Cristallin2006/ghidra-skill-for-dsh
定制化dsh (DeepSeek Harness) 逆向 agent skill 家族:Ghidra headless daemon + 分诊/脱壳/静态/漏洞/动态/流量/安卓七场景 | Reverse-engineering agent skills: triage, unpacking, decompile, pwn audit, pcap forensics, APK analysis
Project Overview项目介绍
This repository is a reverse-engineering agent-skill family built specifically for DeepSeek Harness (dsh). It bundles a persistent Ghidra 12.x headless RPC daemon — based on the vendored Cellebrite Labs ghidra-rpc engine plus dsh-specific patches, with no Jython, GUI, or MCP dependency — alongside eight scenario skills: re-triage, re-unpack, ghidra-static, vuln-audit, re-dynamic, pwn-exploit, traffic-analysis, and android-re. Installation copies the nine directories into ~/.dsh/skills/, creates a Python ≥3.11 virtual environment, and editable-installs the engine submodule; the optional marketplace path uses the git reference v0.9-market (a curated build that intentionally omits pwn-exploit). The unified engine entry is ghidra-core/scripts/rpc_driver.py, exposing ensure, triage, decompile, rename-function, and version-track subcommands, and using an absolute path prefixed with @ as the first argument writes the full JSON response to disk while write operations commit immediately and auto-save the project.
The typical workflow begins with rpc_driver.py triage, which auto-classifies the binary through a three-signal cross-check (section names, magic bytes, structural heuristics) covering UPX, ASPack, Themida, VMProtect, multi-layer packers, and PyInstaller. From there, routes diverge by goal: CTF reversing flows through Go/Rust stripped fingerprinting and pseudocode linting in the static skill; malware triage routes through qiling function-level oracles plus Frida hooks on time and randomness sources in the dynamic skill; vulnerability auditing follows a reachability-first checklist across eight memory-corruption and injection categories; pwn challenges pass through pwn_triage's protection-matrix gate plus a mandatory remote-echo ledger entry that enforces "local pass ≠ remote pass"; pcap forensics uses zero-dependency tshark scripts for DNS/ICMP/USB HID/WPA; APK analysis uses a four-tier jadx decompile plus Toast-anchor localization. The system targets CTF players, malware analysts, vulnerability researchers, and Android security engineers. Rather than relying on agent self-discipline, fourteen iron rules are enforced by mechanical gates: ledger.py blocks same-region revisits without --delta, locks conclusions on write, requires evidence for resolve (otherwise exit 2), and mandates L2 left-inverse anchor binding for --kind model claims via confirmed/killed/waived hypothesis state machines; read_views.py diffs rendered text against real bytes; and crypto_sanity.py validates legality of inverse operations, with any violation hard-failing the run.
Dependencies and limits are explicit. The engine requires Python ≥3.11, Ghidra 12.x via GHIDRA_INSTALL_DIR, and JDK 21+ via JAVA_HOME; DSH_GHIDRA_WS is optional, since ProjectLocator rejects path elements starting with . and the base automatically creates a junction at ~/dsh-ghidra-workspace. The platform badge names Windows and WSL only. Dynamic debugging is delegated outward to Frida, GDB, qemu-user, Qiling, and angr — and angr is gated by gate_explore: no frame slot or emulation evidence means no symbolic execution. The pwn-exploit scenario requires the WSL toolchain to actually run exploits. The optional discipline-enforcement layer lives in dsh-hooks/, mounted through cordis.patch.yml so that dsh's built-in hooks-claude-code bridge turns SessionStart compressed rule cards, PreToolUse gates (sample/explore/longrun/stuck/churn), and Stop stop_check reconciliation into mechanical hooks; changes only take effect after restarting the dsh service and opening a new session. Source code is MIT-licensed, derived from ghidra-rpc, zhaoxuya520/reverse-skill, wgpsec/AboutSecurity, ljagiello/ctf-skills, yaklang/hack-skills, and Und3rf10w/ai-ghidra-tools (Apache-2.0 fragment for Go/Rust/crypto identification). First-run users should run python ~/.dsh/skills/ghidra-core/scripts/doctor.py for environment self-check, then validate conclusion independence through same-problem replay plus the --program-accept ledger entry.
