decompile

A command that uses Ghidra, a software-analysis tool, to decompile a compiled program into a more readable form and analyze its functions.

In plain words
What is it for?
Use it to decompile a binary, focus on a named function, list functions, and fall back to radare2 when Ghidra is unavailable.
Why use it?
It helps you inspect program logic when the original source code is unavailable.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/ogrodev/fsociety/decompile
Clone the repo
git clone --depth 1 https://github.com/ogrodev/fsociety
Per session 11 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 622 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00011 $0.00622
Opus 5 $0.00005 $0.00311
Sonnet 5 $0.00002 $0.00124
Haiku 4.5 $0.00001 $0.00062

Measured 2d ago against content hash 48a59c9e1f66, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

decompile scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

If missing, inform user and suggest: `sudo apt install -y ghidra`
romero/commands/decompile.md · 71 lines

How it starts

The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Storage Policy: ALL output files MUST be saved in the project directory. NEVER write to /tmp/ or any system temporary directory.

Ghidra Headless Decompilation

Parse $ARGUMENTS for the binary path and optional --function <name> flag.

Pre-flight

  1. Verify Ghidra is installed:

    node "${CLAUDE_PLUGIN_ROOT}/scripts/tool-checker.js" check ghidra
    

    If missing, inform user and suggest: sudo apt install -y ghidra

  2. Locate analyzeHeadless:

    find /opt/ghidra* /usr/share/ghidra -name analyzeHeadless 2>/dev/null | head -1
    

Step 1 — Create Project Directory

mkdir -p extracted/ghidra-projects

Step 2 — Run Headless Analysis

analyzeHeadless extracted/ghidra-projects ProjectName \
  -import <binary> \
  -overwrite \
  -analysisTimeoutPerFile 300 \
  -postScript ExportDecompilation.java \
  -scriptPath /path/to/scripts

If ExportDecompilation script is not available, use radare2 as fallback:

r2 -qc 'aaa; pdd @main' <binary>      # Decompile main
r2 -qc 'aaa; afl~[0]' <binary>        # List function addresses
r2 -qc 'aaa; pdd @<addr>' <binary>    # Decompile specific function

Step 3 — Targeted Decompilation

If --function <name> was specified:

r2 -qc 'aaa; s <name>; pdd' <binary>

Step 4 — Key Function Identification

Focus on functions that reference:

  • Network: WSAStartup, connect, send, recv, InternetOpen, HttpSendRequest
  • File I/O: CreateFile, WriteFile, DeleteFile, CopyFile
  • Process: CreateProcess, VirtualAlloc, WriteProcessMemory, CreateRemoteThread
  • Registry: RegCreateKey, RegSetValue, RegOpenKey
  • Crypto: CryptEncrypt, CryptDecrypt, BCryptGenRandom
  • Anti-Debug: IsDebuggerPresent, NtQueryInformationProcess, CheckRemoteDebuggerPresent

Step 5 — Save Output

Save decompiled code to extracted/decompiled-<binary-name>/. Generate summary with key functions annotated.

Read the full file on GitHub · 71 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 71 lines · 11 tokens per session scan B 48a59c9e1f66

Subscribe to this mod's changes

decompile is a command published in the GitHub repository ogrodev/fsociety (20 stars, last pushed 5mo ago), licensed MIT. It adds 11 tokens to every session and 622 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.