Skip to content
Development
Skill

/ghidra-reverse

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

From plugin
coco
386200 skills53 agents41 commands
Install
$ npx -y skills add coco-research/coco --skill ghidra-reverse --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/ghidra-reverse

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

SKILL.md

ghidra-reverse.SKILL.md
name: ghidra-reverse
description: Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
user-invocable: true

Ghidra Reverse Engineering

适用场景

  • 无 IDA 许可证时的主逆向入口
  • 批量 headless 分析 / CI 中反编译
  • Ghidra 脚本(Java/Python Jython/PyGhidra)自动化
  • 与 `binary-diff` / `patch-diff-exploit` 的 ghidriff 联动

与 IDA 分工

| 需求 | 优先 | |------|------| | 已有 IDA MCP 深挖 | `ida-reverse/` | | 开源 / 批量 / 教学 | **本 skill** | | 仅 CLI 快速侦察 | `radare2/` |

工作流

1. 项目与自动分析

□ 新建 Project → Import 文件 → Analyze(默认分析器)
□ 记录语言/编译器识别结果与基址
□ 标记入口、导出表、字符串 xref

2. 关键函数

□ 从字符串 / 导入 API 反查
□ Decompile 窗口还原算法
□ 重命名函数/变量;写 Plate comment
□ 需要动态时交接 Frida/GDB(reverse-engineering 动态章)

3. Headless(批量)

# 示例:analyzeHeadless 路径因安装而异,MUST 确认本机实际安装路径
analyzeHeadless /path/to/project Proj -import sample.bin -postScript ExportDecomp.py

4. MCP(若已配置)

□ 确认 ghidra MCP 端口(常见 8765,以实际环境为准)
□ 用 MCP 工具拉反编译 / xrefs,禁止猜端口

工具链

| 工具 | 用途 | |------|------| | Ghidra | 反编译主工具 | | ghidra-mcp | AI 桥 | | ghidriff | 补丁差分,见 `patch-diff-exploit` |

参考

  • `references/ghidra-cheatsheet.md`
  • `../ida-reverse/` `../radare2/` `../binary-diff/`
Ships withcoco

CoCo Super Intelligence is the orchestration layer that turns Claude Code, Cursor, or Codex into an engineering department: a routed advisory board, 226 skills, 386 commands, persistent state. Local. Open-core — MIT core; Super Intelligence is proprietary, own-use.

Get the whole plugin

Other skills on coco.