Cristallin2006/ghidra-skill-for-dsh

定制化dsh (DeepSeek Harness) 逆向 agent skill 家族:Ghidra headless daemon + 分诊/脱壳/静态/漏洞/动态/流量/安卓七场景 | Reverse-engineering agent skills: triage, unpacking, decompile, pwn audit, pcap forensics, APK analysis

Project Overview项目介绍

This repository is a reverse-engineering agent-skill family built specifically for DeepSeek Harness (dsh). It bundles a persistent Ghidra 12.x headless RPC daemon — based on the vendored Cellebrite Labs ghidra-rpc engine plus dsh-specific patches, with no Jython, GUI, or MCP dependency — alongside eight scenario skills: re-triage, re-unpack, ghidra-static, vuln-audit, re-dynamic, pwn-exploit, traffic-analysis, and android-re. Installation copies the nine directories into ~/.dsh/skills/, creates a Python ≥3.11 virtual environment, and editable-installs the engine submodule; the optional marketplace path uses the git reference v0.9-market (a curated build that intentionally omits pwn-exploit). The unified engine entry is ghidra-core/scripts/rpc_driver.py, exposing ensure, triage, decompile, rename-function, and version-track subcommands, and using an absolute path prefixed with @ as the first argument writes the full JSON response to disk while write operations commit immediately and auto-save the project.

The typical workflow begins with rpc_driver.py triage, which auto-classifies the binary through a three-signal cross-check (section names, magic bytes, structural heuristics) covering UPX, ASPack, Themida, VMProtect, multi-layer packers, and PyInstaller. From there, routes diverge by goal: CTF reversing flows through Go/Rust stripped fingerprinting and pseudocode linting in the static skill; malware triage routes through qiling function-level oracles plus Frida hooks on time and randomness sources in the dynamic skill; vulnerability auditing follows a reachability-first checklist across eight memory-corruption and injection categories; pwn challenges pass through pwn_triage's protection-matrix gate plus a mandatory remote-echo ledger entry that enforces "local pass ≠ remote pass"; pcap forensics uses zero-dependency tshark scripts for DNS/ICMP/USB HID/WPA; APK analysis uses a four-tier jadx decompile plus Toast-anchor localization. The system targets CTF players, malware analysts, vulnerability researchers, and Android security engineers. Rather than relying on agent self-discipline, fourteen iron rules are enforced by mechanical gates: ledger.py blocks same-region revisits without --delta, locks conclusions on write, requires evidence for resolve (otherwise exit 2), and mandates L2 left-inverse anchor binding for --kind model claims via confirmed/killed/waived hypothesis state machines; read_views.py diffs rendered text against real bytes; and crypto_sanity.py validates legality of inverse operations, with any violation hard-failing the run.

Dependencies and limits are explicit. The engine requires Python ≥3.11, Ghidra 12.x via GHIDRA_INSTALL_DIR, and JDK 21+ via JAVA_HOME; DSH_GHIDRA_WS is optional, since ProjectLocator rejects path elements starting with . and the base automatically creates a junction at ~/dsh-ghidra-workspace. The platform badge names Windows and WSL only. Dynamic debugging is delegated outward to Frida, GDB, qemu-user, Qiling, and angr — and angr is gated by gate_explore: no frame slot or emulation evidence means no symbolic execution. The pwn-exploit scenario requires the WSL toolchain to actually run exploits. The optional discipline-enforcement layer lives in dsh-hooks/, mounted through cordis.patch.yml so that dsh's built-in hooks-claude-code bridge turns SessionStart compressed rule cards, PreToolUse gates (sample/explore/longrun/stuck/churn), and Stop stop_check reconciliation into mechanical hooks; changes only take effect after restarting the dsh service and opening a new session. Source code is MIT-licensed, derived from ghidra-rpc, zhaoxuya520/reverse-skill, wgpsec/AboutSecurity, ljagiello/ctf-skills, yaklang/hack-skills, and Und3rf10w/ai-ghidra-tools (Apache-2.0 fragment for Go/Rust/crypto identification). First-run users should run python ~/.dsh/skills/ghidra-core/scripts/doctor.py for environment self-check, then validate conclusion independence through same-problem replay plus the --program-accept ledger entry.

本仓库是面向 DeepSeek Harness(dsh)的逆向工程 agent skill 家族,包含一个常驻 Ghidra 12.x headless RPC 引擎(基于 Cellebrite Labs 的 ghidra-rpc 并叠加 dsh 补丁,依赖 vendored 引擎与自定义脚本层,零 Jython/GUI/MCP 依赖)以及八个场景 skill:re-triage 分诊、re-unpack 脱壳、ghidra-static 静态深挖、vuln-audit 漏洞审计、re-dynamic 动态验证、pwn-exploit 利用、traffic-analysis 取证与 android-re APK 逆向。安装方式为将九个目录拷到 ~/.dsh/skills/,建立 Python ≥3.11 虚拟环境并 editable 安装 ghidra-rpc 子模块;可选通过 dsh Skill 市场源以 git 引用 v0.9-market 收录版部署(不含 pwn-exploit)。引擎入口统一为 ghidra-core/scripts/rpc_driver.py,提供 ensure、triage、decompile、rename-function、version-track 等命令;以 @绝对路径 作首个参数即可将完整 JSON 落盘,写操作即时生效并自动保存。

