# Decompile

> Decompile a function to C-like pseudocode using angr

- **Type:** Skill
- **Install:** `agentstack add skill-dariushoule-x64dbg-skills-decompile`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [dariushoule](https://agentstack.voostack.com/s/dariushoule)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [dariushoule](https://github.com/dariushoule)
- **Source:** https://github.com/dariushoule/x64dbg-skills/tree/main/skills/decompile

## Install

```sh
agentstack add skill-dariushoule-x64dbg-skills-decompile
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# decompile

Decompile a function from the debugged binary into C-like pseudocode using angr.

If no address is specified, decompiles the function containing the current instruction pointer. Accepts an address or symbol name as an argument.

## Instructions

Follow these steps exactly:

### 1. Check prerequisites

Run `pip show angr` via Bash. If angr is not installed, tell the user:

> angr is not installed. Install it with `pip install angr` (requires Python >= 3.10). Note: angr is a large package (~500MB+).

Then stop.

### 2. Verify debugger connection

Call `mcp__x64dbg__get_debugger_status` to confirm the debugger is connected and paused. If not debugging, tell the user and stop.

### 3. Determine target function address

**If the user provided an address or symbol as an argument:**
- If it looks like a hex address, use it directly
- If it looks like a symbol name, resolve it via `mcp__x64dbg__eval_expression`

**If no argument was provided:**
- Get the current instruction pointer via `mcp__x64dbg__get_register` (register `rip` for 64-bit, `eip` for 32-bit)
- Use the current RIP/EIP value as the target address

Call this resolved value `target_addr`.

### 4. Resolve module path and compute RVA

Use `mcp__x64dbg__eval_expression` to evaluate:
- `mod.path(target_addr)` — to get the on-disk path of the module containing the address
- `mod.base(target_addr)` — to get the module's base address

Compute the RVA: `target_addr - module_base`

If `mod.path` fails, the address may not belong to a loaded module. Tell the user and stop.

### 5. Run the decompile script

Execute:

```
python "${CLAUDE_PLUGIN_ROOT}\skills\decompile\decompile.py" --binary "" --address 
```

Where:
- `` is the on-disk path from step 4
- `` is the RVA in hex (e.g. `0x1060`)

The script may take 10-30 seconds for large binaries (CFG generation is the bottleneck). Use a timeout of at least 120 seconds.

### 6. Present results

The script outputs decompiled C pseudocode to stdout and status messages to stderr.

Present the decompiled code to the user in a ```c code block. If the script failed, relay the error message from stderr (e.g., function not found, decompilation failed) and suggest nearby functions if listed.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [dariushoule](https://github.com/dariushoule)
- **Source:** [dariushoule/x64dbg-skills](https://github.com/dariushoule/x64dbg-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-dariushoule-x64dbg-skills-decompile
- Seller: https://agentstack.voostack.com/s/dariushoule
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
