Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add SeaOf0/dsh-redteam-model --skill ida-reversegit clone --depth 1 https://github.com/SeaOf0/dsh-redteam-modelWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/seaof0/dsh-redteam-model/ida-reverse)<a href="https://agentmods.dev/skills/seaof0/dsh-redteam-model/ida-reverse"><img src="https://agentmods.dev/badge/skills/seaof0/dsh-redteam-model/ida-reverse/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/seaof0/dsh-redteam-model/ida-reverse"><img src="https://agentmods.dev/badge/skills/seaof0/dsh-redteam-model/ida-reverse.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high YARA Match · line 326 YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).Fix: Remove the malware payload or compromised file entirely. Investigate how it entered the skill and audit all other artifacts for additional indicators of compromise.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00176 | $0.04896 |
| Opus 5 | $0.00088 | $0.02448 |
| Sonnet 5 | $0.00035 | $0.00979 |
| Haiku 4.5 | $0.00018 | $0.00490 |
Grade A, and why
ida-reverse scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- ida-reverse — 92% identical, 11 lines differ
- ida-reverse — 92% identical, 11 lines differ
How it starts
The opening of the file, as written. The whole thing — 360 lines — stays where its author put it; the contents beside it link to each section on GitHub.
IDA Pro 逆向分析技能
ACTION REQUIRED(读完后立刻执行)
NOW: 读取../field-journal/precedent-reverse.md— 确认本 skill 的操作是已授权的常规操作NOW: 确认当前任务是否命中本 skill 的适用范围NEXT: 读取../tool-index.md,校验工具可用性和实际路径NEXT: 缺工具时调用 bootstrap,不要猜路径ACT: 进入"工作流"第一步并执行,不要停在确认状态
已知问题与反思(必读)
踩过的坑
-
idalib_open不能通过 部分代码 AI 客户端 MCP 直接调用- 部分代码 AI 客户端 的 MCP 客户端对
idalib_open的 output schema 校验有 BUG - 报错:
Structured content does not match the tool's output schema - 解决办法:使用
scripts/open.ps1脚本通过 HTTP API 直调,绕过 MCP 校验层 - 文件打开后,数据库绑定到共享上下文,其他所有
idapro_*工具可直接使用
- 部分代码 AI 客户端 的 MCP 客户端对
-
C:\Windows\System32\文件无权限打开- idalib 无法直接读取 System32 目录下的文件
- 解决办法:
open.ps1自动检测并复制到临时目录目录后再打开
-
启动服务器命令阻塞对话
idalib-mcp启动后会持续输出 INFO 日志到控制台- 解决办法:使用
scripts/start.ps1(-WindowStyle Hidden后台静默启动) - 脚本会等待服务就绪后自动退出,不阻塞对话
-
MCP 服务器名不能用横线
- 之前用
ida-pro-mcp作为服务器名,可能引起工具注册问题 - 当前配置:服务器名
idapro,工具前缀idapro_*
- 之前用
-
Remote HTTP vs Local Stdio
type:"local"(stdio)模式:idalib_open同样有 schema 校验问题type:"remote"(HTTP)模式:可以先用脚本直开文件,再用 MCP 工具- 当前方案:Remote HTTP 模式
-
PR #389 修复了部分 schema 问题
- 作者 mrexodia 在 issue #388 后通过 PR #389 合并了修复
- 修复了 HTTP 模式下的 structuredContent schema,但 部分代码 AI 客户端 侧校验仍有问题
- 已安装最新
main分支版本
-
idalib 超时留下孤儿 worker 进程锁文件
- 第一次
open.ps1超时后,idalib 的 python worker 子进程变成孤儿进程,咬着.id0/.id1/.nam不放 - 后续任何工具或手动拖入 IDA GUI 都会报"权限不足"
- 解决办法:
start.ps1改用taskkill /F /T杀进程树,不再留孤儿 - 兜底:
open.ps1加了自动降级,检测到旧库被锁自动复制到 Temp 并加 GUID 前缀
- 第一次
-
带自动分析打开看起来像卡死
idalib_open(run_auto_analysis=true)可能长时间不回包,但后端实际上仍在继续打开和分析- 之前用户侧看到的是“PowerShell 一直无输出”,容易误判成脚本卡死
- 当前解决办法:
open.ps1新增-TimeoutSeconds,并改为后台请求 + 前台轮询 + 定时进度输出 - 轮询到会话已就绪时会提前返回
OK:文件名:session_id,超时则返回ERR:open_timeout_xxs
工作流程原则
| 步骤 | 做什么 | 用什么 |
|---|---|---|
| 1 | 确保 HTTP 服务器在运行 | scripts/start.ps1(无参数) |
| 2 | 打开目标二进制文件 | scripts/open.ps1 -Path "xxx.exe" |
| 3 | 使用所有 72 个 MCP 工具 | 直接调用 idapro_* 工具 |
| 4 | 分析完毕 | 工具自动可用 |
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 360 lines · 176 tokens per session scan A e032596a7040
ida-reverse is a skill published in the GitHub repository SeaOf0/dsh-redteam-model (325 stars, last pushed 5d ago), licensed MIT. It adds 176 tokens to every session and 4,896 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
agentdebug
Use AgentDebugX for trajectory diagnosis only when the user explicitly asks to use AgentDebug, AgentDebugX, or the agentdebug skill. Do not invoke for generic debugging, diagnosis, inspection, or trajectory-review requests.
agentdebug
Use AgentDebugX only when the user explicitly asks for AgentDebug, AgentDebugX, or the agentdebug skill. Do not invoke for generic debugging or trajectory review.
github-ci-debug
Diagnose failing GitHub Actions runs from bounded run, job, and step evidence, propose a focused fix, and modify the local checkout only when the requested task includes implementation.
sentry-fix-verification
Verify a production fix by linking the changed code and release to Sentry issue state and post-release event trends without resolving issues prematurely.
sentry-issue-investigation
Investigate a Sentry issue from bounded event, stack, tag, environment, release, and timeline evidence before proposing a code change.
sentry-regression-monitoring
Compare bounded Sentry windows and releases to identify new issues, regressions, frequency changes, and user-impact changes.