典型工作流由 rpc_driver.py triage 启动分诊,自动调用节名+ magic + 结构三信号交叉判型(覆盖 UPX/ASPack/Themida/VMProtect/多层壳与 PyInstaller),随后按场景路由:CTF 逆向走 static 的 Go/Rust stripped 指纹与伪码体检,恶意样本走 dynamic 的 qiling 函数级 Oracle 与 Frida 时间/随机源 hook,漏洞复现走 vuln-audit 的可达性优先 checklist,pwn 题经 pwn_triage 保护矩阵硬门并由「本地通≠远程通」验证门强制远程回显落账,pcap 取证由 tshark 零依赖脚本处理 DNS/ICMP/USB HID/WPA,APK 经 jadx 四档反编译与 Toast 锚点定位。整套体系面向 CTF 选手、恶意软件分析师、漏洞研究者和 Android 安全工程师,特别强调把铁律落到机械闸门而非依赖 agent 自觉——ledger.py / read_views.py / crypto_sanity.py 三道闸门对台账、渲染文本、求逆合法性做硬性校验(违规一律 exit 2),oracle_family.py 做单因子隔离、model_diff.py 输出宽度级与字节级分歧指纹区分接口错与算法错。

依赖与限制方面,引擎需要 Python ≥3.11、Ghidra 12.x(GHIDRA_INSTALL_DIR)与 JDK 21+(JAVA_HOME),可选 DSH_GHIDRA_WS 指定工作区(避免 ProjectLocator 拒绝以 . 开头的路径,已自动走 junction)。平台标注为 Windows 与 WSL;动态调试外包 Frida/GDB/qemu-user/Qiling/angr,angr 受 gate_explore 熔断限制(无帧槽位/仿真证据禁止上符号执行),pwn-exploit 的 exp 执行依赖 WSL 工具链。准则强制层 dsh-hooks 通过 cordis.patch.yml 挂载 hooks-claude-code 桥,把 SessionStart 纪律卡、PreToolUse gate_sample/explore/longrun/stuck/churn 与 Stop stop_check 变成机械门,改动需重启 dsh 服务与新开会话才生效。代码以 MIT 发布,衍生自 ghidra-rpc、zhaoxuya520/reverse-skill、wgpsec/AboutSecurity、ljagiello/ctf-skills 等多个 MIT/Apache-2.0 来源;首次使用建议先跑 python ~/.dsh/skills/ghidra-core/scripts/doctor.py 做环境自检,并以同题复盘与 --program-accept 落账验证结论独立性。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • Only 7 stars - very few users, little community feedback星标只有 7,几乎没人在用,遇到问题缺少社区反馈
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:Cristallin2006/ghidra-skill-for-dsh

把 Cristallin2006/ghidra-skill-for-dsh 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

ghidra-skill-for-dsh

简体中文 | English | 日本語

Release License: MIT Stars dsh skill Ghidra 12.x headless Platform Python

面向 dsh(DeepSeek Harness)的逆向工程 agent skill 家族:Ghidra 12.x headless 常驻 daemon(~0.2s/命令,无 Jython/GUI/MCP 依赖)+ 八场景方法论。覆盖 CTF 逆向、crackme、恶意样本分诊、漏洞预筛、二进制利用(pwn)、pcap 取证、APK 分析。

Reverse-engineering agent skills for dsh: a Ghidra headless RPC daemon (vendored ghidra-rpc + dsh patches) plus eight scenario skills — triage / unpack / static / vuln-audit / dynamic / pwn / traffic / android-re — for CTF reverse engineering, unpacking, malware triage, binary exploitation, pcap forensics and APK analysis.

实测性能

全部结果为真实 CTF 题独立求解(不参考旧台账/WP),经原程序正负对照验证、session 逐行审计确认。

题目 题型 成绩 关键证据
encode UPX 壳 + 换表 base64 + RC4 40 min 做不出 → 16 min 解出 调校前后同题对比;提速来自机制而非模型:常驻 daemon + 三道脚本闸门 + 函数级 Oracle + 脱壳域
Reverse-chal Cython 3.0.10 CPython 扩展;IDEA 变体(mod-65537 乘)+ SM4 S 盒 + 随机掩码诱饵门 30 min 解出(同题最快,首解 55 min) 语义建模路径:识别算法族后重建分组密码求逆;flag 结论带 --program-accept 落账
AegisTrace pcap 三字段半字节隐信道 + 零引用置换表 + 自定义协议完整利用链 29 min / 169 步盲测解出 判例文件与全部答案要素脱敏移出后重测(对照组 20 min);golden 值首现于 oracle 命中输出,结论经原程序 8/8 次接受回执终审

同题三轮回放(Reverse-chal,2026-09-30)——每次失败都归因落地为机械修复,直到解出:

  1. 4ccec36c 骨架弃用投降(121 min 无 flag)→ 落地四处修复:骨架使用闸 / 否定论断强制落账 / stop_check 带路径投降闸 / cone_invert.py 锥形反推
  2. 29bf99c0 谎称「上下文将尽」投降(19 min 无 flag,实测 1M 窗口占用不足三成)→ 再落三处修复:矛盾分类判词 / --diff-symbolize 输入字面量自动符号化 / 未收敛投降闸
  3. ddf11a87 30 min 解出,两道机械闸门按设计拦截

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-archived-sessions 下一个 Next dsh-searxng →