AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Bin Triage

skill-batteryshark-rekit-bin-triage · by batteryshark

Fast format-agnostic first look at any file, pure-stdlib: identify format from magic bytes (and route to the right analyzer), chunked Shannon entropy (packed/encrypted regions), string extraction with interesting-string surfacing (URLs/IPs/onion/shell/paths/exec-APIs), and an embedded-signature scan (mini-binwalk: ZIP/gzip/ELF/PDF at non-zero offsets). When given an output dir, also CARVES large…

No reviews yet
0 installs
6 views
0.0% view→install

Install

$ agentstack add skill-batteryshark-rekit-bin-triage

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-batteryshark-rekit-bin-triage)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Bin Triage? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Binary Triage (format-agnostic)

A fast first look at any file, with no external tools. Pure-Python stdlib, read-only. Use it when you don't yet know what you're holding.

When to use

An unknown blob shows up — a dropped file, an attachment, a chunk carved out of something bigger. Run this to learn what it is and where to look next; it routes you to the format-specific analyzer (pe-analyze, elf-analyze, macho-analyze, dotnet-analyze) or to unpack for archives.

What it does

  1. Identify — format from magic bytes (ELF/PE/Mach-O/DEX/WASM, ZIP/gzip/xz/7z/

RAR/CAB/zstd/tar, PDF/PNG/JPEG, scripts) and a route to the right skill.

  1. Entropy — Shannon entropy in 4 KiB chunks → flags packed/encrypted/compressed

regions (BINARY.HIGH_ENTROPY, with the % of the file and first offset).

  1. Strings — ASCII + UTF-16LE, surfacing interesting ones: URLs, IPs, .onion

addresses, shell/exec cues (/bin/sh, cmd.exe, powershell), Windows paths, and exec/inject API names (BINARY.INTERESTING_STRING).

  1. Embedded scan — a lightweight mini-binwalk: known signatures (ZIP, gzip,

xz, 7z, ELF, PDF, PNG, zstd) found at non-zero offsetsBINARY.EMBEDDED. For actual carving/extraction of embedded filesystems use binwalk-carve.

Strictly read-only — reads bytes only, never parses as code or executes.

Usage

rekit run bin-triage ./unknown.bin
rekit run bin-triage ./firmware.img --format json

Prerequisites

  • python3 ≥ 3.8 — pure stdlib, nothing to vendor.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.