Reverse Engineering Skills
A set of reverse engineering skills: symbol and structure recovery, Frida and IDAPython scripting, DEX and IL2CPP dumping, code emulation in Unicorn
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Removes protection and extracts code from third-party Android and iOS apps
- Generates and runs Frida and IDAPython scripts, emulates and debugs binary code
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/reverse-engineering-skillsDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .claude/skills
cp -R "$tmp/skills/rev-dex-dumper" .claude/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .claude/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .claude/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .claude/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .claude/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .claude/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .claude/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .github/skills
cp -R "$tmp/skills/rev-dex-dumper" .github/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .github/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .github/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .github/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .github/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .github/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .github/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .devin/skills
cp -R "$tmp/skills/rev-dex-dumper" .devin/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .devin/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .devin/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .devin/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .devin/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .devin/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .devin/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Formerly Windsurf.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .cline/skills
cp -R "$tmp/skills/rev-dex-dumper" .cline/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .cline/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .cline/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .cline/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .cline/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .cline/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .cline/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .roo/skills
cp -R "$tmp/skills/rev-dex-dumper" .roo/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .roo/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .roo/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .roo/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .roo/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .roo/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .roo/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add p4nda0s/reverse-skills --skill rev-dex-dumper rev-frida rev-idapython rev-struct rev-symbol rev-u3d-dump rev-unicorn-debug -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit a2baa31
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/p4nda0s/reverse-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/rev-dex-dumper/ /skills/rev-frida/ /skills/rev-idapython/ /skills/rev-struct/ /skills/rev-symbol/ /skills/rev-u3d-dump/ /skills/rev-unicorn-debug/
git -C "$tmp" checkout a2baa31c58a3567977188414da68c8c842057152
mkdir -p .agents/skills
cp -R "$tmp/skills/rev-dex-dumper" .agents/skills/rev-dex-dumper
cp -R "$tmp/skills/rev-frida" .agents/skills/rev-frida
cp -R "$tmp/skills/rev-idapython" .agents/skills/rev-idapython
cp -R "$tmp/skills/rev-struct" .agents/skills/rev-struct
cp -R "$tmp/skills/rev-symbol" .agents/skills/rev-symbol
cp -R "$tmp/skills/rev-u3d-dump" .agents/skills/rev-u3d-dump
cp -R "$tmp/skills/rev-unicorn-debug" .agents/skills/rev-unicorn-debugCommands for macOS and Linux, on Windows run them in Git Bash.
Install the set: npx skills add P4nda0s/reverse-skills. Check updates with npx skills check, update with npx skills update.
Other ways from the author
npx skills add P4nda0s/reverse-skillsThe skills installer places the skills into the agent directory. Check updates with npx skills check, update with npx skills update.
This is third-party code. Review the repository files before installing.
What it does
The set gives the agent methodologies for eight reverse engineering tasks. rev-symbol recovers function names from strings, constants and cross-references, and rev-struct rebuilds data structures from decompiled code. rev-frida generates dynamic instrumentation scripts, and rev-unicorn-debug emulates and debugs selected snippets through the Unicorn engine. rev-dex-dumper pulls DEX files from a running Android app's memory, rev-u3d-dump extracts C# symbol addresses from Unity IL2CPP builds, rev-ios-dump decrypts iOS apps on a jailbroken device, and rev-idapython collects an IDAPython scripting reference. The set is built to work with IDA over MCP or through exports from the IDA-NO-MCP plugin.
Who it is for. For reverse engineers and specialists in malware analysis and mobile app security.
Good fit when
- You need to recover function names or structures from IDA decompiled code
- You need a Frida or IDAPython script for a specific analysis task
- You need to dump DEX from an Android app's memory or extract symbols from a Unity IL2CPP build
Not a fit when
- You have no rights to analyze the app or binary
- You have no IDA and no IDA-NO-MCP exports for the skills to work with
Example request
Recover function names from the exports and decompiled code in the IDA exportLimitations
The skills are built around IDA: several steps need IDA Pro connected over MCP or exports from the IDA-NO-MCP plugin. Some skills assume Frida, Unicorn, Android tooling and a jailbroken iOS device. Reverse engineering and app decryption are not always permitted; the legality of use is on the user.
How to disable. Remove the skills with npx skills remove and their names, or delete the rev-* folders from the agent's skills directory.
Security check
- Removes protection and extracts code from third-party Android and iOS apps
- Generates and runs Frida and IDAPython scripts, emulates and debugs binary code
README in short
The README describes eight reverse engineering skills and notes support for many AI tools through the skills installer. Each skill covers its own task: symbols, structures, Frida, Unicorn emulation, DEX dumping, Unity symbol extraction, iOS decryption and an IDAPython reference. The set is built for IDA-NO-MCP: decompilation results are exported from IDA and then analyzed by the agent. Installation is a single npx skills add command, with commands for checking, updating and removing alongside. MIT licensed.
SKILL.md
--- name: rev-symbol description: Restore function symbols by analyzing code patterns, strings, constants, and cross-references --- # rev-symbol - Symbol Recovery Analyze function code characteristics to recover/identify function symbols and names. ## Pre-check **Determine which IDA access method is available:** **Option A — IDA Pro MCP (preferred if connected):** Check if the IDA Pro MCP server is connected (look for an active `ida-pro` or equivalent MCP connection). If connected, you can query IDA directly via MCP tools — no exported files needed. Proceed with the analysis using MCP. **Option B — IDA-NO-MCP exported data:** If MCP is not connected, check if IDA-NO-MCP exported data exists in the current directory: 1. Check if `decompile/` directory exists 2. Check if there are `.c` files inside
FAQ
Do I need IDA?
Yes, for most skills. They work either through an IDA Pro connection over MCP or through data exported by the IDA-NO-MCP plugin.
Can I install only some of the skills?
Yes, remove the ones you do not need with npx skills remove and their names.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents