unpack

unpack is a command for Claude Code from SetsunaYukiOvO/x64dbg-mcp. It costs 10 tokens per session (849 once invoked), scanned A, original, MIT.

A manual workflow for unpacking protected or compressed Windows executable files while examining them in x64dbg or x32dbg, Windows debuggers.

In plain words
What is it for?
Use it to inspect packed executables, analyze sections and imports, detect the original entry point, and dump the unpacked program for further analysis.
Why use it?
Packing can hide a program's actual code and imports, making ordinary analysis difficult. The workflow provides a sequence for identifying the packer and finding the original entry point.

Command for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: positional $N argument.

Part of the skills plugin — 1 skill, 11 commands shipped together

Good fit Use it to inspect packed executables, analyze sections and imports, detect the original entry point, and dump the unpacked program for further analysis.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/setsunayukiovo/x64dbg-mcp/unpack
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/SetsunaYukiOvO/x64dbg-mcp

Made for: Claude Code.

Or install skills, the plugin that ships this one along with the rest of its 1 skill, 11 commands.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for unpack

README.md
[![agentmods](https://agentmods.dev/badge/commands/setsunayukiovo/x64dbg-mcp/unpack/github.svg)](https://agentmods.dev/commands/setsunayukiovo/x64dbg-mcp/unpack)
Your own site
<a href="https://agentmods.dev/commands/setsunayukiovo/x64dbg-mcp/unpack"><img src="https://agentmods.dev/badge/commands/setsunayukiovo/x64dbg-mcp/unpack/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for unpack

Your own site · 80×15
<a href="https://agentmods.dev/commands/setsunayukiovo/x64dbg-mcp/unpack"><img src="https://agentmods.dev/badge/commands/setsunayukiovo/x64dbg-mcp/unpack.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 10 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 849 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00010 $0.00849
Opus 5 $0.00005 $0.00425
Sonnet 5 $0.00002 $0.00170
Haiku 4.5 $0.00001 $0.00085

Measured 11d ago against content hash 1e6abfac2fd8, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

unpack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/commands/unpack.md · 74 lines

How it starts

The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a binary unpacking specialist connected to x64dbg/x32dbg via MCP. Help unpack a packed or protected executable through manual analysis.

Phase 1: Packer Detection & Analysis

  1. Call debug_get_state to ensure the debugger is paused (ideally at the entry point).
  2. Call module_get_main to identify the target module.
  3. Call dump_analyze_module to get comprehensive analysis:
    • Section names (UPX0/UPX1, .themida, .vmp, .aspack = known packers)
    • Section entropy (> 7.0 = likely packed/encrypted)
    • Entry point location relative to sections
    • Import count (very few imports = likely packed)
  4. Call module_get_imports on the main module to see what APIs the packer stub uses.
  5. Call disassembly_at at the entry point with count: 30 to examine the packer stub.

Phase 2: OEP Detection

  1. Call dump_detect_oep with the target module for automatic pattern-based OEP detection.
  2. If auto-detection fails, use manual approaches based on packer hint "$1":
    • UPX: Look for POPAD + JMP sequence — set breakpoint_set on VirtualProtect, run, then single-step to the JMP target.
    • ASPack: Set breakpoint_set on kernel32.VirtualProtect and watch for section permission changes.
    • Themida/VMProtect: Set breakpoint_set on kernel32.VirtualAlloc and monitor for executable memory allocation.
    • General: Use eval_expression to compute the first section base, then set a hardware write breakpoint on it.
  3. Once a candidate OEP is found, use disassembly_at at that address to verify it looks like real code (function prologue, not stub code).
  4. Use bookmark_set on the OEP to mark it for later reference.

Phase 3: Run to OEP & Dump

  1. Use debug_run_to with the OEP address to let the unpacker decompress the code.
  2. Verify with debug_get_state that execution reached the OEP.
  3. Call function_get at the OEP to check if the active debugger recognizes a function there.
  4. Call dump_module with the oep parameter set to the detected OEP:
    • module: target module name
    • output_path: [original_name]_unpacked.exe
    • oep: the OEP address from step 6/7
  5. Call dump_analyze_module to verify the dump is valid.

Read the full file on GitHub · 74 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 74 lines · 10 tokens per session scan A 1e6abfac2fd8

Subscribe to this mod's changes

unpack is a command published in the GitHub repository SetsunaYukiOvO/x64dbg-mcp (460 stars, last pushed 21d ago), licensed MIT. It adds 10 tokens to every session and 849 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.