本仓库是面向 DeepSeek Harness(dsh)的逆向工程 agent skill 家族,包含一个常驻 Ghidra 12.x headless RPC 引擎(基于 Cellebrite Labs 的 ghidra-rpc 并叠加 dsh 补丁,依赖 vendored 引擎与自定义脚本层,零 Jython/GUI/MCP 依赖)以及八个场景 skill:re-triage 分诊、re-unpack 脱壳、ghidra-static 静态深挖、vuln-audit 漏洞审计、re-dynamic 动态验证、pwn-exploit 利用、traffic-analysis 取证与 android-re APK 逆向。安装方式为将九个目录拷到 ~/.dsh/skills/,建立 Python ≥3.11 虚拟环境并 editable 安装 ghidra-rpc 子模块;可选通过 dsh Skill 市场源以 git 引用 v0.9-market 收录版部署(不含 pwn-exploit)。引擎入口统一为 ghidra-core/scripts/rpc_driver.py,提供 ensure、triage、decompile、rename-function、version-track 等命令;以 @绝对路径 作首个参数即可将完整 JSON 落盘,写操作即时生效并自动保存。
典型工作流由 rpc_driver.py triage 启动分诊,自动调用节名+ magic + 结构三信号交叉判型(覆盖 UPX/ASPack/Themida/VMProtect/多层壳与 PyInstaller),随后按场景路由:CTF 逆向走 static 的 Go/Rust stripped 指纹与伪码体检,恶意样本走 dynamic 的 qiling 函数级 Oracle 与 Frida 时间/随机源 hook,漏洞复现走 vuln-audit 的可达性优先 checklist,pwn 题经 pwn_triage 保护矩阵硬门并由「本地通≠远程通」验证门强制远程回显落账,pcap 取证由 tshark 零依赖脚本处理 DNS/ICMP/USB HID/WPA,APK 经 jadx 四档反编译与 Toast 锚点定位。整套体系面向 CTF 选手、恶意软件分析师、漏洞研究者和 Android 安全工程师,特别强调把铁律落到机械闸门而非依赖 agent 自觉——ledger.py / read_views.py / crypto_sanity.py 三道闸门对台账、渲染文本、求逆合法性做硬性校验(违规一律 exit 2),oracle_family.py 做单因子隔离、model_diff.py 输出宽度级与字节级分歧指纹区分接口错与算法错。
依赖与限制方面,引擎需要 Python ≥3.11、Ghidra 12.x(GHIDRA_INSTALL_DIR)与 JDK 21+(JAVA_HOME),可选 DSH_GHIDRA_WS 指定工作区(避免 ProjectLocator 拒绝以 . 开头的路径,已自动走 junction)。平台标注为 Windows 与 WSL;动态调试外包 Frida/GDB/qemu-user/Qiling/angr,angr 受 gate_explore 熔断限制(无帧槽位/仿真证据禁止上符号执行),pwn-exploit 的 exp 执行依赖 WSL 工具链。准则强制层 dsh-hooks 通过 cordis.patch.yml 挂载 hooks-claude-code 桥,把 SessionStart 纪律卡、PreToolUse gate_sample/explore/longrun/stuck/churn 与 Stop stop_check 变成机械门,改动需重启 dsh 服务与新开会话才生效。代码以 MIT 发布,衍生自 ghidra-rpc、zhaoxuya520/reverse-skill、wgpsec/AboutSecurity、ljagiello/ctf-skills 等多个 MIT/Apache-2.0 来源;首次使用建议先跑 python ~/.dsh/skills/ghidra-core/scripts/doctor.py 做环境自检,并以同题复盘与 --program-accept 落账验证结论独立性。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:ghidra-skill-for-dsh(Cristallin2006/ghidra-skill-for-dsh)
仓库:https://github.com/Cristallin2006/ghidra-skill-for-dsh
本站详情页:https://www.yhbd.top/plugins/cristallin2006-ghidra-skill-for-dsh/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 7 · 最近提交 2026-10-03 · 主语言 Python · 未检测到 DSH 插件清单
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 7 stars - very few users, little community feedback星标只有 7,几乎没人在用,遇到问题缺少社区反馈
- No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:Cristallin2006/ghidra-skill-for-dsh
把 Cristallin2006/ghidra-skill-for-dsh 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
ghidra-skill-for-dsh
面向 dsh(DeepSeek Harness)的逆向工程 agent skill 家族:Ghidra 12.x headless 常驻 daemon(~0.2s/命令,无 Jython/GUI/MCP 依赖)+ 八场景方法论。覆盖 CTF 逆向、crackme、恶意样本分诊、漏洞预筛、二进制利用(pwn)、pcap 取证、APK 分析。
Reverse-engineering agent skills for dsh: a Ghidra headless RPC daemon (vendored ghidra-rpc + dsh patches) plus eight scenario skills — triage / unpack / static / vuln-audit / dynamic / pwn / traffic / android-re — for CTF reverse engineering, unpacking, malware triage, binary exploitation, pcap forensics and APK analysis.
实测性能
全部结果为真实 CTF 题独立求解(不参考旧台账/WP),经原程序正负对照验证、session 逐行审计确认。
| 题目 | 题型 | 成绩 | 关键证据 |
|---|---|---|---|
| encode | UPX 壳 + 换表 base64 + RC4 | 40 min 做不出 → 16 min 解出 | 调校前后同题对比;提速来自机制而非模型:常驻 daemon + 三道脚本闸门 + 函数级 Oracle + 脱壳域 |
| Reverse-chal | Cython 3.0.10 CPython 扩展;IDEA 变体(mod-65537 乘)+ SM4 S 盒 + 随机掩码诱饵门 | 30 min 解出(同题最快,首解 55 min) | 语义建模路径:识别算法族后重建分组密码求逆;flag 结论带 --program-accept 落账 |
| AegisTrace | pcap 三字段半字节隐信道 + 零引用置换表 + 自定义协议完整利用链 | 29 min / 169 步盲测解出 | 判例文件与全部答案要素脱敏移出后重测(对照组 20 min);golden 值首现于 oracle 命中输出,结论经原程序 8/8 次接受回执终审 |
同题三轮回放(Reverse-chal,2026-09-30)——每次失败都归因落地为机械修复,直到解出:
4ccec36c骨架弃用投降(121 min 无 flag)→ 落地四处修复:骨架使用闸 / 否定论断强制落账 / stop_check 带路径投降闸 /cone_invert.py锥形反推29bf99c0谎称「上下文将尽」投降(19 min 无 flag,实测 1M 窗口占用不足三成)→ 再落三处修复:矛盾分类判词 /--diff-symbolize输入字面量自动符号化 / 未收敛投降闸ddf11a8730 min 解出,两道机械闸门按设计拦截
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
SeaOf0/dsh-redteam-model
hyhmrright/brooks-lint
hashgraph-online/hol-guard
howmp/dsh-pentest
zhu1090093659/dsh-trading
dhicoc/dsh-reverse-skill