Binary analysis patterns: disassembly, control flow, decompilation
Read compiled binaries with x86-64 idioms — control-flow and data-structure patterns, variable/type recovery, Ghidra and IDA tips
- What
- Read compiled binaries with x86-64 idioms — control-flow and data-structure patterns, variable/type recovery, Ghidra and IDA tips
- Cost
- Free
- Needs
- none for the guidance itself; Ghidra, IDA Pro or Binary Ninja if you want to follow the tool-specific sections. Authorized use only — your own software or authorized assessments, within legal bounds.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT**: @wshobson's binary-analysis pattern library: x86-64 assembly idioms for conditional branches, loops, switch/jump tables, array and struct access, linked-list traversal; arithmetic and bit-manipulation patterns (LEA multiplies, division via shifts, popcount, bit scans); decompilation patterns for variable recovery, function-signature recovery (System V registers) and type recovery from operand widths; Ghidra tips (analysis scripts, improving decompilation) and IDAPython snippets (finding calls, auto-renaming from strings); plus a 7-phase analysis workflow and common pitfalls (optimizer artifacts, tail-call optimization, position-independent code). Kept by editorial choice as a borderline case: static binary analysis is a dual-use capability — the skill lists analyzing malware or obfuscated binaries as a use case, so keep it to your own software or authorized assessments, within legal bounds. Honest caveats: malware analysis is explicitly among the stated use cases; MIT-licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: none for the guidance itself; Ghidra, IDA Pro or Binary Ninja if you want to follow the tool-specific sections. Authorized use only — your own software or authorized assessments, within legal bounds. Install "Binary analysis patterns: disassembly, control flow, decompilation" for me. It teaches x86-64 binary-analysis patterns: disassembly idioms, control-flow and data-structure patterns, decompilation patterns (variable/signature/type recovery), Ghidra and IDA tips, a 7-phase analysis workflow and common pitfalls — by @wshobson, MIT-licensed. Repository: https://github.com/wshobson/agents/blob/main/plugins/reverse-engineering/skills/binary-analysis-patterns/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "binary-analysis-patterns". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install Ghidra/Binary Ninja if I want to follow the tool-specific sections). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.