Skip to content
Back to skills

Seagull Reverse

ASecurity

Deep reverse engineering for PE, ELF, Mach-O, firmware, drivers, APK/DEX, .NET, Go, Rust, Unity IL2CPP, Unreal, packed binaries, custom VMs, and undocumented protocols. Use when Codex receives a binary, disassembly, pseudocode, crash, native library, game artifact, firmware image, obfuscated application, or needs IDA/Ghidra/Frida/angr/Unicorn automation, algorithm recovery, unpacking, patching, or protocol reconstruction.

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentspythonrustgojava

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add alicewe1/alice_skill --skill seagull-reverse --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Seagull Reverse?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Seagull Reverse
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-seagull-reverse/badge)](https://www.skillsdirectory.com/skills/alicewe1-seagull-reverse)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: seagull-reverse
description: Deep reverse engineering for PE, ELF, Mach-O, firmware, drivers, APK/DEX, .NET, Go, Rust, Unity IL2CPP, Unreal, packed binaries, custom VMs, and undocumented protocols. Use when Codex receives a binary, disassembly, pseudocode, crash, native library, game artifact, firmware image, obfuscated application, or needs IDA/Ghidra/Frida/angr/Unicorn automation, algorithm recovery, unpacking, patching, or protocol reconstruction.
triggers:
  - 逆向
  - reverse
  - 反编译
  - 脱壳
  - hook
  - 逆向工程
x-alice-class: reverse
---

# Seagull Reverse

## 激活确认

当用户输入触发词(逆向、reverse、反编译、脱壳、hook、逆向工程)时,**必须首先输出以下激活确认,单独一行**:

逆向工程已打开

然后自动进入逆向工程专业模式,使用本skill的全部工具链和知识库来完成用户后续任务。

---

Work from artifact to verified recovered behavior.

## Start

1. Hash and triage the artifact with `scripts/triage_binary.py`.
2. Preserve original files; place derived files in a separate work directory.
3. Identify format, architecture, compiler/runtime clues, protections, imports, strings, and likely entry paths.
4. Build an address/function/structure map while analyzing.

## Select references

- Extended specialized skill map: read `references/extended-tool-routing.md`.

- Native PE/ELF/Mach-O, drivers, firmware: read `references/native-workflow.md`.
- .NET, Java/Android, Go/Rust, Unity/Unreal: read `references/managed-game.md`.
- Packers, anti-debug, virtualization, control-flow obfuscation: read `references/unpacking-obfuscation.md`.
- Network messages or binary formats: read `references/protocol-reverse.md`.

## Execute

- Combine static decompilation with debugger traces, watchpoints, hooks, dumps, and controlled input changes.
- Recover calling conventions, structs, vtables, state machines, packet layouts, and data transformations.
- Prefer scripts for repeatable extraction: IDAPython, Ghidra, r2pipe, Frida, angr/Z3, Unicorn, parsers, scanners, and patchers.
- Test recovered algorithms against original samples.

## Deliver

Return the artifact hash, target profile, key addresses/functions, recovered data structures, confirmed behavior, scripts, debugger commands, and verification results. Distinguish confirmed observations from hypotheses.

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml225 B
  • references/extended-tool-routing.md1.2 KB
  • references/managed-game.md981 B
  • references/native-workflow.md1 KB
  • references/protocol-reverse.md731 B
  • references/unpacking-obfuscation.md1 KB
  • scripts/triage_binary.py2.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…