Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add satiricalguru/Agents-skills --skill reverse-engineeringgit clone --depth 1 https://github.com/satiricalguru/Agents-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/satiricalguru/agents-skills/reverse-engineering)<a href="https://agentmods.dev/skills/satiricalguru/agents-skills/reverse-engineering"><img src="https://agentmods.dev/badge/skills/satiricalguru/agents-skills/reverse-engineering/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/satiricalguru/agents-skills/reverse-engineering"><img src="https://agentmods.dev/badge/skills/satiricalguru/agents-skills/reverse-engineering.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00247 | $0.03138 |
| Opus 5.5 | $0.00099 | $0.01255 |
| Sonnet 5 | $0.00049 | $0.00628 |
| Haiku 4.5 | $0.00025 | $0.00314 |
Grade A, and why
reverse-engineering-skill scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
1. If user gave a file path, confirm it exists. If a URL, `curl -L -o /tmp/target <url>`. How it starts
The opening of the file, as written. The whole thing — 259 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Reverse Engineering Skill
You are an expert reverse engineer. When this skill triggers, your goal is full autonomous analysis — run the tools, interpret output, and produce actionable intelligence. Don't ask the user to do manual steps.
Read reverse-engineering-skill/references/tooling.md for installation commands before installing anything.
Read reverse-engineering-skill/references/report-template.md for the final report structure.
Read reverse-engineering-skill/references/mcp-backends.md for Ghidra/IDA/radare2-mcp server setup and tool APIs.
Read reverse-engineering-skill/references/cheatsheet.md during analysis for fast command lookup, import pattern recognition, and decision trees.
Tool Priority: Which Backend to Use
Check what's available in this order — use the first one that's connected:
- GhidraMCP / GhidrAssistMCP (best decompilation quality — 31 tools, free)
→ If Ghidra is running with MCP enabled, uselist_functions,decompile_function,xrefs_to, etc. - IDA Pro MCP (commercial, highest quality for stripped binaries)
→ If IDA is running with mcp-server, use the same function/xref API calls - radare2-mcp (official,
r2-mcpbinary — CLI-native, great for automation)
→ Translates r2 commands into MCP tool calls - Built-in FastMCP server (
re_mcp_server.py— always available, no external tools needed)
→ Falls back to this if none of the above are running
When using Ghidra/IDA/radare2-mcp, always start with get_program_info before anything else.
Phase 0: Resolve & Orient
- If user gave a file path, confirm it exists. If a URL,
curl -L -o /tmp/target <url>. - If the target is an archive (
.zip,.tar,.gz,.ipa,.aab), extract it first. - Detect format using
inspect_binary(built-in) orget_program_info(Ghidra/IDA/r2-mcp). - Determine the analysis goal — pick the right workflow below:
- Malware triage → Malware Analysis workflow
- CVE/vuln hunting → Vulnerability Research workflow
- CTF challenge → CTF workflow
- General understanding → Standard Triage workflow
- Firmware → Firmware workflow
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 259 lines · 247 tokens per session scan A 8a734e28a5a3
reverse-engineering-skill is a skill published in the GitHub repository satiricalguru/Agents-skills (6 stars, last pushed 8d ago), licensed MIT. It adds 247 tokens to every session and 3,138 once invoked, about $0.0010 per session on Opus 5.5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-18.
Other skills, from other repositories
vscode-doctor
Diagnose slow or freezing VS Code-compatible editors with evidence-first, zero-hardcoded-assumption workflow. Use when the user reports editor lag, typing delay, UI freezes, extension host stalls, file watcher noise, high editor CPU/RSS, uses VS Code/Cursor as a file browser over a large folder, or wants a safe editor…
review-agent-harness
Review whether a repository's coding-agent harness can reliably carry work from intent through controlled execution, verification, delivery, and learning. Use when asked to assess agent readiness, repeated agent failures, Rules/Skills/Hooks/Memory effectiveness, missing validation or recovery loops, or whether a…
codebase-audit
A read-only method for auditing an entire codebase across contracts, data integrity, errors, security, architecture, technical debt, configuration, and caching. It produces prioritized findings and a repair roadmap.
codex-agent
Use when you want a second-opinion review via Codex CLI, cross-verification after another agent implements changes, debugging help, or alternative implementation proposals. Requires Codex CLI to be installed and authenticated.
codex-log-guard
Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default. Use when a user mentions logs2.sqlite, logs2.sqlite-wal, blockloginserts, SSD/TBW wear, or explicitly asks to protect, clean up, verify, or restore Codex diagnostic logging.
flowguard
Guard long, ambiguous, or stateful AI-agent work from drift. Use when the user asks to run or continue a multi-step task, autonomous loop, bug fix, repo change, PR readiness check, compaction handoff, resume from previous context, cost-control checkpoint, or any task likely to span many tool calls, files, sessions…