anachb
Austrian public transport (VOR AnachB) for all of Austria. Query real-time departures, search…
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.
$ npx -y skills add mitsuhiko/agent-stuff --skill ghidra --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ghidraContext preview
The summary Claude sees to decide when to auto-load this skill.
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.
name: ghidra description: "Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI."
Perform automated reverse engineering using Ghidra's `analyzeHeadless` tool. Import binaries, run analysis, decompile to C code, and extract useful information.
| Task | Command | |------|---------| | Full analysis with all exports | `ghidra-analyze.sh -s ExportAll.java -o ./output binary` | | Decompile to C code | `ghidra-analyze.sh -s ExportDecompiled.java -o ./output binary` | | List functions | `ghidra-analyze.sh -s ExportFunctions.java -o ./output binary` | | Extract strings | `ghidra-analyze.sh -s ExportStrings.java -o ./output binary` | | Get call graph | `ghidra-analyze.sh -s ExportCalls.java -o ./output binary` | | Export symbols | `ghidra-analyze.sh -s ExportSymbols.java -o ./output binary` | | Find Ghidra path | `find-ghidra.sh` |
The skill automatically locates Ghidra in common installation paths. Set `GHIDRA_HOME` environment variable if Ghidra is installed in a non-standard location.
---
./scripts/ghidra-analyze.sh [options] <binary>
Wrapper that handles project creation/cleanup and provides a simpler interface to `analyzeHeadless`.
**Options:**
---
Comprehensive export - runs all other exports and creates a summary. Best for initial analysis.
**Output files:**
./scripts/ghidra-analyze.sh -s ExportAll.java -o ./analysis firmware.bin
Decompile all functions to C pseudocode.
**Output:** `{name}_decompiled.c`
./scripts/ghidra-analyze.sh -s ExportDecompiled.java -o ./output program.exe
Export function list as JSON with addresses, signatures, parameters, and call relationships.
**Output:** `{name}_functions.json`
{
"program": "example.exe",
"architecture": "x86",
"functions": [
{
"name": "main",
"address": "0x00401000",
"size": 256,
"signature": "int main(int argc, char **argv)",
"returnType": "int",
"callingConvention": "cdecl",
"isExternal": false,
"parameters": [{"name": "argc", "type": "int"}, ...],
"calls": ["printf", "malloc", "process_data"],
"calledBy": ["_start"]
}
]
}Extract all strings (ASCII, Unicode) with addresses.
**Output:** `{name}_strings.json`
./scripts/ghidra-analyze.sh -s ExportStrings.java -o ./output malware.exe
Export function call graph showing caller/callee relationships.
**Output:** `{name}_calls.json`
Includes:
Export all symbols: imports, exports, and internal symbols.
**Output:** `{name}_symbols.json`
---
# Create output directory mkdir -p ./analysis # Run comprehensive analysis ./scripts/ghidra-analyze.sh -s ExportAll.java -o ./analysis unknown_binary # Review the summary first cat ./analysis/unknown_binary_summary.txt # Look at interesting patterns (crypto, network, dangerous functions) cat ./analysis/unknown_binary_interesting.txt # Check specific decompiled functions grep -A 50 "encrypt" ./analysis/unknown_binary_decompiled.c
# Specify ARM architecture for firmware
./scripts/ghidra-analyze.sh \
-p "ARM:LE:32:v7" \
-s ExportAll.java \
-o ./firmware_analysis \
firmware.bin# Just get function names and addresses (faster) ./scripts/ghidra-analyze.sh --no-analysis -s ExportFunctions.java -o . program # Parse with jq cat program_functions.json | jq '.functions[] | "\(.address): \(.name)"'
# After running ExportDecompiled, search for patterns grep -n "password\|secret\|key" output_decompiled.c grep -n "strcpy\|sprintf\|gets" output_decompiled.c
for bin in ./samples/*; do
name=$(basename "$bin")
./scripts/ghidra-analyze.sh -s ExportAll.java -o "./results/$name" "$bin"
done---
Common processor IDs for the `-p` option:
| Architecture | Processor ID | |-------------|--------------| | x86 32-bit | `x86:LE:32:default` | | x86 64-bit | `x86:LE:64:default` | | ARM 32-bit | `ARM:LE:32:v7` | | ARM 64-bit | `AARCH64:LE:64:v8A` | | MIPS 32-bit | `MIPS:BE:32:default` or `MIPS:LE:32:default` | | PowerPC | `PowerPC:BE:32:default` |
Find all available processors:
ls "$(dirname $(./scr
Armin's personal Pi Coding Agent package: reusable skills, extensions, prompt commands, themes, and a few supporting utilities that I use across projects. The package is published to npm as mitsupi.
Repo: mitsuhiko/agent-stuff
Austrian public transport (VOR AnachB) for all of Austria. Query real-time departures, search…
Search, read, and extract attachments from Apple Mail's local storage. Query emails by…
Transcribe local audio/video and Apple Voice Memos quickly with cached MLX Whisper models,…
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for…
Access Google Workspace APIs (Drive, Docs, Calendar, Gmail, Sheets, Slides, Chat, People) via…