Skill Claude CodeCodex
Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.
A general-purpose cross-platform reverse-engineering tool covering active Web intrusion, Windows PE/EXE/DLL, Android APK, iOS IPA, and API reverse engineering. Supports the complete workflow from static analysis, packer detection, unpacking, and decompilation to source code modification and rebuilding. Use when users send binary files (.exe/.dll/.apk/.ipa/.app) and request reverse engineering, analysis, unpacking, decompilation, modification, repackaging, or finding flags/serial numbers/APIs. Su
This repository also configures its own agents. See what PE-reverse-skill tells them →
Skill Claude CodeCodex
Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.
Skill Claude CodeCodex
Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
Skill Claude CodeCodex
Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
Skill Claude CodeCodex
Plan offline classification of supplied archives and package ecosystems before selecting specialized reverse-engineering subskills.
Skill Claude CodeCodex
A method for comparing software before and after a vendor patch to infer the vulnerability that was fixed and create a proof of concept. A proof of concept is a controlled demonstration that a flaw can be triggered.
Skill Claude CodeCodex
Perform deeper local, offline PE reasoning from collected static evidence. Use for control-flow maps, data-flow tracing, decoder reconstruction, API-use interpretation, and bounded disassembly review without executing the target.
Skill Claude CodeCodex
Analyze PE structure with local, offline static methods. Use for DOS and NT headers, sections, data directories, imports, exports, resources, strings, compiler clues, and static indicators without executing a target.
Skill Claude CodeCodex
Perform a local, offline first-pass intake of a PE file or PE analysis case. Use for headers, basic metadata, hashes, imports, sections, and an evidence-first scope statement without running the target.
Skill Claude CodeCodex
A toolkit for active penetration testing, which is an authorized attempt to find and verify security weaknesses in systems. It covers tasks such as reconnaissance, port and vulnerability scanning, web testing, SQL injection, directory discovery, and password cracking.
Skill Claude Code
A structured workflow for finding and reporting security vulnerabilities through bug-bounty or coordinated testing programs. It covers reconnaissance, testing, attack examples, payloads, bypass variants, and disclosed vulnerability cases.
Skill Claude CodeCodex
Review planning for license controls, integrity checks, anti-tamper mechanisms, and anti-cheat protections.
Skill Claude CodeCodex
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
Skill Claude CodeCodex
A step-by-step method for turning a discovered binary vulnerability into a working exploit. It covers stack overflows, heap attacks, and kernel attacks, including the differences between local tests and remote targets.
Skill Claude CodeCodex
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together…
Skill Claude CodeCodex
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
Skill Claude Code
Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it…
Skill Claude CodeCodex
Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. Use when analyzing IIFE or switch-based opcode dispatchers, extracting instruction tables, recovering bytecode semantics, capturing VM state at runtime, or reconstructing execution flow.
Skill Claude CodeCodex
Reconstruct evidence-labeled pseudocode and program structure from PE analysis records. Use when translating static observations into functions, types, data models, module boundaries, or human-readable behavior without claiming unavailable source code.
Skill Claude CodeCodex
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
Skill Claude CodeCodex
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
Skill Claude CodeCodex
Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
Skill Claude CodeCodex
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
Skill Claude CodeCodex
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
Skill Codex
A skill for authorized security testing of desktop applications, called thick clients, that run substantial code on the user's computer. It examines local data, updates, communication between processes, network traffic, and trust boundaries.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: