Reverse Flow
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yaklang/hack-skills symbolic-execution-tools --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/symbolic-execution-tools .claude/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .claude/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-toolsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yaklang/hack-skills symbolic-execution-tools --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/symbolic-execution-tools .agents/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .agents/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yaklang/hack-skills symbolic-execution-tools --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/symbolic-execution-tools .cursor/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .cursor/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yaklang/hack-skills.git --path skills/symbolic-execution-tools--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yaklang/hack-skills symbolic-execution-tools --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/symbolic-execution-tools .gemini/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .gemini/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yaklang/hack-skills symbolic-execution-toolsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/symbolic-execution-tools .github/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .github/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yaklang/hack-skills symbolic-execution-tools --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/symbolic-execution-tools .opencode/skills/symbolic-execution-tools && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "symbolic-execution-tools" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/symbolic-execution-tools into .opencode/skills/symbolic-execution-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symbolic-execution-tools", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
symbolic-execution-toolsSymbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.
Symbolic Execution Tools is an agent skill from yaklang/hack-skills. Symbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or automating binary analysis with angr, Z3, or Unicorn Engine.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `ANGR_COOKBOOK.md`).
It sits in Security, covering Capture the flag and Reverse engineering and malware. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Symbolic Execution Tools loads about 3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 470 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 470 words, ~3,031 tokens.
.claude/skills/symbolic-execution-tools/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.AI LOAD INSTRUCTION: Expert symbolic execution techniques using angr, Z3, and Unicorn Engine. Covers CTF challenge automation, constraint solving patterns, function hooking, SimProcedure replacement, and emulation-based unpacking. Base models often produce broken angr scripts due to incorrect state initialization or missing hooks for libc functions.
Also load ANGR_COOKBOOK.md when you need:
| Scenario | Best Tool | Why |
|---|---|---|
| Pure math / equation system | Z3 | Direct constraint solving, no binary needed |
| Binary with control flow | angr | Explores paths, manages constraints automatically |
| Emulate specific code region | Unicorn | Fast, no symbolic overhead, good for unpacking |
| Complex binary + custom VM | angr + Unicorn (combo) | angr for control flow, Unicorn for VM handlers |
| Kernel / firmware code | Qiling | Full system emulation with OS awareness |
Project(binary)
→ Factory.entry_state() / blank_state(addr=)
→ SimulationManager(state)
→ explore(find=target, avoid=bad)
→ found[0].solver.eval(symbolic_var)import angr
import claripy
proj = angr.Project('./challenge', auto_load_libs=False)
# Entry state: start from program entry point
state = proj.factory.entry_state()
# Blank state: start from arbitrary address
state = proj.factory.blank_state(addr=0x401000)
# Full init state: with command-line args
state = proj.factory.full_init_state(args=['./challenge', arg1_sym])
simgr = proj.factory.simulation_manager(state)
simgr.explore(find=0x401234, avoid=[0x401300])
if simgr.found:
found = simgr.found[0]
solution = found.solver.eval(symbolic_input, cast_to=bytes)
print(f"Solution: {solution}")# Bitvector (fixed-size integer)
sym_input = claripy.BVS("input", 64) # 64-bit symbolic
sym_byte = claripy.BVS("byte", 8) # 8-bit symbolic
sym_buf = claripy.BVS("buffer", 8 * 32) # 32-byte buffer
# Concrete bitvector
concrete = claripy.BVV(0x41, 8) # concrete value 0x41
# Constraints
state.solver.add(sym_input > 0)
state.solver.add(sym_input < 100)
state.solver.add(sym_byte >= 0x20) # printable ASCII
state.solver.add(sym_byte <= 0x7e)
# Evaluate
value = state.solver.eval(sym_input)
all_values = state.solver.eval_upto(sym_input, 10) # up to 10 solutionsflag_len = 32
sym_stdin = claripy.BVS("stdin", 8 * flag_len)
state = proj.factory.entry_state(stdin=sym_stdin)
# Constrain to printable ASCII
for i in range(flag_len):
byte = sym_stdin.get_byte(i)
state.solver.add(byte >= 0x20)
state.solver.add(byte <= 0x7e)# Hook by address (skip N bytes of original code)
@proj.hook(0x401100, length=5)
def skip_check(state):
state.regs.eax = 1 # force success
# SimProcedure: replace library function
class MyStrcmp(angr.SimProcedure):
def run(self, s1, s2):
return claripy.If(
self.state.memory.load(s1, 32) == self.state.memory.load(s2, 32),
claripy.BVV(0, 32),
claripy.BVV(1, 32)
)
proj.hook_symbol('strcmp', MyStrcmp())
# Hook common problematic functions
proj.hook_symbol('printf', angr.SIM_PROCEDURES['libc']['printf']())
proj.hook_symbol('scanf', angr.SIM_PROCEDURES['libc']['scanf']())
proj.hook_symbol('puts', angr.SIM_PROCEDURES['libc']['puts']())# Read memory (symbolic-aware)
data = state.memory.load(addr, size) # returns BV
data_concrete = state.solver.eval(data, cast_to=bytes)
# Write memory
state.memory.store(addr, claripy.BVV(0x41, 8))
state.memory.store(addr, sym_buf)
# Read/write registers
rax = state.regs.rax
state.regs.rdi = claripy.BVV(0x1000, 64)from z3 import *
# Sorts
x = BitVec('x', 32) # 32-bit bitvector
y = Int('y') # arbitrary precision integer
b = Bool('b') # boolean
# Solver
s = Solver()
s.add(x + y == 42)
s.add(x > 0)
s.add(y > 0)
if s.check() == sat:
m = s.model()
print(f"x = {m[x]}, y = {m[y]}")# Serial key validation: each char satisfies constraints
key = [BitVec(f'k{i}', 8) for i in range(16)]
s = Solver()
for k in key:
s.add(k >= 0x30, k <= 0x7a) # alphanumeric-ish
# XOR key recovery
plaintext = b"known_plaintext"
ciphertext = b"\x12\x34..."
