Skip to content
Security
Skill

/ghidra-reverse

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

BOOST
From plugin
reverse-skill
39k46 skills
Install
$ npx -y skills add zhaoxuya520/reverse-skill --skill ghidra-reverse --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/ghidra-reverse

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

SKILL.md

ghidra-reverse.SKILL.md
name: ghidra-reverse
description: Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

Ghidra Reverse Engineering

ACTION REQUIRED(读完后立刻执行)

1. `NOW`: 读取 `../field-journal/precedent-reverse.md` 2. `NOW`: 确认需要 **Ghidra**(无 IDA / 偏好开源 / 批量 headless) 3. `NEXT`: 读 `../tool-index.md` 查 ghidra / ghidra-mcp 路径 4. `NEXT`: 缺工具 → bootstrap `ghidra-mcp`(若 manifest 支持)或按手动步骤装 Ghidra 5. `ACT`: 导入样本 → 自动分析 → 导出关键函数反编译

适用场景

  • 无 IDA 许可证时的主逆向入口
  • 批量 headless 分析 / CI 中反编译
  • Ghidra 脚本(Java/Python Jython/PyGhidra)自动化
  • 与 `binary-diff` / `patch-diff-exploit` 的 ghidriff 联动

与 IDA 分工

| 需求 | 优先 | |------|------| | 已有 IDA MCP 深挖 | `ida-reverse/` | | 开源 / 批量 / 教学 | **本 skill** | | 仅 CLI 快速侦察 | `radare2/` |

工作流

1. 项目与自动分析

□ 新建 Project → Import 文件 → Analyze(默认分析器)
□ 记录语言/编译器识别结果与基址
□ 标记入口、导出表、字符串 xref

2. 关键函数

□ 从字符串 / 导入 API 反查
□ Decompile 窗口还原算法
□ 重命名函数/变量;写 Plate comment
□ 需要动态时交接 Frida/GDB(reverse-engineering 动态章)

3. Headless(批量)

# 示例:analyzeHeadless 路径因安装而异,MUST 从 tool-index 取
analyzeHeadless /path/to/project Proj -import sample.bin -postScript ExportDecomp.py

4. MCP(若已配置)

□ 确认 ghidra MCP 端口(常见 8765,以 tool-index 为准)
□ 用 MCP 工具拉反编译 / xrefs,禁止猜端口

工具链

| 工具 | 用途 | 自举 | |------|------|------| | Ghidra | 反编译主工具 | 手动 release / 包管理器 | | ghidra-mcp | AI 桥 | bootstrap 能力名 `ghidra-mcp` | | ghidriff | 补丁差分 | 见 `patch-diff-exploit` |

参考

  • `references/ghidra-cheatsheet.md`
  • `../ida-reverse/` `../radare2/` `../binary-diff/`

路由上下文

**上游**: MASTER R22 **下游**: 动态验证 → Frida/GDB;利用 → `pwn-chain` **同级**: `ida-reverse`(商业深挖)

任务完成自检

  • [ ] 是否基于真实 Ghidra/tool-index 路径?
  • [ ] 是否标注函数地址与重命名?
  • [ ] 是否有可复现步骤?
  • [ ] Checklist / journal?
Read more
Ships withreverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Get the whole plugin
Stats
39,460
Stars
5,492
Forks
Active
Maintenance
PowerShell
Language
MIT
License
11d ago
Last commit
4mo ago
Created
3h ago
Added

Repo: zhaoxuya520/reverse-skill

Other skills on reverse-skill.

binary-diff
Skill

binary-diff

跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…