find-oep
Smart trace-based OEP finder for packed/protected PE executables. Traces through packer stubs using intelligent stepping, anti-debug evasion, and heuristic OEP…
Decompile a function to C-like pseudocode using angr
$ npx -y skills add dariushoule/x64dbg-skills --skill decompile --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/decompileContext preview
The summary Claude sees to decide when to auto-load this skill.
Decompile a function to C-like pseudocode using angr
name: decompile description: Decompile a function to C-like pseudocode using angr allowed-tools: mcp__x64dbg__get_debugger_status, mcp__x64dbg__get_register, mcp__x64dbg__eval_expression, mcp__x64dbg__get_symbol, Bash, Read
Decompile a function from the debugged binary into C-like pseudocode using angr.
If no address is specified, decompiles the function containing the current instruction pointer. Accepts an address or symbol name as an argument.
Follow these steps exactly:
Run `pip show angr` via Bash. If angr is not installed, tell the user:
> angr is not installed. Install it with `pip install angr` (requires Python >= 3.10). Note: angr is a large package (~500MB+).
Then stop.
Call `mcp__x64dbg__get_debugger_status` to confirm the debugger is connected and paused. If not debugging, tell the user and stop.
**If the user provided an address or symbol as an argument:**
**If no argument was provided:**
Call this resolved value `target_addr`.
Use `mcp__x64dbg__eval_expression` to evaluate:
Compute the RVA: `target_addr - module_base`
If `mod.path` fails, the address may not belong to a loaded module. Tell the user and stop.
Execute:
python "${CLAUDE_PLUGIN_ROOT}\skills\decompile\decompile.py" --binary "<module_path>" --address <rva_hex>Where:
The script may take 10-30 seconds for large binaries (CFG generation is the bottleneck). Use a timeout of at least 120 seconds.
The script outputs decompiled C pseudocode to stdout and status messages to stderr.
Present the decompiled code to the user in a ```c code block. If the script failed, relay the error message from stderr (e.g., function not found, decompilation failed) and suggest nearby functions if listed.
Claude Code plugin providing skills for x64dbg debugger automation.
Smart trace-based OEP finder for packed/protected PE executables. Traces through packer stubs using intelligent stepping, anti-debug evasion, and heuristic OEP…
Load, unpack, and analyze shellcode in x64dbg. Use this skill when the user wants to analyze shellcode, load a shellcode blob into a debugger, unpack…
Compare two state snapshots to identify register and memory changes between two points in time
Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis
Trace execution (into or over calls) for N steps or until a condition, then analyze the recorded instruction log
Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.