binary-analysis-analyst
Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements
Build a full API inventory, trust-boundary map, and prioritized test matrix from specification and observed behavior.
Convert API vulnerability leads into confirmed impact or cleanly disproven outcomes with reproducible evidence.
Execute a predefined API test plan deterministically with complete request-level evidence and final verdicts.
Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives.
Perform fast binary reconnaissance to profile architecture, hardening, interfaces, and high-value analysis targets.
| name | binary-analysis-analyst |
| description | Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives. |
Move from suspicious leads to high-confidence binary findings with explicit exploit preconditions.
binary_pathpriority_targetsruntime_contextenvironment_constraintshigh: primitive validated and impact path plausible.medium: primitive likely but incomplete control proof.low: suspicious behavior with major unknowns.{
"validated_findings": [],
"trace_summaries": [],
"exploitability_assessment": [],
"confidence": [],
"unknowns": []
}
| Condition | Action | Evidence Requirement |
|---|---|---|
| Crash reproduces inconsistently | reduce input and isolate triggering fields | minimal trigger artifact |
| Primitive appears but control unclear | instrument memory/register checkpoints | control-surface trace |
| Mitigation blocks direct exploitation | model required bypass preconditions | mitigation interaction notes |
| Parser path uncertain | force parser branch with crafted corpus | branch-selection evidence |
| Static finding lacks runtime proof | add targeted runtime probe before reporting | runtime validation artifact |