Skip to main content

archive-file-triage

Use file, 7z, unzip, tar-compatible tools, hashes, and bounded shell inspection for safe triage of provided archives and unknown files.

跳到安装

来源信息

仓库
Aethena-Lab/Z3r0
最近来源活动
2026年9月3日 10:00
检测到的 SKILL.md 语言
英语
星标
846
分支
194

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
archive-file-triage
description
Use file, 7z, unzip, tar-compatible tools, hashes, and bounded shell inspection for safe triage of provided archives and unknown files.
# archive-file-triage Use local file and archive tools for safe triage of provided archives, unknown files, evidence bundles, source packages, firmware packages, and extracted artifacts. ## Help first Before constructing commands, use installed help or version output as the source of truth: ```sh file --help 7z i unzip -h tar --help ``` ## Usage rules - Work only on explicitly provided files or task-scoped outputs. - Identify file type and size before extraction. - Extract only into a task-scoped output directory. - Preserve original files and record hashes when identity matters. - Prefer listing archive contents before extraction. - Do not execute extracted content. - Watch for path traversal, absolute paths, symlinks, excessive file counts, nested archives, and unexpectedly large expansion. - Save large listings and extraction logs to files rather than streaming them into the conversation. ## Common workflows Identify and hash before extraction: ```sh file artifact.bin sha256sum artifact.bin ``` List archive contents first: ```sh 7z l archive.7z unzip -l archive.zip tar -tf archive.tar ``` Extract into a task-scoped directory: ```sh mkdir -p extracted 7z x archive.7z -oextracted unzip archive.zip -d extracted tar -xf archive.tar -C extracted ``` After extraction, inspect file types before any deeper analysis: ```sh find extracted -maxdepth 2 -type f -exec file '{}' + ``` ## Output Report the input path, type, size, hashes when relevant, command used, output directory, notable extracted paths, suspicious archive behavior, and limitations.
在 GitHub 查看