Claude
Chat app · Skill upload
In Claude, open Customize → Skills and use Create skill to upload the ZIP. Skill availability depends on your plan and workspace settings.
Official Claude setup →Community skill · Free instruction package
Expert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research. Use PROACTIVELY for binary analysis, CTF challenges, security research, or understanding undocumented software.
Community instruction package. Read the full workflow below, then choose your app in the setup guide. Package instructions and compatibility claims have not been individually verified; check dependencies and license before use.
CHOOSE YOUR AI APP
Choose your app below for setup instructions. Keep the complete downloaded folder together. Each package may need tools, dependencies or permissions that your app does not provide.
Chat app · Skill upload
In Claude, open Customize → Skills and use Create skill to upload the ZIP. Skill availability depends on your plan and workspace settings.
Official Claude setup →Chat app · Access varies
Where Skills is available, open Plugins → Skills → Create → Upload from your computer. Otherwise, copy the instructions into a chat and add your brief; this does not install a skill or include its supporting files.
Official ChatGPT setup →Agent · Project skills
Extract the complete skill folder into your project’s .agents/skills directory. Ask the agent to use the skill for your task.
.agents/skills/reverse-engineer/SKILL.mdOfficial Google Antigravity setup →Code editor · Project skills
Extract the complete folder into .cursor/skills. Check the editor’s skill settings and ask the agent to use it.
.cursor/skills/reverse-engineer/SKILL.mdOfficial Cursor setup →Coding agent · Project skills
Extract the complete folder into .claude/skills. Ask Claude to use the named skill, or use its slash command when available.
.claude/skills/reverse-engineer/SKILL.mdOfficial Claude Code setup →For text-only workflows, you can also paste the instructions into an AI conversation. Copying text does not enable scripts, connect accounts or grant tool access. App subscriptions may cost extra. Logos identify the products; KuchhBhi is independent and is not endorsed by these companies.
## Use this skill when
- Working on common re scripting environments tasks or workflows
- Needing guidance, best practices, or checklists for common re scripting environments
## Do not use this skill when
- The task is unrelated to common re scripting environments
- You need a different domain or tool outside this scope
## Instructions
- Clarify goals, constraints, and required inputs.
- Apply relevant best practices and validate outcomes.
- Provide actionable steps and verification.
- If detailed examples are required, open `resources/implementation-playbook.md`.
## Analysis Methodology
### Phase 1: Reconnaissance
1. **File identification**: Determine file type, architecture, compiler
2. **Metadata extraction**: Strings, imports, exports, resources
3. **Packer detection**: Identify packers, protectors, obfuscators
4. **Initial triage**: Assess complexity, identify interesting regions
### Phase 2: Static Analysis
1. **Load into disassembler**: Configure analysis options appropriately
2. **Identify entry points**: Main function, exported functions, callbacks
3. **Map program structure**: Functions, basic blocks, control flow
4. **Annotate code**: Rename functions, define structures, add comments
5. **Cross-reference analysis**: Track data and code references
### Phase 3: Dynamic Analysis
1. **Environment setup**: Isolated VM, network monitoring, API hooks
2. **Breakpoint strategy**: Entry points, API calls, interesting addresses
3. **Trace execution**: Record program behavior, API calls, memory access
4. **Input manipulation**: Test different inputs, observe behavior changes
### Phase 4: Documentation
1. **Function documentation**: Purpose, parameters, return values
2. **Data structure documentation**: Layouts, field meanings
3. **Algorithm documentation**: Pseudocode, flowcharts
4. **Findings summary**: Key discoveries, vulnerabilities, behaviors
## Response Approach
When assisting with reverse engineering tasks:
1. **Clarify scope**: Ensure the analysis is for authorized purposes
2. **Understand objectives**: What specific information is needed?
3. **Recommend tools**: Suggest appropriate tools for the task
4. **Provide methodology**: Step-by-step analysis approach
5. **Explain findings**: Clear explanations with supporting evidence
6. **Document patterns**: Note interesting code patterns, techniques
## Code Pattern Recognition
### Common Patterns
```c
// String obfuscation (XOR)
for (int i = 0; i < len; i++)
str[i] ^= key;
// Anti-debugging (IsDebuggerPresent)
if (IsDebuggerPresent())
exit(1);
// API hashing (common in malware)
hash = 0;
while (*name)
hash = ror(hash, 13) + *name++;
// Stack string construction
char s[8];
*(DWORD*)s = 0x6C6C6548; // "Hell"
*(DWORD*)(s+4) = 0x6F; // "o\0"
User: "I have a CTF binary that asks for a password. How do I approach this?"
Response: Let me guide you through the analysis:
1. First, identify the binary type:
$ file challenge
$ checksec --file=challenge
2. Load in Ghidra/IDA and find main()
3. Look for:
- String comparisons (strcmp, memcmp)
- Crypto functions (xor loops, constants like 0x5A827999)
- Input validation logic
4. Set breakpoints on comparison functions in GDB:
$ gdb ./challenge
(gdb) break strcmp
(gdb) run
5. Examine memory at comparison point to see expected value
User: "I need to understand how this closed-source DLL handles authentication"
Response: For authorized analysis of the DLL:
1. Static analysis:
- List exports: dumpbin /exports library.dll
- Find auth-related functions by name patterns
- Load in IDA/Ghidra, analyze exported functions
2. Dynamic analysis:
- Hook API calls with Frida
- Monitor network traffic
- Trace function parameters
3. Documentation:
- Document function signatures
- Map data structures
- Note any security considerations
The instruction package is free to download. Your AI app, model usage, connected services and third-party assets may have separate costs.
It is a set of instructions for a compatible AI assistant. It does not run by itself, connect accounts or install an MCP server.
Check that the named folder contains SKILL.md directly, not a second nested ZIP folder. Confirm that your editor supports skills and that its current settings allow this location. See the official documentation below.