CtrlK
BlogDocsLog inGet started
Tessl Logo

binary-analysis-patterns

Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic.

48

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/binary-analysis-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a well-organized but monolithic pattern catalog: strong on concrete code examples and section structure, weak on token efficiency because most of the assembly patterns restate knowledge Claude already has. The single progressive-disclosure reference is broken (the file does not exist), and the analysis workflow lacks validation checkpoints.

Suggestions

Move the assembly pattern catalog (x86-64/ARM calling conventions, control flow, data structures) into one-level-deep reference files such as references/x86-patterns.md and references/arm-patterns.md, keeping SKILL.md as a concise overview with clearly signaled links — and fix or remove the broken 'resources/implementation-playbook.md' path, which does not exist in the bundle.

Cut sections that restate textbook compiler-output knowledge (calling conventions, prologue/epilogue, loop and bit-manipulation idioms) and retain only non-obvious content such as optimizer artifacts, tail-call optimization, and RIP-relative addressing, which is where this skill currently adds real value.

Add validation checkpoints to the Analysis Workflow — e.g., verify recovered function signatures against cross-references and re-run decompilation after applying types in Ghidra/IDA — so the sequence includes feedback loops rather than ending at 'Documentation'.

DimensionReasoningScore

Conciseness

Roughly 430 of the ~460 lines restate knowledge Claude already has — System V and Microsoft x64 calling conventions, prologue/epilogue, conditional-branch and loop lowering, standard bit-manipulation idioms — plus generic template boilerplate ('Use this skill when', 'Apply relevant best practices and validate outcomes'). It is not padded prose, but the unnecessary-explanation fraction is far more than 'some', sitting noticeably below the midpoint.

2 / 5

Actionability

The body is dense with concrete material: annotated assembly patterns ('cmp eax, ebx / jne skip_block', jump-table switches, struct offsets) and runnable tool scripting (IDAPython find_calls, Ghidra type-fixing snippets). Minor gaps keep it below 5 — placeholder operands like 'mov rdi, [a]', the auto_rename stub ending in 'pass', and fragmentary Ghidra Java — but it is well above the pseudocode-only midpoint.

4 / 5

Workflow Clarity

A clear 7-step 'Analysis Workflow' exists (triage, string analysis, function identification, control flow mapping, data structure recovery, algorithm identification, documentation), but no validation checkpoints appear anywhere and the opening 'Instructions' section is vague ('Apply relevant best practices and validate outcomes'). The sequence is present while checkpoints are missing, matching the anchor rather than the checkpoint-bearing level above.

3 / 5

Progressive Disclosure

Section headers are good, but ~400 lines of pattern catalog that belong in separate reference files are inlined in SKILL.md, and the body's only reference — 'open resources/implementation-playbook.md' — points to a file that does not exist in the bundle (no references/, scripts/, assets/, or resources/ directories). Structure exists but content is not split and the one reference is broken, fitting the 'some structure' anchor rather than the 'mostly well-placed' one.

3 / 5

Total

12

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear niche (binary/assembly analysis) in third person with a coherent 'what', but it reads as a topic statement rather than a capability-and-trigger description. It has no 'Use when...' guidance and omits the natural trigger vocabulary of the field, so it would rely on lucky keyword matches to be invoked.

Suggestions

Add an explicit trigger clause, e.g. 'Use when reverse engineering binaries, reading disassembly or decompiler output, or when the user mentions Ghidra, IDA, assembly, or decompiling.'

Drop the 'Comprehensive patterns and techniques' filler and name concrete deliverables users act on, such as 'recognize compiler-generated idioms (prologues, calling conventions, jump tables) and recover function signatures, types, and data structures in Ghidra or IDA.'

Include the field's natural synonyms — reverse engineering, disassembly, decompilation, and tool names — since 'binary analysis' alone is not the phrase most users say.

DimensionReasoningScore

Specificity

The description names the domain plus three actions — 'analyzing compiled binaries', 'understanding assembly code', 'reconstructing program logic' — but the verbs are generic and 'Comprehensive patterns and techniques' is filler with no tools or concrete deliverables. It exceeds the minimal-actions level but falls short of the specific, minor-gaps level above.

3 / 5

Completeness

The 'what' is stated clearly, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. It cannot score 4 because the 'when' is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Terms like 'binary', 'assembly code', and 'compiled' are relevant, but the phrases users would most naturally say for this skill — 'reverse engineering', 'disassembly', 'decompile', tool names like Ghidra or IDA — are all missing. Some relevant keywords with common synonyms absent matches the middle anchor.

3 / 5

Distinctiveness Conflict Risk

The domain — compiled binaries and assembly — is a fairly clear niche, distinct from source-code analysis skills, with only minor overlap risk against neighboring reverse-engineering or security-review skills. It lacks the distinct trigger phrases needed for the top anchor but is more specific than the 'somewhat specific' anchor below.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.