key_byte = BitVec('key', 8)
s = Solver()
for p, c in zip(plaintext, ciphertext):
s.add(p ^ key_byte == c)
# System of linear equations (modular)
a, b, c = BitVecs('a b c', 32)
s = Solver()
s.add(3*a + 5*b + 7*c == 0x12345678)
s.add(2*a + 4*b + 6*c == 0xDEADBEEF)
s.add(a ^ b ^ c == 0xCAFEBABE)from z3 import Optimize
opt = Optimize()
x = BitVec('x', 32)
opt.add(x > 0)
opt.add(x < 1000)
opt.minimize(x) # find smallest satisfying value
opt.check()
print(opt.model())from unicorn import *
from unicorn.x86_const import *
from capstone import Cs, CS_ARCH_X86, CS_MODE_64
mu = Uc(UC_ARCH_X86, UC_MODE_64)
CODE_ADDR = 0x400000
STACK_ADDR = 0x7fff0000
STACK_SIZE = 0x10000
mu.mem_map(CODE_ADDR, 0x10000)
mu.mem_map(STACK_ADDR, STACK_SIZE)
mu.mem_write(CODE_ADDR, code_bytes)
mu.reg_write(UC_X86_REG_RSP, STACK_ADDR + STACK_SIZE - 0x1000)
mu.reg_write(UC_X86_REG_RBP, STACK_ADDR + STACK_SIZE - 0x1000)
mu.emu_start(CODE_ADDR, CODE_ADDR + len(code_bytes))
result = mu.reg_read(UC_X86_REG_RAX)# Hook memory access
def hook_mem(uc, access, address, size, value, user_data):
if access == UC_MEM_WRITE:
print(f"Write {value:#x} to {address:#x}")
elif access == UC_MEM_READ:
print(f"Read from {address:#x}")
mu.hook_add(UC_HOOK_MEM_READ | UC_HOOK_MEM_WRITE, hook_mem)
# Hook specific instruction (for tracing)
def hook_code(uc, address, size, user_data):
code = uc.mem_read(address, size)
md = Cs(CS_ARCH_X86, CS_MODE_64)
for insn in md.disasm(bytes(code), address):
print(f" {insn.address:#x}: {insn.mnemonic} {insn.op_str}")
mu.hook_add(UC_HOOK_CODE, hook_code)| Use Case | Approach |
|---|---|
| Unpack shellcode | Map shellcode, emulate, dump decoded payload |
| Decrypt strings | Emulate decryption function with controlled inputs |
| Brute-force short keys | Loop emulation with different key inputs |
| Analyze obfuscated function | Emulate function, observe register/memory state |
| Firmware code emulation | Map firmware memory layout, emulate routines |
simgr.explore(
find=lambda s: b"Correct" in s.posix.dumps(1), # stdout contains "Correct"
avoid=lambda s: b"Wrong" in s.posix.dumps(1) # avoid "Wrong" output
)| Strategy | Implementation |
|---|---|
| Constrain input space | Add constraints (printable, length limits) |
| Avoid dead-end paths | Use avoid= for known failure addresses |
| Hook complex functions | Replace with simplified SimProcedure |
| Limit loop iterations | state.options.add(angr.options.LAZY_SOLVES) |
| Use veritesting | simgr.explore(..., technique=angr.exploration_techniques.Veritesting()) |
| DFS instead of BFS | simgr.use_technique(angr.exploration_techniques.DFS()) |
| Timeout per path | simgr.explore(..., num_find=1) + timeout wrapper |
state = proj.factory.entry_state(
add_options={angr.options.UNICORN} # use Unicorn for concrete regions
)This dramatically speeds up execution: concrete code runs natively via Unicorn, switching to symbolic only when symbolic variables are involved.
