Agent skill

Steganography Techniques

by yaklang in yaklang/hack-skills

Steganography detection and extraction playbook. An agent skill from yaklang/hack-skills.

MITAuto-check passed

Install Steganography Techniques

skills CLI
$ npx skills add yaklang/hack-skills --skill steganography-techniques -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills steganography-techniques --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/steganography-techniques .claude/skills/steganography-techniques && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
steganography-techniques
GitHub stars
2.4k
Token cost
~2.7k tokens
SKILL.md length
201 words
Files
2
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Steganography detection and extraction playbook. An agent skill from yaklang/hack-skills.

  • Works in 6 steps: RELATED ROUTING → IMAGE STEGANOGRAPHY → AUDIO STEGANOGRAPHY → …
  • Analyzing images (LSB
  • SKILL.md covers 0. RELATED ROUTING, 1. IMAGE STEGANOGRAPHY, 2. AUDIO STEGANOGRAPHY and 3. FILE STEGANOGRAPHY, plus 2 more sections
  • Calls python3 and java

What it does

Steganography Techniques is an agent skill from yaklang/hack-skills. Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `STEGO_TOOLS_GUIDE.md`).

The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Analyzing images (LSB
  • Audio (spectrogram
  • Files (polyglots
  • Text (whitespace

Example prompts

  • “/steganography-techniques”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. RELATED ROUTING
  2. IMAGE STEGANOGRAPHY
  3. AUDIO STEGANOGRAPHY
  4. FILE STEGANOGRAPHY
  5. TEXT STEGANOGRAPHY
  6. DECISION TREE

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Steganography Techniques loads about 2.7k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 201 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 201 words, ~2,652 tokens.

Download SKILL.mdSave it as .claude/skills/steganography-techniques/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
steganography-techniques
description
Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.

SKILL: Steganography Techniques — Expert Analysis Playbook

AI LOAD INSTRUCTION: Expert steganography detection and extraction techniques. Covers image steganography (LSB, PNG chunk hiding, JPEG DCT, EXIF metadata, dimension tricks, palette manipulation), audio steganography (spectrogram, LSB, DTMF, morse), file steganography (polyglots, binwalk, NTFS ADS, steghide), and text steganography (whitespace, zero-width Unicode, homoglyphs). Base models miss the systematic file-type-based analysis approach and tool-specific extraction workflows.

Before going deep, consider loading:

Tool Reference

Also load STEGO_TOOLS_GUIDE.md when you need:

  • Tool installation instructions and dependencies
  • Detailed command reference for each stego tool
  • Workflow patterns for specific file types

1. IMAGE STEGANOGRAPHY

LSB (Least Significant Bit)

LSB embeds data in the least significant bits of pixel color channels.

bash
# zsteg — LSB analysis for PNG/BMP
zsteg image.png                       # auto-detect all LSB patterns
zsteg image.png -a                    # try all known methods
zsteg image.png -b 1                  # extract bit plane 1
zsteg image.png -E "b1,rgb,lsb,xy"   # specific extraction pattern

# StegSolve (Java GUI)
java -jar StegSolve.jar
# Navigate color planes: Red 0, Green 0, Blue 0 → look for hidden image/text
# Data Extractor: specify bit planes + byte order

# stegoveritas — comprehensive automated analysis
stegoveritas image.png
# Runs: exiftool, binwalk, zsteg, foremost, color plane extraction
PNG Specific
bash
# pngcheck — validate structure, find hidden chunks
pngcheck -v image.png

# Hidden chunks: tEXt, zTXt (compressed text), iTXt (international text)
# Custom/private chunks may contain hidden data

# CRC vs dimensions trick
# If CRC doesn't match declared dimensions → image was cropped
# Fix: brute-force correct width/height → reveals hidden rows/columns
python3 -c "
import struct, zlib
with open('image.png','rb') as f:
    data = f.read()
# Check IHDR CRC at offset 29
ihdr = data[12:29]
for h in range(1,2000):
    for w in range(1,2000):
        new_ihdr = struct.pack('>II',w,h) + ihdr[8:]
        if zlib.crc32(b'IHDR'+new_ihdr) & 0xffffffff == struct.unpack('>I',data[29:33])[0]:
            print(f'Width: {w}, Height: {h}')
"

