Use this skill for static malware analysis and reverse engineering of suspicious binaries, Android APKs, Office documents, web payloads, scripts, source-code droppers, and multi-stage chains across Linux, macOS, and Windows. It guides Codex through safe lab workflow, tool discovery with per-install authorization, triage, staged payload retrieval when authorized, decoding, evidence preservation, AGENTS.md memory, REPORT.md reporting, C2/drop URL extraction, and family attribution.
2026-04-27