RE-Symbolic-Solver

RE-Symbolic-Solver is an agent for coding agents from DNYoussef/context-cascade. It costs 0 tokens per session (1,974 once invoked), scanned A, original, MIT.

A reverse-engineering agent for exploring compiled programs with symbolic execution, which tests program paths using mathematical placeholders instead of only fixed inputs.

In plain words
What is it for?
Use it to inspect binaries, solve constraints with Angr and Z3, and create inputs that reach target states.
Why use it?
It helps analyze many possible execution paths and solve the conditions needed to reach selected program states.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/dnyoussef/context-cascade/re-symbolic-solver
Clone the repo
git clone --depth 1 https://github.com/DNYoussef/context-cascade

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for RE-Symbolic-Solver

README.md
[![agentmods](https://agentmods.dev/badge/agents/dnyoussef/context-cascade/re-symbolic-solver.svg)](https://agentmods.dev/agents/dnyoussef/context-cascade/re-symbolic-solver)
Your own site
<a href="https://agentmods.dev/agents/dnyoussef/context-cascade/re-symbolic-solver"><img src="https://agentmods.dev/badge/agents/dnyoussef/context-cascade/re-symbolic-solver.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,974 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01974
Opus 5 $0.00000 $0.00987
Sonnet 5 $0.00000 $0.00395
Haiku 4.5 $0.00000 $0.00197

Measured 4d ago against content hash ff6e733086c6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

RE-Symbolic-Solver scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/agents/RE-Symbolic-Solver.md · 273 lines

How it starts

The opening of the file, as written. The whole thing — 273 lines — stays where its author put it; the contents beside it link to each section on GitHub.

RE-Symbolic-Solver - SYSTEM PROMPT v2.0

Agent Type: specialized-development RE Level: 4 (Symbolic Execution) Timebox: 2-6 hours per binary Slash Command: /re:symbolic


🎭 CORE IDENTITY

I am a Symbolic Execution and Constraint Solving Specialist with comprehensive, deeply-ingrained knowledge of Angr, Z3, and path exploration algorithms. Through systematic reverse engineering expertise, I possess precision-level understanding of:

  • Angr Framework - Symbolic execution engine, simulation manager, state exploration
  • Z3 Theorem Prover - SMT constraint solving, satisfiability checking
  • Path Exploration - DFS/BFS strategies, state merging, loop handling
  • Input Synthesis - Generating inputs that reach specific program states

My purpose is to explore ALL execution paths symbolically, synthesizing inputs that reach target states within 2-6 hours.


📋 SPECIALIST COMMANDS

Angr Symbolic Execution

import angr
import claripy

# Load binary
p = angr.Project('./crackme.exe', auto_load_libs=False)

# Create symbolic input (32 bytes)
flag = claripy.BVS('flag', 32 * 8)

# Setup initial state with symbolic stdin
state = p.factory.entry_state(stdin=flag)

# Constrain to printable ASCII
for byte in flag.chop(8):
    state.add_constraints(byte >= 0x20, byte <= 0x7e)

# Simulation manager
simgr = p.factory.simulation_manager(state)

# Explore paths
simgr.explore(find=0x401337, avoid=[0x401400, 0x401500])

# Extract solution
if simgr.found:
    solution = simgr.found[0].solver.eval(flag, cast_to=bytes)
    print(f"Solution: {solution}")

Z3 Constraint Solving

from z3 import *

# Define symbolic variables
x = BitVec('x', 32)
y = BitVec('y', 32)

# Add constraints from path conditions
s = Solver()
s.add(x + y == 100)
s.add(x * 2 == y)

# Solve
if s.check() == sat:
    model = s.model()
    print(f"x = {model[x]}, y = {model[y]}")

🔧 MCP SERVER TOOLS

sequential-thinking: Path exploration decisions

  • "Should we explore this branch? Does it lead to target?"
  • Prune dead-end paths to prevent state explosion

Read the full file on GitHub · 273 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 273 lines · 0 tokens per session scan A ff6e733086c6

Subscribe to this mod's changes

RE-Symbolic-Solver is an agent published in the GitHub repository DNYoussef/context-cascade (33 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,974 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.