Skip to content
Security
Skill

/ida-reverse

IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering".

BOOST
From plugin
reverse-skill
39k46 skills
Install
$ npx -y skills add zhaoxuya520/reverse-skill --skill ida-reverse --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/ida-reverse

Context preview

The summary Claude sees to decide when to auto-load this skill.

IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering".

SKILL.md

ida-reverse.SKILL.md
name: ida-reverse
description: |
  IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。

  Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or "reverse engineering". This includes requests like "看看这个exe", "分析这个dll", "帮我破解", "找一下密码", "这个软件怎么注册", etc.

  Use the bundled scripts (scripts/start.ps1, scripts/open.ps1) for deterministic server management and file opening — do NOT write ad-hoc PowerShell commands for these operations.

IDA Pro 逆向分析技能

ACTION REQUIRED(读完后立刻执行)

1. `NOW`: 读取 `../field-journal/precedent-reverse.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认当前任务是否命中本 skill 的适用范围 3. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 4. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 5. `ACT`: 进入"工作流"第一步并执行,不要停在确认状态

已知问题与反思(必读)

踩过的坑

1. **`idb_open`(旧名 `idalib_open`)不要直接靠部分 AI 客户端 MCP 调用**

  • 部分代码 AI 客户端 的 MCP 客户端对 open 类工具的 output schema 校验有 BUG
  • 报错:`Structured content does not match the tool's output schema`
  • **解决办法**:使用 `scripts/open.ps1` 脚本通过 HTTP API 直调,绕过 MCP 校验层
  • 当前 ida-pro-mcp 2.x 工具名为 `idb_open` / `idb_list` / `idb_save`(不再是 `idalib_*`)
  • 文件打开后返回 `session_id`(database),后续工具调用需带该 session

2. **`C:\Windows\System32\` 文件无权限打开**

  • idalib 无法直接读取 System32 目录下的文件
  • **解决办法**:`open.ps1` 自动检测并复制到 `临时目录` 目录后再打开

3. **启动服务器命令阻塞对话**

  • `idalib-mcp` 启动后会持续输出 INFO 日志到控制台
  • **解决办法**:使用 `scripts/start.ps1`(`-WindowStyle Hidden` 后台静默启动)
  • 脚本会等待服务就绪后自动退出,不阻塞对话

4. **MCP 服务器名不能用横线**

  • 之前用 `ida-pro-mcp` 作为服务器名,可能引起工具注册问题
  • **当前配置**:服务器名 `idapro`,工具前缀 `idapro_*`

5. **Remote HTTP vs Local Stdio**

  • `type:"local"`(stdio)模式:`idalib_open` 同样有 schema 校验问题
  • `type:"remote"`(HTTP)模式:可以先用脚本直开文件,再用 MCP 工具
  • **当前方案**:Remote HTTP 模式

6. **PR #389 修复了部分 schema 问题**

  • 作者 mrexodia 在 issue #388 后通过 PR #389 合并了修复
  • 修复了 HTTP 模式下的 structuredContent schema,但 部分代码 AI 客户端 侧校验仍有问题
  • 已安装最新 `main` 分支版本

7. **idalib 超时留下孤儿 worker 进程锁文件**

  • 第一次 `open.ps1` 超时后,idalib 的 python worker 子进程可能变成孤儿,咬着 `.id0`/`.id1`/`.nam` 不放
  • 后续任何工具或手动拖入 IDA GUI 都会报"权限不足"
  • **禁止** `taskkill /F /T` 杀进程树——`/T` 会把 GUI `ida.exe` 子进程一起干掉
  • **解决办法**:`start.ps1` 只在端口无人监听、或 `tools/list` 快速返回但缺 `py_eval`(旧 supervisor)时替换 managed supervisor;RPC 超时且 13337 仍在听视为忙,不杀。开库时 `open.ps1` 写 `opening.lock`,watchdog 不得 `-Force`
  • **死锁例外**:`tools/list` **连续失败超过 3 分钟**(按 last-healthy 时间戳,不是进程创建时间),且没有 in-flight `opening.lock`、不是 GUI 占端口时,才 `-Force` 替换 supervisor,仍不杀 `ida.exe`
  • **兜底**:`open.ps1` 检测到旧库被锁自动复制到 Temp 并加 GUID 前缀

8. **带自动分析打开看起来像卡死**

  • `idalib_open(run_auto_analysis=true)` 可能长时间不回包,但后端实际上仍在继续打开和分析
  • 之前用户侧看到的是“PowerShell 一直无输出”,容易误判成脚本卡死
  • **当前解决办法**:`open.ps1` 新增 `-TimeoutSeconds`,并改为后台请求 + 前台轮询 + 定时进度输出
  • 轮询到会话已就绪时会提前返回 `OK:文件名:session_id`,超时则返回 `ERR:open_timeout_xxs`

9. **HTTP MCP 会在登录后静默退出**

  • Cursor/Claude 的 `type: http` 不会代为拉起进程;旧计划任务只在登录时跑一次
  • `pythonw` 无控制台,崩溃时 Application 日志也是空的
  • **解决办法**:`start.ps1` 默认健康则复用;`watchdog.ps1` 每分钟巡检;日志在 `%LOCALAPPDATA%\reverse-skill\ida-mcp\`
  • 安装:`scripts/install-autostart.ps1`。HTTP 客户端若启动时端口还没起来,仍需在 MCP 面板手动刷新一次

