CtrlK
BlogDocsLog inGet started
Tessl Logo

ghidra

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/ghidra/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-organized body with executable commands throughout and a bundle structure that matches its documentation. The weaknesses are the missing validation/feedback loop in the batch-analysis workflow and a slightly long inline JSON example that could be trimmed or moved out.

Suggestions

Add a validation step to the batch workflow, e.g. checking each binary's summary output exists (or the wrapper's exit code) before proceeding to the next sample.

Trim or relocate the ExportFunctions JSON schema example to a reference file to reduce inline token cost.

Tighten the Tips section — points like 'Decompilation isn't perfect' can be stated in fewer tokens or folded into the relevant workflow.

DimensionReasoningScore

Conciseness

The body is efficient — a quick-reference table, terse option lists, and output-file bullets — with only minor trimmable content such as the multi-line JSON schema example with an ellipsis and the somewhat chatty Tips section. It does not explain concepts Claude already knows, so it is above a 3 but not perfectly lean at 5.

4 / 5

Actionability

Nearly every section provides copy-paste-ready commands: 'ghidra-analyze.sh -s ExportAll.java -o ./analysis firmware.bin', jq parsing one-liners, grep patterns, and a processor-ID table. Common cases are covered with concrete, executable examples.

5 / 5

Workflow Clarity

The 'Analyze an Unknown Binary' workflow is well sequenced with review steps, but the 'Analyze Multiple Binaries' batch loop has no validation or verification per binary, and per the scoring notes a batch workflow without feedback loops caps workflow clarity at 3.

3 / 5

Progressive Disclosure

Structure is good: all referenced bundle files (ghidra-analyze.sh, find-ghidra.sh, and the six Export*.java scripts) exist, references are one level deep, and navigation via the quick-reference table is clear. Minor gap: the per-script documentation could be split into reference files for the larger exports.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that concretely states what the skill does with distinct, natural trigger terms. Its main weakness is the complete absence of a 'when to use' clause, which limits discoverability and caps completeness.

Suggestions

Add an explicit trigger clause, e.g. 'Use when analyzing unknown binaries, malware, or firmware, or when the user mentions reverse engineering, decompiling, or Ghidra.'

Include common file extensions and synonyms users would naturally say, such as '.exe', '.elf', '.bin', 'firmware', or 'malware analysis'.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'Decompile executables, extract functions, strings, symbols, and analyze call graphs' — giving comprehensive coverage of the skill's capabilities with no significant gaps.

5 / 5

Completeness

The 'what' is clearly and concretely answered, but there is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines.

3 / 5

Trigger Term Quality

Natural phrases like 'reverse engineer', 'binaries', 'decompile', and 'Ghidra' match what users would say, but common variations are missing: no file extensions (.exe, .elf, .bin, firmware) and no synonyms like 'malware analysis' or 'disassemble'.

4 / 5

Distinctiveness Conflict Risk

'Reverse engineer binaries using Ghidra's headless analyzer' carves out a clear niche with tool-specific triggers; conflict risk with other skills is minimal.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mitsuhiko/agent-stuff
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.