CtrlK
BlogDocsLog inGet started
Tessl Logo

reverse-engineering-tools

Guide for reverse engineering protected games and anti-cheat components across user mode, kernel mode, and hypervisor-aware environments. Use this skill when analyzing drivers, IOCTL protocols, callback registration, injected-code artifacts, integrity checks, protected binaries, or debugging security-sensitive game components.

65

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/reverse-engineering/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, technically rich reference skill that delegates deep detail to remote archives and a wiki overview while retaining actionable specifics like URL formats and the DBI trap-and-emulate recipe. Its main weakness is conciseness — duplicated entries and a redundant README-coverage map inflate the body.

Suggestions

Remove the "README Coverage" bulleted map; those categories are already represented by the structured sections that follow, so it duplicates content without aiding navigation.

Deduplicate tool entries that appear in multiple sections (e.g. dnSpy under both Specialized Debuggers and Decompilation) by keeping each tool in its single most relevant section and cross-referencing if needed.

Move the long per-tool catalogs (Debugging Tools, Disassembly & Decompilation, DBI Frameworks) into a bundled references file, leaving SKILL.md as a concise overview with one-level-deep pointers, which would improve both conciseness and progressive disclosure.

DimensionReasoningScore

Conciseness

Per-item entries are lean, but the body carries bulk that could be trimmed: the 26-line "README Coverage" section restates categories already covered below, and several tools (e.g. dnSpy) are listed twice, adding tokens without new information.

3 / 5

Actionability

Concrete and specific throughout — named tools with one-line uses, copy-paste-ready archive/description URL formats with examples, and a detailed DBI technique (HLT 0xF4 / SALC 0xD6 sentinels, KiUserExceptionDispatcher hook, branch-emulation table) — with only minor gaps in executable detail.

4 / 5

Workflow Clarity

Where workflows exist they are well sequenced: the data-source retrieval flow gives an explicit priority order (Description → Archive → README) with 404 fallback feedback, and the DBI section lays out a full patch→fault→capture→emulate→record→restore cycle. No destructive/batch operation needs a validation cap, but the skill is mostly catalog rather than procedural, so it is not a 5.

4 / 5

Progressive Disclosure

Good one-level-deep structure: external README/archive/description URLs are clearly signaled with formats and a priority order, and the compiled wiki overview is referenced upfront. It is not a 5 because substantial inline tool catalogs (Debugging, Disassembly, DBI lists) read as reference material that could live in a bundled file.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-targeted description that crisply states the domain and scope and pairs it with an explicit, trigger-rich "Use when" clause. Only minor synonym coverage is missing.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "analyzing drivers, IOCTL protocols, callback registration, injected-code artifacts, integrity checks, protected binaries, or debugging security-sensitive game components" — giving comprehensive coverage of the domain rather than vague abstraction.

5 / 5

Completeness

Explicitly answers both what ("Guide for reverse engineering protected games and anti-cheat components across user mode, kernel mode, and hypervisor-aware environments") and when ("Use this skill when analyzing drivers, IOCTL protocols...") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural keywords for the niche ("drivers", "IOCTL protocols", "anti-cheat", "integrity checks", "debugging"), but a few common variations users say ("unpack", "dump", "VMP/Themida") are absent, so it stops just short of comprehensive.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (game-security / anti-cheat reverse engineering) with distinctive triggers spanning user/kernel/hypervisor modes, making collision with unrelated skills unlikely.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (517 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
gmh5225/awesome-game-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.