
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
reverse-engineering-skill
Advanced tools
Deterministic binary analysis, runtime instrumentation & protocol reverse-engineering skill for AI coding agents.
A practical, deterministic reverse engineering playbook and toolset designed for AI coding agents and human engineers alike.
When you hand an AI coding assistant a mystery binary, a stripped executable, or an unknown network protocol, it usually does one of two things:
This repository is an agent skill that solves that problem. It equips an AI agent (or you in a terminal) with a disciplined methodology and standalone helper scripts. Instead of guessing, the agent runs concrete tools, measures entropy, extracts real symbols, traces runtime behaviors, and produces verifiable specifications.
The core rule is simple: Scripts do the math; the LLM does the semantics.
.gopclntab (Go 1.2 through 1.24+).Option<T>, Result<T>), and maps panic machinery..class, JAR, APK, and DEX structures via Jadx..pyc), PyInstaller (MEI), and Nuitka wrappers..
├── SKILL.md # Agent skill entrypoint (decision tree & core directives)
├── assets/
│ └── banner.svg # Repository banner
├── scripts/ # Standalone, zero-dependency helper scripts
│ ├── triage_binary.py # Detects container, arch, compiler hints, and file entropy
│ ├── calculate_entropy.py # Computes section-by-section Shannon entropy
│ ├── extract_go_metadata.py # Locates .gopclntab & extracts symbols from stripped Go binaries
│ ├── validate_struct.py # Validates recovered struct field offsets and padding
│ ├── ghidra_headless.sh # Bash wrapper for headless Ghidra batch decompilation
│ ├── decompile_functions.py # Ghidra post-script to export C pseudocode
│ └── frida_templates/ # Production-ready Frida dynamic instrumentation scripts
│ ├── hook_crypto.js # Intercepts AES, RC4, HMAC, and OpenSSL EVP calls
│ ├── ssl_unpin.js # Universal TLS pinning bypass (iOS, macOS, Android, Linux)
│ └── trace_ipc.js # Hooks read/write/send/recv and Mach messages with byte previews
├── references/ # Focused, modular runbooks (loaded on demand)
│ ├── 01-triage.md # Phase 1: Container detection, magic bytes, compiler signatures
│ ├── 02-binary-analysis.md# Assembly idiom translation (x86_64 / ARM64), vtable recovery
│ ├── 03-modern-binaries.md# Go runtime structures, Rust layouts, WASM, Swift
│ ├── 04-managed-runtimes.md # JVM, .NET, Electron/ASAR, Python bytecode versions
│ ├── 05-protocols-ipc.md # Framing inference, state machine modeling, wire structs
│ ├── 06-deobfuscation-dyn.md # Flattening, opaque predicates, MBA, Frida hooks, SMT/Z3
│ ├── 07-cleanroom.md # Clean-room specification freezing & reimplementation rules
│ ├── 08-output-standards.md # Exact templates for deliverable reports and evidence tags
│ ├── 09-checklist.md # Final quality-assurance verification checklist
│ └── 10-mcp-tooling.md # Model Context Protocol integration (Ghidra, Binary Ninja, IDA)
└── examples/ # Realistic end-to-end case studies
├── go_stripped_reversal.md # Reversing a stripped Go malware binary step-by-step
└── custom_protocol_pcap.md # Reconstructing a binary wire protocol from packet captures
You can run the tools directly with npx or install the package globally:
# Run triage on a binary directly without installing:
npx reverse-engineering-skill triage /path/to/binary
# Or install the skill files into your project's .agent/skills directory:
npx reverse-engineering-skill install
You don't need any complex setup or heavy dependencies to run the core scripts. All Python utilities use standard library modules.
Get container type, CPU architecture, compiler clues, and overall entropy in under a second:
python3 scripts/triage_binary.py /path/to/binary
Example output:
File: target_binary (34,640 bytes)
Container: Mach-O 64-bit (ARM64)
Entropy: 5.25 bits/byte (normal)
Compiler: Go
Suggested: triage template in 01-triage.md
Measure section-by-section Shannon entropy. Any section scoring > 7.0 is usually compressed, packed (UPX, VMProtect), or encrypted:
python3 scripts/calculate_entropy.py /path/to/binary
Go binaries ship their own symbol and function table inside .gopclntab. This script extracts all function names even after strip has removed standard symbol tables:
python3 scripts/extract_go_metadata.py /path/to/stripped_go_binary
When you've figured out fields and offsets from assembly or memory dumps, write a simple JSON schema and verify that there are no overlapping fields or unexpected alignment holes:
python3 scripts/validate_struct.py struct.json
Inject non-invasive Frida hooks without modifying the target binary:
# Bypass TLS certificate pinning to inspect HTTPS/TLS traffic
frida -n target_process -l scripts/frida_templates/ssl_unpin.js
# Capture encryption keys and plaintext buffers in memory
frida -n target_process -l scripts/frida_templates/hook_crypto.js
# Monitor raw IPC packets (sockets, pipes, Mach messages)
frida -n target_process -l scripts/frida_templates/trace_ipc.js
This repo is built following the Progressive Disclosure pattern:
SKILL.md): The main skill instruction file stays under 80 lines. It defines strict rules (e.g. no hand-calculating offsets, always cite evidence tags like observed:, inferred:, proposed:) and features a quick decision matrix.references/): Instead of drowning the agent's context window with thousands of lines of documentation, the agent only reads the specific guide it needs (e.g. 03-modern-binaries.md for Go/Rust, or 05-protocols-ipc.md for wire framing).When working on binary reversing, assumptions lead to broken implementations. Every finding produced under this skill is tagged with a clear confidence marker:
observed: Directly verified from disassembly, string table, or runtime trace.inferred: Deduced from surrounding context, calling conventions, or struct offsets.proposed: A hypothetical label or name created to aid understanding.web: Verified from external specifications, RFCs, or official documentation.TBD (unverified): Explicit marker showing where evidence is still missing.IMPORTANT: This skill, its documentation, templates, and associated scripts are provided strictly for educational, research, security auditing, interoperability, and defensive analysis purposes.
references/07-cleanroom.md. Never copy, paste, or incorporate proprietary decompiled code directly into production software. Extract only non-copyrightable functional specifications, interface definitions, and state transitions.This project is licensed under the MIT License. Free for personal, academic, and commercial reverse engineering workflows.
FAQs
Deterministic binary analysis, runtime instrumentation & protocol reverse-engineering skill for AI coding agents.
The npm package reverse-engineering-skill receives a total of 21 weekly downloads. As such, reverse-engineering-skill popularity was classified as not popular.
We found that reverse-engineering-skill demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.