windows-reverse-engineering

windows-reverse-engineering is a skill for Claude Code, Codex from zhaji2333/CkSKILLS. It costs 129 tokens per session (4,385 once invoked), scanned A, original, MIT.

A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.

In plain words
What is it for?
Use it for reverse engineering, protocol analysis, debugging, fuzz testing, and validating issues such as buffer overflows, command execution, privilege escalation, information leaks, or denial of service.
Why use it?
Windows binaries often need analysis without access to their original source code, especially when investigating suspicious behavior or possible vulnerabilities.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/zhaji2333/ckskills/windows-reverse-engineering
Any agent
npx skills add zhaji2333/CkSKILLS --skill windows-reverse-engineering
Clone the repo
git clone --depth 1 https://github.com/zhaji2333/CkSKILLS

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for windows-reverse-engineering

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhaji2333/ckskills/windows-reverse-engineering.svg)](https://agentmods.dev/skills/zhaji2333/ckskills/windows-reverse-engineering)
Your own site
<a href="https://agentmods.dev/skills/zhaji2333/ckskills/windows-reverse-engineering"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/windows-reverse-engineering.svg" alt="Measured on agentmods" height="20"></a>
Per session 129 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,385 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00129 $0.04385
Opus 5 $0.00064 $0.02193
Sonnet 5 $0.00026 $0.00877
Haiku 4.5 $0.00013 $0.00439

Measured 5d ago against content hash ebbc038dc136, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

windows-reverse-engineering scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/windows-reverse-engineering/SKILL.md · 399 lines

How it starts

The opening of the file, as written. The whole thing — 399 lines — stays where its author put it; the contents beside it link to each section on GitHub.

windows-reverse-engineering — Windows 逆向与二进制漏洞专项深度挖掘

何时调用(触发条件)

  • 拿到 Windows PE 文件(EXE/DLL/SYS)需要逆向分析
  • 目标为 Windows 服务/守护进程,需挖掘内存破坏类漏洞
  • 程序处理网络/文件/IPC 输入,存在溢出/命令执行面
  • 需要 .NET 程序反编译(dnSpy/ILSpy)
  • 驱动/内核组件漏洞挖掘(IOCTL、Pool 溢出)
  • 协议逆向、加密算法还原
  • 需要绕过反调试/反虚拟机/反分析
  • 需要构造 PoC/exploit 验证漏洞可利用性

一、漏洞类型全景

类型 危险函数/场景 挖掘要点
缓冲区溢出 strcpy/strcat/sprintf/gets/memcpy/wcscpy 栈溢出、堆溢出、off-by-one、整型溢出
远程命令执行 system/CreateProcess/ShellExecute/WinExec 命令拼接、UNC路径、COM接口滥用
权限提升 服务路径未引用/UAC绕过/令牌滥用/弱权限 Unquoted Service Path、DLL劫持、令牌窃取
信息泄露 硬编码凭证/调试输出/内存残留/配置文件 字符串扫描、资源段、内存dump
拒绝服务 未校验长度/空指针/除零/死循环/资源耗尽 输入长度异常、空对象解引用

二、工具链

静态分析

反汇编:IDA Pro / Ghidra / Binary Ninja / Radare2
反编译:Hex-Rays / Ghidra Decompiler / RetDec
.NET:  dnSpy / ILSpy / dotPeek
字符串:Strings / FLOSS / BinText
结构:  PEview / CFF Explorer / Detect It Easy (DIE)
扫描:  cppcheck / FlawFinder / Semgrep(带源码时)
YARA:  规则匹配已知漏洞模式/恶意特征

动态分析

调试器:x64dbg/x32dbg / WinDbg / OllyDbg
.NET:  dnSpy 动态调试
Hook:  Frida / API Monitor / Detours
内存:  Cheat Engine / Process Hacker
网络:  Wireshark / mitmproxy / socket replay
模糊测试:AFL++ / WinAFL / boofuzz(协议)/ honggfuzz
流量重放:scapy / 自定义 Python socket

