reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user
$ npx -y skills add zhaoxuya520/reverse-skill --skill radare2 --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/radare2Context preview
The summary Claude sees to decide when to auto-load this skill.
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user
name: radare2 description: | Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together with CLI analysis, `rabin2`, `rasm2`, `radiff2`, `r2pipe`, or asks for radare2 command help on Windows/Linux/macOS.
面向 `radare2` CLI 的二进制分析技能。重点是直接用命令行完成侦察、分析、定位、导出和轻量修改,不依赖 GUI。
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认当前任务是否命中本 skill 的适用范围 3. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 4. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 5. `ACT`: 进入"工作流"第一步并执行,不要停在确认状态
当用户有这些意图时应优先使用本 skill:
如果用户明确要 GUI 逆向、Hex-Rays 风格伪代码、或 IDA 工作流,优先考虑 `ida-reverse`。如果是网页 JS 逆向,优先考虑 `reverse-engineering`。
先不要假设 `r2` 可用。先检查:
r2 -v rabin2 -v
如果未安装,再检查常见安装位置或提示安装。
Windows 常见可执行文件:
这个 skill 自带两个资源,优先复用,不要每次临时组织一套重复命令。
标准侦察脚本,适合先做第一轮概况分析。会输出:
调用方式:
powershell -File "<skill-root>\radare2\scripts\recon.ps1" -TargetPath "C:\path\to\sample.exe"
如果需要附带 `r2` 自动分析:
powershell -File "<skill-root>\radare2\scripts\recon.ps1" -TargetPath "C:\path\to\sample.exe" -RunAnalysis
当需要更多命令细节、常见场景模板、或要快速回忆语法时,读取这个速查表,而不是凭记忆硬猜。
某些 PE 文件在 `rabin2` 侦察时,可能出现类似下面的告警:
ERROR: Cannot find ...\share\format\dll\*.sdb
如果主体输出仍然正常返回,通常不影响基础侦察结论,先继续分析即可。不要因为这类附带告警就直接判定分析失败。
不要一上来就全量自动分析。先用轻量命令确认文件类型、架构、入口点、字符串、导入表,再决定是否做 `aaa`、`aaaa` 或定向分析。
`radare2` 命令非常多,用户通常只需要最短路径:
如果用户要 patch 二进制:
适合刚拿到一个二进制文件时。
对 PE/ELF/Mach-O 等含导入表的二进制,**MUST** 先完成导入表检查并落成 Evidence,再进入函数级分析或动态步骤:
1. 执行 `rabin2 -i <sample>`(或 `recon.ps1` 输出中的 imports 段);DLL/SYS 另 MUST `rabin2 -E` 并记 `E-exports` 2. 将完整/分类后的导入表结果写入 Evidence(建议 id:`E-imports` 或 `E-triage-imports`),至少包含:
3. .NET 等无传统 IAT:MUST 走等价锚点(dnSpy/IL/元数据摘要)写入同一 Evidence 语义槽,禁止空过 4. 加壳样本 IAT 修复:x86 用 ImportREC(或等价)、x64 用 Scylla(或等价)。修复失败 MUST 记 `E-iat-repair-fail` 后转动态 API 断点;**禁止**在静态 IAT 上无限死磕(见 `reverse-engineering/references/re-agent-workflow.md` §1.2) 5. 用户明确要求「重做导入表检查 / 重新检查导入表 / 重做 IAT」时:MUST 重做被点名步骤本身(阻塞时先走可行性门闩:说明前提+请确认;强制则标 quality=unreadable),**禁止改换为无关步骤冒充完成**
未记录导入表(或合法等价锚点 / IAT 失败旁路)Evidence 前:MUST NOT 声称「基础侦察完成」,MUST NOT 进入工作流 2+ 的深挖结论。
优先直接运行内置脚本:
powershell -File "<skill-root>\radare2\scripts\recon.ps1" -TargetPath "sample.exe"
如果只需要手动最小命令,则使用:
rabin2 -I sample.exe rabin2 -z sample.exe rabin2 -i sample.exe rabin2 -E sample.exe
关注点:
r2 sample.exe
进入后常用:
aaa # 常规自动分析 afl # 列出函数 iz # 列出字符串 iS # 列节区 is # 列符号 s entry0 # 跳到入口点 pdf # 反汇编当前函数 VV # 进入可视化模式(如果终端适合) q # 退出
说明:
afl~main afl~sym. iz~http iz~error axt <addr>
思路:
px 64 # 当前地址起 64 字节十六进制 pd 20 # 反汇编 20 条指令 psz # 读取当前地址字符串 pxa # 更友好的十六进制视图
仅当用户明确要求修改文件时使用:
r2 -w sample.exe
进入后例如:
s 0x401000 wa nop wa jmp 0x401050 wq
常见写操作:
修改前最好先备份原文件。如果用户没提备份,至少提醒一次。
适合一次性输出结果:
r2 -A -q -c "afl;iz;ii;q" sample.exe
常用参数:
如果命令很多,优先整理成易读顺序,不要塞入难以维护的超长串。
更推荐先用内置侦察脚本打底,再决定要不要补定制命令。
适合静态信息提取:
rabin2 -I sample.exe # 基本信息 rabin2 -S sample.exe # 节区 rabin2 -s sample.exe # 符号 rabin2 -i sample.exe # 导入 rabin2 -E sample.exe # 导出 rabin2 -z sample.exe # 字符串 rabin2 -zz sample.exe # 更详细字符串
适合快速汇编/反汇编:
rasm2 -d "9090" rasm2 -a x86 -b 64 "xor eax, eax"
适合对比两个二进制:
radiff2 old.exe new.exe radiff2 -C old.exe new.exe
适合算哈希:
rahash2 -a md5 sample.exe rahash2 -a sha256 sample.exe
适合进制和编码转换:
rax2 0x401000 rax2 4198400 rax2 -s hello
遇到未知样本时,按这个顺序做:
1. `rabin2 -I` 看格式、架构、入口点 2. `rabin2 -z` 看字符串 3. `rabin2 -i` 看导入函数 — **MUST + Evidence(硬门,见工作流 1)** 4. 如需交互分析,再进 `r2`(仅当步骤 3 的 Evidence 已落盘) 5. 先 `aaa`,再 `afl` / `iz` / `pdf` 6. 通过字符串引用、导入调用、入口流程逐步定位关键函数
这个顺序的好处是噪音低,能尽快建立方向感。步骤 3 不是可选优化,是进入深挖前的硬门。
当用户不是只要命令,而是要你实际分析文件时:
不要只罗列命令而不解释为什么这么做。
用户:`帮我看看这个 exe 干了什么,用 radare2 就行`
处理方式:
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…