1. Static analysis: identify input method, success/fail conditions
└─ Find "Correct" / "Wrong" strings → get their xref addresses
2. Choose tool:
├─ Pure math (no binary needed) → Z3
├─ Small binary, clear success/fail → angr explore
└─ Specific function to emulate → Unicorn
3. Set up symbolic input:
├─ stdin → claripy.BVS + entry_state(stdin=)
├─ argv → full_init_state(args=[...])
├─ file input → SimFile
└─ specific memory → state.memory.store(addr, sym)
4. Hook problematic functions:
├─ printf/puts → SimProcedure or no-op
├─ scanf → custom handler
├─ time/random → return concrete value
└─ anti-debug → skip entirely
5. Explore and extract:
└─ simgr.explore(find=, avoid=) → solver.eval()Need to solve a reversing challenge?
│
├─ Is the challenge pure math / equations?
│ └─ Yes → Z3
│ ├─ Linear equations → BitVec + Solver
│ ├─ Modular arithmetic → BitVec (natural mod 2^n)
│ ├─ Boolean logic → Bool + Solver
│ └─ Optimization → Optimize + minimize/maximize
│
├─ Is it a compiled binary with clear success/fail?
│ └─ Yes → angr
│ ├─ Input via stdin → symbolic stdin
│ ├─ Input via argv → full_init_state with symbolic args
│ ├─ Input via file → SimFile
│ ├─ Path explosion → add constraints, avoid paths, hook loops
│ └─ Complex library calls → hook with SimProcedure
│
├─ Need to emulate a specific function/region?
│ └─ Yes → Unicorn Engine
│ ├─ Decryption routine → map code + data, emulate, read result
│ ├─ Shellcode analysis → map shellcode, hook syscalls
│ └─ Key schedule → emulate with different inputs
│
├─ Need to analyze firmware / exotic arch?
│ └─ Yes → Qiling (full system emulation with OS support)
│
├─ Binary has VM protection?
│ └─ angr for handler analysis + Z3 for bytecode constraints
│
└─ None of the above working?
├─ Combine: Unicorn for concrete regions + Z3 for constraints
├─ Manual reverse engineering with debugger
└─ Side-channel approach (timing, power analysis for hardware)| Problem | Cause | Fix |
|---|---|---|
| angr hangs forever | Path explosion in loops | Add avoid= for loop-back edges, or hook the loop |
Z3 returns unknown | Non-linear constraints too complex | Simplify, split into sub-problems, use set_param("timeout", 5000) |
| Unicorn crashes on syscall | Syscall not handled | Hook syscall interrupt, handle or skip |
| angr wrong result | Incorrect state initialization | Verify initial memory layout matches actual binary |
| Symbolic memory too large | Unbounded symbolic reads | Concretize array indices where possible |
| SimProcedure wrong types | Argument type mismatch | Check calling convention (cdecl vs fastcall) |
| angr can't load binary | Missing libraries | Use auto_load_libs=False + hook needed symbols |
# angr (Python 3.8+)
pip install angr
# Z3
pip install z3-solver
# Unicorn Engine
pip install unicorn
# Capstone (disassembly, pairs with Unicorn)
pip install capstone
# Keystone (assembly)
pip install keystone-engine© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/symbolic-execution-tools of yaklang/hack-skills.
Open the folder on GitHubat commit 6fbf0bc
Symbolic Execution Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Symbolic Execution Tools this skillyaklang/hack-skills | 2.4k | — | ~3k | Automated safety check: Pass | MIT | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | |
| Anti Reversing Techniqueswshobson/agents | 40k | — | ~980 | Automated safety check: Pass | MIT | |
| Analyzing Binariestrilwu/secskills | 157 | — | ~2.9k | Automated safety check: Pass | MIT |
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
wshobson/agents
Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
yaklang/hack-skills
Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
Draw a testable attack surface from one authorized target URL or one application.
yaklang/hack-skills
Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.
Categories
Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills. Symbolic Execution Tools is an agent skill from yaklang/hack-skills. Symbolic execution and constraint solving playbook.
Symbolic Execution Tools fits situations like: solving CTF reversing challenges; recovering keys; bypassing checks; automating binary analysis with angr.
Run `npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a claude-code`. Or copy the skill folder (skills/symbolic-execution-tools in yaklang/hack-skills) into .claude/skills/symbolic-execution-tools in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a codex`. Or copy the skill folder (skills/symbolic-execution-tools in yaklang/hack-skills) into .agents/skills/symbolic-execution-tools in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill symbolic-execution-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/symbolic-execution-tools, .gemini/skills/symbolic-execution-tools, .github/skills/symbolic-execution-tools and .opencode/skills/symbolic-execution-tools in your project.
Going by SKILL.md and its folder, Symbolic Execution Tools needs the command-line tools its instructions call (pip). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Symbolic Execution Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Symbolic Execution Tools: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and Anti Reversing Techniques (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,418 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.
Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.