漏洞利用

框架:  pwntools / mona.py (Immunity) / ROPgadget
Shellcode:msfvenom / shellcodecs / 自写
Gadget: ROPgadget / ropper / rp++
计算:  !py mona pattern_create / pattern_offset

三、静态分析要点

1. 信息收集先行

文件类型:DIE / TrID 识别编译器/语言/壳
PE结构:  检查 ASLR/DEP/CFG/SafeSEH/SEHOP 保护标志
导入表:  关注危险 API(见下表)
字符串:  提取 URL/IP/路径/密钥/SQL/错误信息
资源段:  嵌入配置/证书/PE/脚本

2. 危险 API 速查表

类别 危险 API 风险
字符串 strcpy/strcat/sprintf/vsprintf/gets 栈溢出
宽字符 wcscpy/wcscat/swprintf 栈溢出
内存 memcpy/RtlCopyMemory/memmove 长度可控溢出
格式化 printf/sprintf/fprintf/wsprintf 格式化字符串
命令 system/CreateProcess/ShellExecute/WinExec 命令注入
文件 fopen/CreateFile/WriteFile 路径穿越/任意写
网络 recv/WSARecv/ReadFile(pipe) 网络输入面
注册表 RegSetValue/RegCreateKey 持久化/配置篡改
加载 LoadLibrary/GetProcAddress DLL劫持/注入
内存 VirtualAlloc/WriteProcessMemory 注入面

Read the full file on GitHub · 399 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 399 lines · 129 tokens per session scan A ebbc038dc136

Subscribe to this mod's changes

windows-reverse-engineering is a skill published in the GitHub repository zhaji2333/CkSKILLS (74 stars, last pushed 4d ago), licensed MIT. It adds 129 tokens to every session and 4,385 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

dingtalk_channel_connect

Use a headed browser to automatically complete DingTalk channel integration for QwenPaw. Applicable when the user mentions DingTalk, developer console, Client ID, Client Secret, bot, Stream mode, binding or configuring a channel. Supports pausing when a login page is detected and resuming after the user logs in.

agentscope-ai/QwenPaw · 69 tokens

make_plan

For external plan request scenarios, guides the Agent to request a clear, actionable, step-by-step plan from a stronger Agent via listagents and chatwithagent, emphasizing that the plan is executed by the requester, not by the consulted Agent.

agentscope-ai/QwenPaw · 51 tokens

pdf

当用户需要对PDF文件进行任何操作时,请使用此技能。包括从 PDF 中读取或提取文本/表格、合并多个 PDF、拆分 PDF、旋转页面、添加水印、创建新PDF、填写PDF表单、加密/解密 PDF、提取图片,以及对扫描版 PDF 进行 OCR 使其可搜索。如果用户提到 .pdf 文件或要求生成 PDF,请使用此技能。.

agentscope-ai/QwenPaw · 95 tokens

gpt-image-2

面向 GPT Image 2 的图像生成 / 编辑技能。可在 3 种环境下使用:(A) Garden 本地模式,通过 OpenAI 兼容接口直接出图并落盘;(B) Host-Native 模式,把本 Skill 当作提示词工程指引,把渲染好的 prompt 交给宿主 Agent 自带的图像工具出图;(C) Advisor 模式,宿主无任何图像工具时退化为高质量 prompt 顾问。涵盖 18 大类、80+ 个结构化模板,覆盖海报 / UI / 产品 / 信息图 / 学术图 / 技术架构图 / 漫画 / 头像 / 流程板 / 电影分镜 / IP 周边 / 编辑工作流等场景。.

ConardLi/garden-skills · 177 tokens

new

Create a new project to start development quickly.

clacky-ai/openclacky · 10 tokens

oss-upload

Upload local files to Tencent COS (oss.1024code.com CDN) using coscli. Use when user wants to upload a file to CDN/OSS, or deploy static assets.

clacky-ai/openclacky · 40 tokens