external/trailofbits-skills-curated/plugins/ghidra-headless/skills/ghidra-headless/SKILL.md
Reverse engineers binaries using Ghidra's headless analyzer. Use when decompiling executables, extracting functions, strings, symbols, or analyzing call graphs from compiled binaries without the Ghidra GUI.
npx skillsauth add seikaikyo/dash-skills ghidra-headlessInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Perform automated reverse engineering using Ghidra's analyzeHeadless tool.
Import binaries, run analysis, decompile to C code, and extract useful
information.
| Task | Command |
|------|---------|
| Full analysis with all exports | {baseDir}/scripts/ghidra-analyze.sh -s ExportAll.java -o ./output binary |
| Decompile to C code | {baseDir}/scripts/ghidra-analyze.sh -s ExportDecompiled.java -o ./output binary |
| List functions | {baseDir}/scripts/ghidra-analyze.sh -s ExportFunctions.java -o ./output binary |
| Extract strings | {baseDir}/scripts/ghidra-analyze.sh -s ExportStrings.java -o ./output binary |
| Get call graph | {baseDir}/scripts/ghidra-analyze.sh -s ExportCalls.java -o ./output binary |
| Export symbols | {baseDir}/scripts/ghidra-analyze.sh -s ExportSymbols.java -o ./output binary |
| Find Ghidra path | {baseDir}/scripts/find-ghidra.sh |
brew install --cask ghidraThe skill automatically locates Ghidra in common installation paths. Set
GHIDRA_HOME environment variable if Ghidra is installed in a non-standard
location.
{baseDir}/scripts/ghidra-analyze.sh [options] <binary>
Wrapper that handles project creation/cleanup and provides a simpler
interface to analyzeHeadless.
Options:
-o, --output <dir> — Output directory for results (default: current dir)-s, --script <name> — Post-analysis script to run (can be repeated)-a, --script-args <args> — Arguments for the last specified script--script-path <path> — Additional script search path-p, --processor <id> — Processor/architecture (e.g., x86:LE:32:default)-c, --cspec <id> — Compiler spec (e.g., gcc, windows)--no-analysis — Skip auto-analysis (faster, but less info)--timeout <seconds> — Analysis timeout per file--keep-project — Keep the Ghidra project after analysis--project-dir <dir> — Directory for Ghidra project (default: /tmp)--project-name <name> — Project name (default: auto-generated)-v, --verbose — Verbose outputRuns summary, decompilation, function list, strings, and interesting-pattern exports. Does not include call graph or symbols — run ExportCalls.java and ExportSymbols.java separately if needed. Best for initial analysis.
Output files:
{name}_summary.txt — Overview: architecture, memory sections, function counts{name}_decompiled.c — All functions decompiled to C{name}_functions.json — Function list with signatures and calls{name}_strings.txt — All strings found (plain text; use ExportStrings.java for JSON){name}_interesting.txt — Functions matching security-relevant patterns{baseDir}/scripts/ghidra-analyze.sh -s ExportAll.java -o ./analysis firmware.bin
Decompile all functions to C pseudocode.
Output: {name}_decompiled.c
Export function list as JSON with addresses, signatures, parameters, and call relationships.
Output: {name}_functions.json
Extract all strings (ASCII, Unicode) with addresses.
Output: {name}_strings.json
Export function call graph showing caller/callee relationships. Includes full call graph, potential entry points, and most frequently called functions.
Output: {name}_calls.json
Export all symbols: imports, exports, and internal symbols.
Output: {name}_symbols.json
mkdir -p ./analysis
{baseDir}/scripts/ghidra-analyze.sh -s ExportAll.java -o ./analysis unknown_binary
cat ./analysis/unknown_binary_summary.txt
cat ./analysis/unknown_binary_interesting.txt
{baseDir}/scripts/ghidra-analyze.sh \
-p "ARM:LE:32:v7" \
-s ExportAll.java \
-o ./firmware_analysis \
firmware.bin
{baseDir}/scripts/ghidra-analyze.sh --no-analysis -s ExportFunctions.java -o . program
cat program_functions.json | jq '.functions[] | "\(.address): \(.name)"'
# After running ExportDecompiled, search for patterns
grep -n "password\|secret\|key" output_decompiled.c
grep -n "strcpy\|sprintf\|gets" output_decompiled.c
Common processor IDs for the -p option:
| Architecture | Processor ID |
|-------------|--------------|
| x86 32-bit | x86:LE:32:default |
| x86 64-bit | x86:LE:64:default |
| ARM 32-bit | ARM:LE:32:v7 |
| ARM 64-bit | AARCH64:LE:64:v8A |
| MIPS 32-bit | MIPS:BE:32:default or MIPS:LE:32:default |
| PowerPC | PowerPC:BE:32:default |
{baseDir}/scripts/find-ghidra.sh
# Or set GHIDRA_HOME if in non-standard location
export GHIDRA_HOME=/path/to/ghidra_11.x_PUBLIC
{baseDir}/scripts/ghidra-analyze.sh --timeout 300 -s ExportAll.java binary
# Or skip analysis for quick export
{baseDir}/scripts/ghidra-analyze.sh --no-analysis -s ExportSymbols.java binary
Set before running:
export MAXMEM=4G
Explicitly specify the processor:
{baseDir}/scripts/ghidra-analyze.sh -p "ARM:LE:32:v7" -s ExportAll.java firmware.bin
--timeout and consider --no-analysis for quick scansdevelopment
拋棄式 HTML mockup 比稿:產出 2 到 3 個設計立場不同的變體(密度 / 版式 / 強調軸,不是換色),各附取捨說明,最後給有立場的對比結論。適用:「畫個草圖」「比較 A 版 B 版」「先看方向再做」「給我看幾種做法」。要 production 元件或設計已定案時不適用。
tools
需求不明時的意圖萃取訪談:一次一題、每題附上自己的猜測、聽出「真正想要 vs 覺得應該要」,直到能預測使用者反應(約 95% 信心)才動工。適用:需求缺少對象 / 動機 / 成功標準 / 約束,或使用者點名「訪談我」「先確認一下」「我們確定嗎」。明確自足的指示、純資訊查詢、機械性操作不適用。
development
對非平凡決策啟動新鮮 context 對抗審查(找碴不背書),在修正還便宜的時候抓出錯誤方向。適用:高風險改動(production、資安敏感邏輯、不可逆操作)、不熟的程式碼、要宣稱「這樣是安全的 / 可行的」之前。機械性操作與一行修改不適用。
testing
Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.