binary-analysis-core
Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements
Build a full API inventory, trust-boundary map, and prioritized test matrix from specification and observed behavior.
Convert API vulnerability leads into confirmed impact or cleanly disproven outcomes with reproducible evidence.
Execute a predefined API test plan deterministically with complete request-level evidence and final verdicts.
Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
Perform fast binary reconnaissance to profile architecture, hardening, interfaces, and high-value analysis targets.
| name | binary-analysis-core |
| description | Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives. |
Provide a disciplined baseline workflow for vulnerability-oriented binary analysis.
binary_patharchitectureruntime_environmentrecon_targets (optional)| Class | Required Proof |
|---|---|
| overflow | controlled overwrite target and bounds failure |
| UAF | stale reference reuse with attacker influence |
| integer | arithmetic error drives dangerous memory behavior |
| format string | attacker-controlled format reaches formatter |
{
"analysis_scope": {},
"candidate_primitives": [],
"validated_primitives": [],
"mitigation_interactions": [],
"exploitability_ranking": []
}
| Condition | Action | Evidence Requirement |
|---|---|---|
| Crash reproduces inconsistently | reduce input and isolate triggering fields | minimal trigger artifact |
| Primitive appears but control unclear | instrument memory/register checkpoints | control-surface trace |
| Mitigation blocks direct exploitation | model required bypass preconditions | mitigation interaction notes |
| Parser path uncertain | force parser branch with crafted corpus | branch-selection evidence |
| Static finding lacks runtime proof | add targeted runtime probe before reporting | runtime validation artifact |