# APNG (animated PNG) — hidden frames
# Use apngdis to extract all frames: apngdis image.png
JPEG Specific
bash
# steghide — embed/extract from JPEG (DCT coefficient modification)
steghide extract -sf image.jpg                 # extract (no passphrase)
steghide extract -sf image.jpg -p PASSWORD     # extract with passphrase
steghide info image.jpg                        # check if data is embedded

# stegcracker — brute force steghide passphrase
stegcracker image.jpg wordlist.txt

# jsteg — JPEG LSB steganography
jsteg reveal image.jpg output.txt

# JPEG structure analysis
exiftool -v3 image.jpg       # verbose metadata + structure
jpegdump image.jpg           # raw JPEG marker analysis
EXIF Metadata
bash
# exiftool — comprehensive metadata extraction
exiftool image.jpg
exiftool -b -ThumbnailImage image.jpg > thumb.jpg   # extract thumbnail
exiftool -all= image.jpg                             # strip all metadata

# Hidden data in EXIF fields (comment, artist, copyright, etc.)
exiftool -Comment image.jpg
exiftool -UserComment image.jpg
strings image.jpg | grep -i "flag\|key\|secret"
Palette-Based (GIF)
bash
# GIF color table manipulation — data in color palette order
gifsicle -I image.gif                    # info
gifsicle --color-info image.gif          # palette details
# Check for animation frames: convert -coalesce image.gif frame_%d.png

2. AUDIO STEGANOGRAPHY

Spectrogram Analysis
bash
# Sonic Visualiser — best for spectrogram viewing
# Layer → Add Spectrogram → look for visual patterns (text/images)

# Audacity
# Analyze → Plot Spectrum
# Select audio → change view to Spectrogram

# sox for command-line spectrogram generation
sox audio.wav -n spectrogram -o spectro.png
Audio LSB
bash
# DeepSound — hide/extract files in audio (Windows)
# GUI tool: open audio file → extract hidden files

# WavSteg — LSB in WAV files
python3 WavSteg.py -r -i audio.wav -o output.txt -n 1   # extract 1 LSB
python3 WavSteg.py -r -i audio.wav -o output.txt -n 2   # extract 2 LSBs
DTMF / Morse Code
bash
# DTMF decoder (phone tones)
multimon-ng -t wav -a DTMF audio.wav

# Morse code
# Audacity → visual inspection of on/off pattern
# Online decoder or manual: .- = A, -... = B, etc.

# SSTV (Slow-Scan Television) — image in audio
qsstv                    # GUI decoder
# Or: RX-SSTV (Windows)
WAV Header Manipulation
bash
# Check for data appended after WAV audio data
# WAV data chunk size vs actual file size
python3 -c "
import wave
w = wave.open('audio.wav','rb')
print(f'Frames: {w.getnframes()}, Channels: {w.getnchannels()}, Width: {w.getsampwidth()}')
expected = w.getnframes() * w.getnchannels() * w.getsampwidth() + 44  # 44 = WAV header
import os
actual = os.path.getsize('audio.wav')
if actual > expected:
    print(f'Extra data: {actual - expected} bytes appended')
"

3. FILE STEGANOGRAPHY

Polyglot Files

A single file that is valid in two or more formats simultaneously.

bash
# Detection: check file with multiple tools
file suspicious_file
xxd suspicious_file | head          # check magic bytes
binwalk suspicious_file             # find embedded files

# Common polyglots: PDF+ZIP, JPEG+ZIP, JPEG+RAR, PNG+ZIP
# Try unzip on image files:
unzip image.jpg -d extracted/
7z x image.jpg -oextracted/
Appended / Embedded Data
bash
# binwalk — scan for embedded files and data
binwalk image.png                   # scan
binwalk -e image.png                # extract embedded files
binwalk --dd='.*' image.png         # extract everything

