Agent skill

Code Obfuscation Deobfuscation

by yaklang in yaklang/hack-skills

Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills.

MITAuto-check passedSecurity

Install Code Obfuscation Deobfuscation

skills CLI
$ npx skills add yaklang/hack-skills --skill code-obfuscation-deobfuscation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills code-obfuscation-deobfuscation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-obfuscation-deobfuscation .claude/skills/code-obfuscation-deobfuscation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-obfuscation-deobfuscation
GitHub stars
2.4k
Token cost
~3.3k tokens
SKILL.md length
947 words
Files
1
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills.

  • Works in 11 steps: RELATED ROUTING → JUNK CODE & OPAQUE PREDICATES → SELF-MODIFYING CODE (SMC) → …
  • Reversing binaries protected by junk code
  • SKILL.md covers 0. RELATED ROUTING, 1. JUNK CODE & OPAQUE PREDICATES, 2. SELF-MODIFYING CODE (SMC) and 3. CONTROL FLOW FLATTENING (CFF), plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Obfuscation Deobfuscation is an agent skill from yaklang/hack-skills. Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Reversing binaries protected by junk code
  • Opaque predicates
  • Self-modifying code
  • Control flow flattening

Example prompts

  • “/code-obfuscation-deobfuscation”

Requirements

  • Python 3

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. RELATED ROUTING
  2. JUNK CODE & OPAQUE PREDICATES
  3. SELF-MODIFYING CODE (SMC)
  4. CONTROL FLOW FLATTENING (CFF)
  5. MOVFUSCATOR
  6. VM PROTECTION (VMProtect / Themida / Code Virtualizer)
  7. STRING ENCRYPTION
  8. IMPORT HIDING
  9. ANTI-DISASSEMBLY TRICKS
  10. DECISION TREE
  11. TOOLBOX

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, asm and c).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Obfuscation Deobfuscation loads about 3.3k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 947 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 947 words, ~3,316 tokens.

Download SKILL.mdSave it as .claude/skills/code-obfuscation-deobfuscation/SKILL.md (or your agent's skills folder).
name
code-obfuscation-deobfuscation
description
Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.

SKILL: Code Obfuscation & Deobfuscation — Expert Analysis Playbook

AI LOAD INSTRUCTION: Expert techniques for identifying, classifying, and defeating code obfuscation in native binaries. Covers junk code, opaque predicates, SMC, control flow flattening, movfuscator, VM protectors (VMProtect/Themida/Code Virtualizer), string encryption, import hiding, and anti-disassembly tricks. Base models often conflate packing with obfuscation and miss the distinction between static and dynamic deobfuscation strategies.

Quick identification picks
Symptom in IDA/GhidraLikely ObfuscationStart With
Flat CFG, single giant switchControl flow flatteningSymbolic execution to recover CFG
Only mov instructionsmovfuscatordemovfuscation / trace-based lifting
pushad/pushfd → VM entryVM protectorHandler table extraction
XOR loop before code executionSMC / string encryptionDynamic analysis, breakpoint after decode
Impossible conditions (opaque predicates)Junk code insertionPattern-based removal
All strings unreadableString encryptionHook decryption routine, or emulate
No imports in IATImport hidingTrace GetProcAddress / hash resolution

1. JUNK CODE & OPAQUE PREDICATES

1.1 Junk Code Insertion

Dead code that never affects program output, added to increase analysis time.

Identification:

  • Instructions that write to registers/memory never read afterward
  • Function calls whose return values are discarded and have no side effects
  • Loops with invariant bounds that compute unused results

Removal strategy:

  1. Compute def-use chains (IDA/Ghidra data flow analysis)
  2. Mark instructions with no downstream use as dead
  3. Verify removal doesn't change program behavior (trace comparison)
1.2 Opaque Predicates

Conditional branches where the condition is always true or always false, but this is non-obvious.

TypeExampleAlways Evaluates To
Arithmeticx² ≥ 0True
Number theoryx*(x+1) % 2 == 0True (product of consecutive ints)
Pointer-basedptr == ptr after aliasingTrue
Hash-basedCRC32(constant) == known_valueTrue

Deobfuscation:

  • Abstract interpretation: prove the condition is constant
  • Symbolic execution: Z3 proves ∀x: predicate(x) = True
  • Pattern matching: recognize known opaque predicate families
  • Dynamic: trace and observe the branch is never taken / always taken
python
import z3
x = z3.BitVec('x', 32)
s = z3.Solver()
s.add(x * (x + 1) % 2 != 0)
print(s.check())  # unsat → always true

2. SELF-MODIFYING CODE (SMC)

Runtime code patching: encrypted code is decrypted just before execution.

