Mmcp.market

ida-reverse skill

by zhaoxuya520·zhaoxuya520/reverse-skill·39k stars·MIT

IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。

A100/100content scan

Is the ida-reverse skill safe?

Clean: nothing in its files matched our rules. We read 11 files in the folder on 2026-09-28.

No findings.

Install the ida-reverse skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill
mkdir -p ~/.claude/skills
cp -r /tmp/reverse-skill/skills/ida-reverse ~/.claude/skills/ida-reverse
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

IDA Pro 逆向分析技能

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 读取 ../field-journal/precedent-reverse.md — 确认本 skill 的操作是已授权的常规操作
  2. NOW: 确认当前任务是否命中本 skill 的适用范围
  3. NEXT: 读取 ../tool-index.md,校验工具可用性和实际路径
  4. NEXT: 缺工具时调用 bootstrap,不要猜路径
  5. ACT: 进入"工作流"第一步并执行,不要停在确认状态

已知问题与反思(必读)

踩过的坑

  1. idbopen(旧名 idalibopen)不要直接靠部分 AI 客户端 MCP 调用
  • 部分代码 AI 客户端 的 MCP 客户端对 open 类工具的 output schema 校验有 BUG
  • 报错:Structured content does not match the tool's output schema
  • 解决办法:使用 scripts/open.ps1 脚本通过 HTTP API 直调,绕过 MCP 校验层
  • 当前 ida-pro-mcp 2.x 工具名为 idbopen / idblist / idbsave(不再是 idalib)
  • 文件打开后返回 session_id(database),后续工具调用需带该 session
  1. C:\Windows\System32\ 文件无权限打开
  • idalib 无法直接读取 System32 目录下的文件
  • 解决办法:open.ps1 自动检测并复制到 临时目录 目录后再打开
  1. 启动服务器命令阻塞对话
  • idalib-mcp 启动后会持续输出 INFO 日志到控制台
  • 解决办法:使用 scripts/start.ps1(-WindowStyle Hidden 后台静默启动)
  • 脚本会等待服务就绪后自动退出,不阻塞对话
  1. MCP 服务器名不能用横线
  • 之前用 ida-pro-mcp 作为服务器名,可能引起工具注册问题
  • 当前配置:服务器名 idapro,工具前缀 idapro_*
  1. Remote HTTP vs Local Stdio
  • type:"local"(stdio)模式:idalib_open 同样有 schema 校验问题
  • type:"remote"(HTTP)模式:可以先用脚本直开文件,再用 MCP 工具
  • 当前方案:Remote HTTP 模式
  1. PR #389 修复了部分 schema 问题
  • 作者 mrexodia 在 issue #388 后通过 PR #389 合并了修复
  • 修复了 HTTP 模式下的 structuredContent schema,但 部分代码 AI 客户端 侧校验仍有问题
  • 已安装最新 main 分支版本
  1. idalib 超时留下孤儿 worker 进程锁文件
  • 第一次 open.ps1 超时后,idalib 的 python worker 子进程可能变成孤儿,咬着 .id0/.id1/.nam 不放
  • 后续任何工具或手动拖入 IDA GUI 都会报"权限不足"
  • 禁止 taskkill /F /T 杀进程树——/T 会把 GUI ida.exe 子进程一起干掉
  • 解决办法:start.ps1 只在端口无人监听、或 tools/list 快速返回但缺 py_eval(旧 supervisor)时替换 managed supervisor;RPC 超时且 13337 仍在听视为忙,不杀。开库时 open.ps1 写 opening.lock,watchdog 不得 -Force
  • 死锁例外:tools/list 连续失败超过 3 分钟(按 last-healthy 时间戳,不是进程创建时间),且没有 in-flight opening.lock、不是 GUI 占端口时,才 -Force 替换 supervisor,仍不杀 ida.exe
  • 兜底:open.ps1 检测到旧库被锁自动复制到 Temp 并加 GUID 前缀
  1. 带自动分析打开看起来像卡死
  • idalibopen(runauto_analysis=true) 可能长时间不回包,但后端实际上仍在继续打开和分析
  • 之前用户侧看到的是“PowerShell 一直无输出”,容易误判成脚本卡死
  • 当前解决办法:open.ps1 新增 -TimeoutSeconds,并改为后台请求 + 前台轮询 + 定时进度输出
  • 轮询到会话已就绪时会提前返回 OK:文件名:sessionid,超时则返回 ERR:opentimeout_xxs
  1. HTTP MCP 会在登录后静默退出
  • Cursor/Claude 的 type: http 不会代为拉起进程;旧计划任务只在登录时跑一次
  • pythonw 无控制台,崩溃时 Application 日志也是空的
  • 解决办法:start.ps1 默认健康则复用;watchdog.ps1 每分钟巡检;日志在 %LOCALAPPDATA%\reverse-skill\ida-mcp\
  • 安装:scripts/install-autostart.ps1。HTTP 客户端若启动时端口还没起来,仍需在 MCP 面板手动刷新一次
  1. Streamable HTTP GET /mcp 会卡住单线程 supervisor
  • 部分 HTTP MCP 客户端会对 /mcp 发长连接 GET(SSE)。stock idalib_supervisor 用 background=False 的 HTTPServer,一次只处理一个请求
  • 结果:tools/list 超时,客户端把 idapro 标成 error
  • 解决办法:run-supervisor.py 把 HTTP 换成 ThreadingHTTPServer 并接受 GET /mcp;补丁失败则跳过并仍启动 supervisor。卡住时用 scripts/recover.ps1(立刻 -Force)