# foremost — file carving
foremost -i suspicious_file -o output_dir/

# dd — manual extraction
# If binwalk shows embedded ZIP at offset 0x1234:
dd if=suspicious_file bs=1 skip=$((0x1234)) of=extracted.zip
NTFS Alternate Data Streams (ADS)
cmd
:: List ADS (Windows)
dir /r file.txt
Get-Item file.txt -Stream *

:: Read hidden stream
more < file.txt:hidden_stream
Get-Content file.txt -Stream hidden_stream

:: Create ADS (for testing)
echo "hidden data" > file.txt:secret
Steghide Brute Force
bash
# stegcracker — wordlist attack on steghide passphrase
stegcracker image.jpg /usr/share/wordlists/rockyou.txt

# stegseek — faster alternative
stegseek image.jpg /usr/share/wordlists/rockyou.txt
# stegseek is ~10000x faster than stegcracker

4. TEXT STEGANOGRAPHY

Whitespace Encoding
bash
# Tabs and spaces encode binary (tab=1, space=0 or vice versa)
# stegsnow — whitespace steganography
stegsnow -C message.txt                # extract hidden message
stegsnow -C -p PASSWORD message.txt    # extract with password

# Manual detection:
cat -A file.txt | head     # show tabs (^I) and line endings ($)
xxd file.txt | grep "09 20\|20 09"    # look for tab/space patterns
Zero-Width Characters
bash
# Unicode invisible characters used for encoding:
# U+200B (Zero-Width Space), U+200C (ZWNJ), U+200D (ZWJ), U+FEFF (BOM)

# Detection:
python3 -c "
text = open('message.txt','r').read()
hidden = [c for c in text if ord(c) in [0x200b, 0x200c, 0x200d, 0xfeff]]
print(f'Found {len(hidden)} zero-width characters')
binary = ''.join('0' if ord(c)==0x200b else '1' for c in hidden)
# Convert binary to ASCII
"

# Online tools: holloway.nz/steg, Unicode Steganography decoders
Homoglyph Substitution
bash
# Visually identical characters from different Unicode blocks
# e.g., Latin 'a' (U+0061) vs Cyrillic 'а' (U+0430)

# Detection:
python3 -c "
text = open('message.txt','r').read()
for i, c in enumerate(text):
    if ord(c) > 127:
        print(f'Position {i}: char={c} ord={ord(c)} name={__import__(\"unicodedata\").name(c,\"?\")}')
"

5. DECISION TREE

Suspect hidden data — what file type?
│
├── Image (PNG/BMP)?
│   ├── Check metadata: exiftool (§1 EXIF)
│   ├── Check structure: pngcheck, binwalk (§1 PNG)
│   ├── LSB analysis: zsteg, StegSolve (§1 LSB)
│   ├── Check dimensions vs CRC: height/width brute force (§1 PNG)
│   ├── Check for appended data: binwalk -e (§3)
│   └── Try as polyglot: unzip/7z (§3)
│
├── Image (JPEG)?
│   ├── Check metadata: exiftool (§1 EXIF)
│   ├── Try steghide: steghide extract (§1 JPEG)
│   │   └── Password protected? → stegseek brute force (§3)
│   ├── Try jsteg: jsteg reveal (§1 JPEG)
│   ├── Check for appended data: binwalk -e (§3)
│   └── Check thumbnail: exiftool -b -ThumbnailImage (§1 EXIF)
│
├── Image (GIF)?
│   ├── Check frames: extract all animation frames (§1 Palette)
│   ├── Check palette: gifsicle --color-info (§1 Palette)
│   └── Check for appended data: binwalk -e (§3)
│
├── Audio (WAV/MP3/FLAC)?
│   ├── Spectrogram: Sonic Visualiser / Audacity (§2)
│   ├── LSB: WavSteg (§2)
│   ├── DTMF tones: multimon-ng (§2)
│   ├── Morse code: manual or decoder (§2)
│   ├── SSTV: qsstv (§2)
│   └── Check file size vs expected: header analysis (§2)
│
├── Text file?
│   ├── Check whitespace: cat -A, stegsnow (§4)
│   ├── Check zero-width chars: Unicode analysis (§4)
│   ├── Check homoglyphs: non-ASCII detection (§4)
│   └── Check encoding: multiple base decodings
│
├── Any file type?
│   ├── strings: strings -n 8 file | grep -i "flag\|key\|pass"
│   ├── binwalk: binwalk -e file (embedded files) (§3)
│   ├── file: file suspicious_file (true type)
│   ├── xxd: check magic bytes, compare headers
│   └── NTFS? → check ADS: dir /r (§3)
│
└── Password/passphrase needed?
    ├── steghide → stegseek / stegcracker (§3)
    ├── Check challenge description for hints
    └── Try common passwords: password, file name, challenge name