2.1 XOR Decryption Loop (Most Common)
asm
lea esi, [encrypted_code]
mov ecx, code_length
mov al, xor_key
decrypt_loop:
    xor byte [esi], al
    inc esi
    loop decrypt_loop
    jmp encrypted_code  ; now decrypted
2.2 Analysis Strategy
1. Identify the decryption routine (look for XOR/ADD/SUB in loops writing to .text)
2. Set breakpoint AFTER the loop completes
3. At breakpoint: dump the decrypted memory region
4. Re-analyze the dumped code in IDA/Ghidra
5. For multi-layer: repeat for each decryption stage
2.3 Automated Unpacking via Emulation
python
from unicorn import *
from unicorn.x86_const import *

mu = Uc(UC_ARCH_X86, UC_MODE_32)
mu.mem_map(0x400000, 0x10000)
mu.mem_write(0x400000, binary_code)
mu.emu_start(decrypt_entry, decrypt_end)
decrypted = mu.mem_read(code_start, code_length)

3. CONTROL FLOW FLATTENING (CFF)

3.1 Structure

Original sequential blocks are transformed into a dispatcher loop:

Original:      A → B → C → D

Flattened:     ┌──────────────────┐
               │   dispatcher     │
               │   switch(state)  │◄─────┐
               ├──────────────────┤      │
               │ case 1: block A  │──────┤
               │ case 2: block B  │──────┤
               │ case 3: block C  │──────┤
               │ case 4: block D  │──────┘
               └──────────────────┘

Each block sets state = next_state before jumping back to the dispatcher.

3.2 Recovery Techniques
TechniqueToolEffectiveness
Symbolic executionangr, Triton, miasmHigh — traces all state transitions
Trace-based recoveryPin/DynamoRIO trace → reconstruct CFGMedium — covers executed paths only
Pattern matchingCustom IDA/Ghidra scriptMedium — works for known flatteners
D-810 (IDA plugin)IDA ProHigh — specifically designed for CFF
3.3 Symbolic Deflattening (angr approach)
python
import angr, claripy

proj = angr.Project('./obfuscated')
cfg = proj.analyses.CFGFast()

# Find dispatcher block (highest in-degree basic block)
dispatcher = max(cfg.graph.nodes(), key=lambda n: cfg.graph.in_degree(n))

# For each case block, symbolically determine successor
for block in case_blocks:
    state = proj.factory.blank_state(addr=block.addr)
    # ... solve state variable to find real successor

4. MOVFUSCATOR

4.1 Concept

All computation reduced to mov instructions only (Turing-complete via memory-mapped computation tables). Created by Christopher Domas.

4.2 Identification
  • Function contains only mov instructions (no add, sub, xor, jmp, call)
  • Large lookup tables in data section
  • Memory-mapped flag registers
4.3 Demovfuscation
ApproachDescription
demovfuscator (tool)Static analysis, recovers original operations from mov patterns
Trace + taint analysisRun with Pin/DynamoRIO, taint inputs, observe computation
Symbolic executionTreat entire function as constraint system

5. VM PROTECTION (VMProtect / Themida / Code Virtualizer)

5.1 VM Architecture
Protected code → bytecode compiler → custom bytecode
Runtime: VM entry (pushad/pushfd) → fetch → decode → execute → VM exit (popad/popfd)
5.2 VM Entry Point Identification
asm
; Typical VMProtect entry
pushad                    ; save all registers
pushfd                    ; save flags
mov ebp, esp              ; VM stack frame
sub esp, VM_LOCALS_SIZE   ; allocate VM context
mov esi, bytecode_addr    ; bytecode instruction pointer
jmp vm_dispatcher         ; enter VM loop
5.3 Handler Table Extraction
1. Find dispatcher (large switch or indirect jump via table)
2. Each case/entry = one VM handler (implements one VM opcode)
3. Map handler addresses to operations by analyzing each handler:
   - Handler reads operand from bytecode stream (esi)
   - Performs operation on VM registers/stack
   - Advances bytecode pointer
   - Returns to dispatcher
5.4 Devirtualization Approaches
MethodDescriptionTool
Manual handler mappingReverse each handler, build ISA specIDA + scripting
Trace recordingRecord all handler executions, reconstruct programREVEN, Pin
Symbolic liftingSymbolically execute handlers, lift to IRTriton, miasm
Pattern matchingMatch handler patterns to known VM familiesCustom scripts
Show full SKILL.md (375 more words)Show less
5.5 VMProtect Specifics
  • Uses opaque predicates in dispatcher
  • Handler mutation: same opcode, different handler code per build
  • Multiple VM layers (VM inside VM)
  • Integrates anti-debug and integrity checks