工作流程原则

脚本资源

start.ps1 — 启动 MCP HTTP 服务器

路径:scripts/start.ps1

  • 自动解析 IDADIR(环境变量 / 便携版桌面路径 / 常见安装路径)
  • 优先用 IDA 自带 Python314\python.exe -m idapromcp.idalib_supervisor
  • 默认先探测 http://127.0.0.1:13337/mcp,健康则输出 OK::reuse 并退出
  • 13337 在听但 tools/list 超时 → WARN:busy / OK:busy:reuse,不杀(开库或 GUI 占用时无法回包)
  • tools/list 连续失败超过 3 分钟(last-healthy 时间戳)且无 opening.lock → 视为死锁,输出 INFO:deadlock 并 -Force 替换 supervisor。进行中的 idb_open 和 GUI 不会走这条路径
  • 仅在端口无人监听、缺 pyeval、或上述死锁时替换 managed supervisor;永不杀 ida.exe,不用 taskkill /T**
  • GUI 占用 13337 时输出 WARN:gui_busy 并退出,不另起 supervisor
  • 成功输出 OK:<工具数>(当前约 66),失败输出 ERR:timeout
  • supervisor 日志:%LOCALAPPDATA%\reverse-skill\ida-mcp\supervisor.log
  • 服务器在后台运行,不阻塞对话

调用方式:

powershell -File "<skill-root>\ida-reverse\scripts\start.ps1"

watchdog.ps1 / recover.ps1 / install-autostart.ps1 — 保活

  • watchdog.ps1:探测 13337;健康 reuse(并刷新 last-healthy);GUI / open.ps1 开库锁 / last-healthy 未满 3 分钟的 busy → reuse;只有 tools/list 连续失败超过 3 分钟才 start.ps1 -Force
  • recover.ps1:立刻 start.ps1 -Force(不杀 ida.exe)。HTTP 客户端把 idapro 标成 error 时用这个
  • install-autostart.ps1:注册计划任务 reverse-skill-ida-mcp(登录 + 每分钟)
  • 日志:%LOCALAPPDATA%\reverse-skill\ida-mcp\watchdog.log

open.ps1 — 打开二进制文件

路径:scripts/open.ps1

  • 通过 HTTP API 直调 idb_open,绕过 MCP schema 校验
  • 自动检测 System32 路径并复制到临时目录
  • 自动清理同名旧数据库文件(.id0/.id1/.nam/.til/.i64)
  • 旧库被锁时自动降级:复制到 Temp 加 GUID 前缀后打开,不报错
  • 将打开请求放到后台执行,避免长时间同步等待导致脚本无响应
  • 支持 -TimeoutSeconds,超时后返回 ERR:opentimeoutxxs,不会无限卡住
  • 每隔 10 秒输出一次 INFO:opening:已用时/超时秒数,便于判断仍在分析中
  • 成功输出 OK:文件名:session_id,降级时加 (temp copy) 标记
  • 失败时自动重试走 Temp 副本