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/steganography-techniques of yaklang/hack-skills.

  • SKILL.md
  • STEGO_TOOLS_GUIDE.md

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Steganography Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Steganography Techniques compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Steganography Techniques this skillyaklang/hack-skills2.4k—~2.7kAutomated safety check: PassMIT
Detecting Process Injection Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.0
Performing Steganography Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: NotesApache-2.0
Analyzing Malware Sandbox Evasion Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~713Automated safety check: PassApache-2.0
Detecting Credential Dumping Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~849Automated safety check: PassApache-2.0
Detecting Fileless Malware Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Detecting Process Injection Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading.

    34k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Steganography Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and extracts hidden data embedded in images, audio, and other media files using steganalysis tools such as StegDetect, zsteg, stegsolve, binwalk, steghide, and OpenStego to uncover covert…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analyzing Malware Sandbox Evasion Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun…

    34k GitHub stars~713 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Credential Dumping Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.

    34k GitHub stars~849 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Fileless Malware Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Process Hollowing Technique

    mukul975/Anthropic-Cybersecurity-Skills

    Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child anomalies using EDR telemetry, Volatility's malfind plugin, pe-sieve…

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from yaklang/hack-skills

All 27 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 25 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 25 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 25 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 25 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 25 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 25 days ago
    Auto-check passed

Questions about Steganography Techniques

What does Steganography Techniques do?

Steganography detection and extraction playbook. An agent skill from yaklang/hack-skills. Steganography Techniques is an agent skill from yaklang/hack-skills. Steganography detection and extraction playbook.

When should I use Steganography Techniques?

Steganography Techniques fits situations like: analyzing images (LSB; audio (spectrogram; files (polyglots; text (whitespace.

How do I install Steganography Techniques in Claude Code?

Run `npx skills add yaklang/hack-skills --skill steganography-techniques -a claude-code`. Or copy the skill folder (skills/steganography-techniques in yaklang/hack-skills) into .claude/skills/steganography-techniques in your project. Claude Code loads it when a task matches its description.

How do I install Steganography Techniques in Codex?

Run `npx skills add yaklang/hack-skills --skill steganography-techniques -a codex`. Or copy the skill folder (skills/steganography-techniques in yaklang/hack-skills) into .agents/skills/steganography-techniques in your project. Codex loads it when a task matches its description.

Can I use Steganography Techniques in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill steganography-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/steganography-techniques, .gemini/skills/steganography-techniques, .github/skills/steganography-techniques and .opencode/skills/steganography-techniques in your project.

What does Steganography Techniques need to run?

Going by SKILL.md and its folder, Steganography Techniques needs the command-line tools its instructions call (python3 and java). Our summary lists: Python 3.

Does Steganography Techniques access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Steganography Techniques safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Steganography Techniques use?

Steganography Techniques is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Steganography Techniques use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Steganography Techniques?

Skills that share tags, products or a category with Steganography Techniques: Detecting Process Injection Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Steganography Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Malware Sandbox Evasion Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Credential Dumping Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Steganography Techniques?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,409 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.