6. STRING ENCRYPTION

6.1 Common Patterns
PatternExampleRecovery
XOR loopfor (i=0; i<len; i++) s[i] ^= key;Hook or emulate XOR function
Stack stringsmov [esp+0], 'H'; mov [esp+1], 'e'; ...IDA FLIRT / Ghidra script to reassemble
RC4 encryptedEncrypted blob + RC4 key in binaryExtract key, decrypt offline
AES encryptedEncrypted blob + AES key derived at runtimeHook after decryption
Custom encodingBase64 + XOR + reverseTrace the decode function, replicate
6.2 Automated String Decryption
python
# Ghidra script: find XOR decryption calls, emulate them
from ghidra.program.model.symbol import SourceType

decrypt_func = getFunction("decrypt_string")
refs = getReferencesTo(decrypt_func.getEntryPoint())

for ref in refs:
    call_addr = ref.getFromAddress()
    # extract arguments (encrypted buffer ptr, key, length)
    # emulate decryption, add comment with plaintext

7. IMPORT HIDING

7.1 GetProcAddress + Hash Lookup
c
FARPROC resolve(DWORD hash) {
    // Walk PEB → LDR → InMemoryOrderModuleList
    // For each DLL, walk export table
    // Hash each export name, compare with target hash
    // Return matching function pointer
}
7.2 Recovery
  1. Identify the hash algorithm (common: CRC32, djb2, ROR13+ADD)
  2. Compute hashes for all known API names
  3. Build hash → API name lookup table
  4. Annotate resolved calls in IDA/Ghidra
7.3 Common Hash Algorithms
NameAlgorithmUsed By
ROR13hash = (hash >> 13 | hash << 19) + charMetasploit shellcode
djb2hash = hash * 33 + charVarious malware
CRC32Standard CRC32 of function nameSophisticated packers
FNV-1ahash = (hash ^ char) * 0x01000193Modern malware

8. ANTI-DISASSEMBLY TRICKS

8.1 Techniques
TrickMechanismFix
Overlapping instructionsjmp $+2; db 0xE8 (fake call prefix)Manual re-analysis from correct offset
Misaligned jumpsJump into middle of multi-byte instructionForce IDA to re-analyze at target
Conditional jump pairjz $+5; jnz $+3 (always jumps, confuses linear disasm)Convert to unconditional jmp
Return address manipulationpush addr; ret instead of jmp addrRecognize push+ret as jump
Exception-based flowTrigger exception, real code in handlerAnalyze exception handler chain
Call + add [esp]call $+5; add [esp], N; ret (computed jump)Calculate actual target
8.2 IDA Fixes
Right-click → Undefine (U)
Right-click → Code (C) at correct offset
Edit → Patch → Assemble (for permanent fix)