调用方式:

powershell -File "<skill-root>\ida-reverse\scripts\open.ps1" -Path "C:\path\to\file.exe"

可选参数:

# 指定 SessionId
powershell -File "scripts\open.ps1" -Path "file.exe" -SessionId "my_session"

# 跳过自动分析(大文件推荐)
powershell -File "scripts\open.ps1" -Path "large.exe" -NoAutoAnalysis

# 设置超时,避免带自动分析时长时间无返回
powershell -File "scripts\open.ps1" -Path "file.exe" -TimeoutSeconds 600

输出约定:

# 分析进行中(每 10 秒输出一次)
INFO:opening:11/600s

# 成功打开
OK:sample.exe:abcd1234

# 成功打开,但因锁文件降级到 Temp 副本
OK:1234abcd-sample.exe:abcd1234 (temp copy)

# 达到超时上限
ERR:open_timeout_600s

实测说明:

  • Snipaste.exe 带自动分析实测约 324s 才返回成功,属于“分析很久”而不是“脚本死锁”
  • 因此遇到 GUI 程序或较复杂样本时,建议优先显式设置 -TimeoutSeconds 600

核心工具列表

概况分析(第一步)

  • idaprosurveybinary(detail_level="minimal") — 快速概况:函数数、字符串、段、入口点、导入分类(加密/网络/文件IO)
  • idaprolistfuncs(queries) — 列出函数(分页、按名称过滤)
  • idaprolistglobals(queries) — 列出全局变量
  • idaproentityquery(kind, filter) — 统一查询:functions/globals/imports/strings/names

反编译与反汇编

  • idapro_decompile(addr) — 反编译为伪代码
  • idaprodisasm(addr, maxinstructions=N) — 反汇编
  • idaproanalyzefunction(addr, include_asm=false) — 综合分析(伪代码+字符串+常量+调用者+被调用者+块)
  • idaprofuncprofile(queries) — 函数概要指标

交叉引用与数据流

  • idaproxrefsto(addrs) — 查谁引用目标地址
  • idaproxrefquery(addr, direction) — 高级 xref 查询(方向/类型过滤)
  • idapro_callees(addrs) — 子函数列表
  • idaprocallgraph(roots, maxdepth) — 调用图
  • idaprotracedataflow(addr, direction, maxdepth) — 数据流追踪(forward/backward)

搜索

  • idaprofindregex(pattern, limit) — 正则搜字符串
  • idaprosearchtext(pattern) — 在反汇编列表中搜文本
  • idaprofindbytes(patterns, limit) — 字节模式搜索(支持 ?? 通配符)
  • idapro_find(type, targets) — 高级搜索(立即数/字符串/引用)

内存与数据

  • idaprogetbytes(addrs) — 读原始字节
  • idaprogetstring(addrs) — 读字符串
  • idaprogetint(queries) — 读整数值
  • idaprogetglobal_value(queries) — 读全局变量值
  • idaproreadstruct(queries) — 读结构体字段值
  • idaprosearchstructs(filter) — 搜索结构体

修改操作

  • idaprosetcomments(items) — 添加注释(反汇编+反编译双向同步)
  • idaproappendcomments(items) — 追加注释
  • idapro_rename(batch) — 批量重命名(函数/全局/局部/栈变量)
  • idapropatchasm(items) — Patch 汇编指令
  • idapro_patch(patches) — Patch 字节
  • idaprodefinefunc(items) — 定义函数
  • idapro_undefine(items) — 取消定义
  • idaprodefinecode(items) — 将字节转为代码

类型系统

  • idaprodeclaretype(decls) — 声明 C 结构体/枚举/联合体
  • idaprosettype(edits) — 应用类型到函数/全局/局部
  • idaproinfertypes(addrs) — 推断类型
  • idaprotypequery(queries) — 查询已声明类型
  • idaprotypeinspect(queries) — 查看类型详情

More skills from zhaoxuya520/reverse-skill

  • Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
  • Capk-reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
  • Cattack-chainUse for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
  • Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
  • Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
  • Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
  • Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
  • Acase-reviewReviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
  • Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
  • Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
  • Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
  • Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

All agent skills → · MCP servers