters)
1. Load ScyllaHide / set LD_PRELOAD (covers 80% of checks)
2. Handle TLS callbacks (break before main)
3. Patch remaining custom checks (Frida or binary patch)
4. Verify: run with breakpoints, confirm no premature exit
Step 4: Validate bypass completeness
└─ Set BP on ExitProcess/exit/_exit — if hit unexpectedly,
a check was missed → trace back from exit callBinary exits/crashes under debugger?
│
├─ Crashes immediately before main?
│ └─ TLS callback anti-debug
│ └─ Enable TLS callback breaking in debugger
│
├─ Crashes at startup?
│ ├─ Linux: check for ptrace(TRACEME)
│ │ └─ LD_PRELOAD hook or NOP patch
│ └─ Windows: check IsDebuggerPresent / PEB
│ └─ ScyllaHide or manual PEB patch
│
├─ Crashes after some execution?
│ ├─ Consistent crash point → API-based check
│ │ ├─ NtQueryInformationProcess → hook return values
│ │ ├─ /proc/self/status → filter TracerPid
│ │ └─ Hardware BP detection → hook GetThreadContext
│ │
│ ├─ Variable crash point → timing-based check
│ │ └─ Hook rdtsc / QueryPerformanceCounter
│ │
│ └─ Crash on breakpoint hit → exception-based check
│ ├─ INT 2D / INT 3 trick → handle in VEH
│ └─ SIGTRAP handler → GDB: handle SIGTRAP pass
│
├─ Debugger loses control silently?
│ └─ ThreadHideFromDebugger
│ └─ Hook NtSetInformationThread
│
├─ Child process detects and kills parent?
│ └─ Self-debugging (fork+ptrace)
│ └─ Patch fork() or handle both processes
│
└─ All basic bypasses applied but still detected?
└─ Multi-layer / custom checks
├─ Use Frida for comprehensive API hooking
├─ Full emulation with Qiling
└─ Trace all calls to exit/abort to find remaining checks| Pattern | Frequency | Quick Bypass |
|---|---|---|
Single ptrace(TRACEME) | Very common | LD_PRELOAD one-liner |
IsDebuggerPresent + NtGlobalFlag | Common | ScyllaHide |
| rdtsc timing in loop | Moderate | Patch comparison threshold |
| signal(SIGTRAP) + raise | Moderate | GDB signal forwarding |
| fork + ptrace watchdog | Rare but tricky | Kill child or patch fork |
| Nanomite INT3 replacement | Rare (advanced) | Reconstruct jump table |
| Protector | Primary Anti-Debug | Recommended Tool |
|---|---|---|
| VMProtect | PEB + timing + driver-level | TitanHide + ScyllaHide |
| Themida | Multi-layer PEB + SEH + timing | ScyllaHide + manual patches |
| Enigma Protector | IsDebuggerPresent + CRC checks | x64dbg + ScyllaHide |
| UPX (custom) | Usually none (just packing) | Standard unpack |
| Custom (malware) | Varies widely | Frida + Qiling for analysis |
# LD_PRELOAD anti-ptrace
echo 'long ptrace(int r, ...) { return 0; }' > /tmp/ap.c
gcc -shared -o /tmp/ap.so /tmp/ap.c
LD_PRELOAD=/tmp/ap.so ./target
# GDB: catch and bypass ptrace
(gdb) catch syscall ptrace
(gdb) commands
> set $rax = 0
> continue
> end// Hook IsDebuggerPresent (Windows)
Interceptor.replace(
Module.getExportByName('kernel32.dll', 'IsDebuggerPresent'),
new NativeCallback(() => 0, 'int', [])
);
// Hook ptrace (Linux)
Interceptor.replace(
Module.getExportByName(null, 'ptrace'),
new NativeCallback(() => 0, 'long', ['int', 'int', 'pointer', 'pointer'])
);
// Timing spoof
Interceptor.attach(Module.getExportByName(null, 'clock_gettime'), {
onLeave(retval) {
// manipulate timespec to hide debugger delay
}
});© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/anti-debugging-techniques of yaklang/hack-skills.
Open the folder on GitHubat commit 6fbf0bc
Anti Debugging Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Anti Debugging Techniques this skillyaklang/hack-skills | 2.4k | — | ~3.4k | Automated safety check: Pass | MIT | |
| PlotJuggler 4 Perf ProfilingPlotJuggler/PlotJuggler | 6.2k | — | ~1.6k | Automated safety check: Notes | MPL-2.0 | |
| The Art of Debuggingstas00/the-art-of-debugging | 1.7k | — | ~6.1k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Gearcoleco Debuggingdrhelius/Gearcoleco | 141 | — | ~3.5k | Automated safety check: Pass | GPL-3.0 | |
| Issue Trackingstatic-web-server/static-web-server | 2.4k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| OpenLogi Device DiagnosisAprilNEA/OpenLogi | 23k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 |
PlotJuggler/PlotJuggler
Guides CPU profiling of PlotJuggler 4 on Linux with perf: count first, record cheaply with LBR, then read per-thread, flat, flamegraph or time-window views.
stas00/the-art-of-debugging
Condensed debugging method and tool recipes for Unix, Python and PyTorch programs: crashes, hangs, segfaults, wrong output, CUDA OOM, NaN values and slowness.
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
static-web-server/static-web-server
Triage, debug, fix, and document issues for the Static Web Server (SWS) project — bug reports, root cause analysis, fix implementation, and regression prevention
AprilNEA/OpenLogi
Finds the first failing layer when an OpenLogi Logitech device is missing or misbehaving across enumeration, open, probe, IPC and UI.
novotnyllc/dotnet-artisan
Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…
yaklang/hack-skills
API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
Draw a testable attack surface from one authorized target URL or one application.
yaklang/hack-skills
Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills.
Works with
Categories
Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills. Anti Debugging Techniques is an agent skill from yaklang/hack-skills. Anti-debugging detection and bypass playbook.
Anti Debugging Techniques fits situations like: reversing protected binaries that detect debuggers via ptrace; signal/exception handlers on Linux and Windows.
Run `npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a claude-code`. Or copy the skill folder (skills/anti-debugging-techniques in yaklang/hack-skills) into .claude/skills/anti-debugging-techniques in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a codex`. Or copy the skill folder (skills/anti-debugging-techniques in yaklang/hack-skills) into .agents/skills/anti-debugging-techniques in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill anti-debugging-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anti-debugging-techniques, .gemini/skills/anti-debugging-techniques, .github/skills/anti-debugging-techniques and .opencode/skills/anti-debugging-techniques in your project.
SKILL.md names no scripts, command-line tools or credentials: Anti Debugging Techniques is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Anti Debugging Techniques is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Anti Debugging Techniques: PlotJuggler 4 Perf Profiling (PlotJuggler/PlotJuggler, 6.2k stars), The Art of Debugging (stas00/the-art-of-debugging, 1.7k stars), Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars) and Issue Tracking (static-web-server/static-web-server, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,394 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.
Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.