Skip to content
Back to skills

Ghidra Reverse

ASecurity

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

  • 434 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentspythonjavabashapi

Works with

  • cli
  • api
  • mcp

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add coco-research/coco --skill ghidra-reverse --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ghidra Reverse?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ghidra Reverse
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/coco-research-ghidra-reverse/badge)](https://www.skillsdirectory.com/skills/coco-research-ghidra-reverse)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ghidra-reverse
description: Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
user-invocable: true
---

# Ghidra Reverse Engineering

## 适用场景

- 无 IDA 许可证时的主逆向入口
- 批量 headless 分析 / CI 中反编译
- Ghidra 脚本(Java/Python Jython/PyGhidra)自动化
- 与 `binary-diff` / `patch-diff-exploit` 的 ghidriff 联动

## 与 IDA 分工

| 需求 | 优先 |
|------|------|
| 已有 IDA MCP 深挖 | `ida-reverse/` |
| 开源 / 批量 / 教学 | **本 skill** |
| 仅 CLI 快速侦察 | `radare2/` |

## 工作流

### 1. 项目与自动分析

```text
□ 新建 Project → Import 文件 → Analyze(默认分析器)
□ 记录语言/编译器识别结果与基址
□ 标记入口、导出表、字符串 xref
```

### 2. 关键函数

```text
□ 从字符串 / 导入 API 反查
□ Decompile 窗口还原算法
□ 重命名函数/变量;写 Plate comment
□ 需要动态时交接 Frida/GDB(reverse-engineering 动态章)
```

### 3. Headless(批量)

```bash
# 示例:analyzeHeadless 路径因安装而异,MUST 确认本机实际安装路径
analyzeHeadless /path/to/project Proj -import sample.bin -postScript ExportDecomp.py
```

### 4. MCP(若已配置)

```text
□ 确认 ghidra MCP 端口(常见 8765,以实际环境为准)
□ 用 MCP 工具拉反编译 / xrefs,禁止猜端口
```

## 工具链

| 工具 | 用途 |
|------|------|
| Ghidra | 反编译主工具 |
| ghidra-mcp | AI 桥 |
| ghidriff | 补丁差分,见 `patch-diff-exploit` |

## 参考

- `references/ghidra-cheatsheet.md`
- `../ida-reverse/` `../radare2/` `../binary-diff/`

Files in this skill

  • SKILL.md1.7 KB
  • references/ghidra-cheatsheet.md353 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…