10. **Streamable HTTP GET `/mcp` 会卡住单线程 supervisor**

  • 部分 HTTP MCP 客户端会对 `/mcp` 发长连接 GET(SSE)。stock `idalib_supervisor` 用 `background=False` 的 `HTTPServer`,一次只处理一个请求
  • 结果:`tools/list` 超时,客户端把 `idapro` 标成 error
  • **解决办法**:`run-supervisor.py` 把 HTTP 换成 `ThreadingHTTPServer` 并接受 GET `/mcp`;补丁失败则跳过并仍启动 supervisor。卡住时用 `scripts/recover.ps1`(立刻 `-Force`)

工作流程原则

| 步骤 | 做什么 | 用什么 | |------|--------|--------| | 1 | 确保 HTTP 服务器在运行 | `scripts/start.ps1`(无参数) | | 2 | 打开目标二进制文件 | `scripts/open.ps1 -Path "xxx.exe"` | | 3 | 使用 MCP 分析工具 | 直接调用 `idapro_*` / HTTP tools(约 65 个,视版本而定) | | 4 | 分析完毕 | 工具自动可用 |

脚本资源

start.ps1 — 启动 MCP HTTP 服务器

路径:`scripts/start.ps1`

  • 自动解析 `IDADIR`(环境变量 / 便携版桌面路径 / 常见安装路径)
  • 优先用 IDA 自带 `Python314\python.exe -m ida_pro_mcp.idalib_supervisor`
  • 默认先探测 `http://127.0.0.1:13337/mcp`,健康则输出 `OK:<n>:reuse` 并退出
  • 13337 在听但 `tools/list` 超时 → `WARN:busy` / `OK:busy:reuse`,**不杀**(开库或 GUI 占用时无法回包)
  • `tools/list` **连续失败超过 3 分钟**(last-healthy 时间戳)且无 `opening.lock` → 视为死锁,输出 `INFO:deadlock` 并 `-Force` 替换 supervisor。进行中的 `idb_open` 和 GUI 不会走这条路径
  • 仅在端口无人监听、缺 `py_eval`、或上述死锁时替换 managed supervisor;**永不杀 `ida.exe`,不用 `taskkill /T`**
  • GUI 占用 13337 时输出 `WARN:gui_busy` 并退出,不另起 supervisor
  • 成功输出 `OK:<工具数>`(当前约 66),失败输出 `ERR:timeout`
  • supervisor 日志:`%LOCALAPPDATA%\reverse-skill\ida-mcp\supervisor.log`
  • 服务器在后台运行,不阻塞对话

**调用方式**:

powershell -File "<skill-root>\ida-reverse\scripts\start.ps1"

watchdog.ps1 / recover.ps1 / install-autostart.ps1 — 保活

  • `watchdog.ps1`:探测 13337;健康 reuse(并刷新 last-healthy);GUI / `open.ps1` 开库锁 / last-healthy 未满 3 分钟的 busy → reuse;只有 `tools/list` 连续失败超过 3 分钟才 `start.ps1 -Force`
  • `recover.ps1`:立刻 `start.ps1 -Force`(不杀 `ida.exe`)。HTTP 客户端把 `idapro` 标成 error 时用这个
  • `install-autostart.ps1`:注册计划任务 `reverse-skill-ida-mcp`(登录 + 每分钟)
  • 日志:`%LOCALAPPDATA%\reverse-skill\ida-mcp\watchdog.log`

open.ps1 — 打开二进制文件

路径:`scripts/open.ps1`

  • 通过 HTTP API 直调 `idb_open`,绕过 MCP schema 校验
  • 自动检测 System32 路径并复制到临时目录
  • 自动清理同名旧数据库文件(`.id0`/`.id1`/`.nam`/`.til`/`.i64`)
  • 旧库被锁时自动降级:复制到 Temp 加 GUID 前缀后打开,不报错
  • 将打开请求放到后台执行,避免长时间同步等待导致脚本无响应
  • 支持 `-TimeoutSeconds`,超时后返回 `ERR:open_timeout_xxs`,不会无限卡住
  • 每隔 10 秒输出一次 `INFO:opening:已用时/超时秒数`,便于判断仍在分析中
  • 成功输出 `OK:文件名:session_id`,降级时加 `(temp copy)` 标记
  • 失败时自动重试走 Temp 副本

**调用方式**:

powershell -File "<skill-root>\ida-reverse\scripts\open.ps1" -Path "C:\path\to\file.exe"

**可选参数**:

# 指定 SessionId
powershell -File "scripts\open.ps1" -Path "file.exe" -SessionId "my_session"

# 跳过自动分析(大文件推荐)
powershell -File "scripts\open.ps1" -Path "large.exe" -NoAutoAnalysis

# 设置超时,避免带自动分析时长时间无返回
powershell -File "scripts\open.ps1" -Path "file.exe" -TimeoutSeconds 600

**输出约定**:

# 分析进行中(每 10 秒输出一次)
INFO:opening:11/600s

# 成功打开
OK:sample.exe:abcd1234

# 成功打开,但因锁文件降级到 Temp 副本
OK:1234abcd-sample.exe:abc
Read more
Ships withreverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Get the whole plugin
Stats
39,460
Stars
5,492
Forks
Active
Maintenance
PowerShell
Language
MIT
License
11d ago
Last commit
4mo ago
Created
3h ago
Added

Repo: zhaoxuya520/reverse-skill

Other skills on reverse-skill.

binary-diff
Skill

binary-diff

跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…