9. DECISION TREE

Obfuscated binary — how to approach?
│
├─ Can you run it?
│  ├─ Yes → Dynamic analysis first
│  │  ├─ Set BP on interesting APIs (file, network, crypto)
│  │  ├─ Trace execution to understand real behavior
│  │  └─ Dump decrypted code/strings at runtime
│  │
│  └─ No (embedded/firmware/exotic arch) → Static only
│     └─ Identify obfuscation type from patterns below
│
├─ What does the code look like?
│  │
│  ├─ Giant flat switch/dispatcher loop?
│  │  ├─ State variable drives control flow → CFF
│  │  │  └─ Use D-810 or symbolic deflattening
│  │  └─ Bytecode fetch-decode-execute → VM protection
│  │     └─ Extract handlers, build disassembler
│  │
│  ├─ Only mov instructions?
│  │  └─ movfuscator → demovfuscator tool
│  │
│  ├─ XOR/ADD loop writing to .text section?
│  │  └─ SMC → breakpoint after decode, dump
│  │
│  ├─ Impossible conditions in branches?
│  │  └─ Opaque predicates → Z3 proving or pattern removal
│  │
│  ├─ Disassembly looks wrong / functions overlap?
│  │  └─ Anti-disassembly → manual re-analysis at correct offsets
│  │
│  ├─ No readable strings?
│  │  └─ String encryption → hook decrypt function or emulate
│  │
│  ├─ No imports in IAT?
│  │  └─ Import hiding → identify hash, build lookup table
│  │
│  └─ pushad/pushfd → complex code → popad/popfd?
│     └─ VM protector entry/exit → full VM analysis
│
└─ What tool to use?
   ├─ Known protector (VMProtect/Themida) → specific deprotection guide
   ├─ Custom obfuscation → combine: IDA scripting + Triton + manual
   ├─ CTF challenge → angr symbolic execution often fastest
   └─ Malware analysis → dynamic (debugger + API monitor) first

10. TOOLBOX

ToolPurposeBest For
IDA Pro + Hex-RaysDisassembly, decompilation, scriptingAll-around analysis
GhidraFree alternative with scripting (Java/Python)Budget-friendly RE
D-810 (IDA plugin)Automated CFF deflatteningOLLVM-style obfuscation
miasmIR-based analysis frameworkSymbolic deobfuscation
TritonDynamic symbolic executionOpaque predicate solving, CFF
REVENFull-system trace recording and replayVM protector analysis
demovfuscatormovfuscator reversalmov-only binaries
x64dbg + pluginsDynamic analysis with scriptingWindows RE
Unicorn EngineCPU emulationSMC unpacking, shellcode
CapstoneDisassembly libraryCustom tooling
IDA FLIRTFunction signature matchingIdentify library code in stripped binaries
Binary NinjaAlternative disassembler with MLIL/HLILAutomated analysis

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/code-obfuscation-deobfuscation of yaklang/hack-skills.

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Code Obfuscation Deobfuscation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Obfuscation Deobfuscation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Obfuscation Deobfuscation this skillyaklang/hack-skills2.4k—~3.3kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from yaklang/hack-skills

All 26 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 24 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 24 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 24 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 24 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 24 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Code Obfuscation Deobfuscation

What does Code Obfuscation Deobfuscation do?

Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills. Code Obfuscation Deobfuscation is an agent skill from yaklang/hack-skills. Code obfuscation analysis and deobfuscation playbook.

When should I use Code Obfuscation Deobfuscation?

Code Obfuscation Deobfuscation fits situations like: reversing binaries protected by junk code; opaque predicates; self-modifying code; control flow flattening.

How do I install Code Obfuscation Deobfuscation in Claude Code?

Run `npx skills add yaklang/hack-skills --skill code-obfuscation-deobfuscation -a claude-code`. Or copy the skill folder (skills/code-obfuscation-deobfuscation in yaklang/hack-skills) into .claude/skills/code-obfuscation-deobfuscation in your project. Claude Code loads it when a task matches its description.

How do I install Code Obfuscation Deobfuscation in Codex?

Run `npx skills add yaklang/hack-skills --skill code-obfuscation-deobfuscation -a codex`. Or copy the skill folder (skills/code-obfuscation-deobfuscation in yaklang/hack-skills) into .agents/skills/code-obfuscation-deobfuscation in your project. Codex loads it when a task matches its description.

Can I use Code Obfuscation Deobfuscation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill code-obfuscation-deobfuscation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-obfuscation-deobfuscation, .gemini/skills/code-obfuscation-deobfuscation, .github/skills/code-obfuscation-deobfuscation and .opencode/skills/code-obfuscation-deobfuscation in your project.

What does Code Obfuscation Deobfuscation need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Obfuscation Deobfuscation is instructions for the agent only. Our summary lists: Python 3.

Does Code Obfuscation Deobfuscation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Obfuscation Deobfuscation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Obfuscation Deobfuscation use?

Code Obfuscation Deobfuscation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Obfuscation Deobfuscation use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Obfuscation Deobfuscation?

Skills that share tags, products or a category with Code Obfuscation Deobfuscation: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Obfuscation Deobfuscation?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,394 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.