AgentStack
SKILL verified MIT Self-run

State Snapshot

skill-dariushoule-x64dbg-skills-state-snapshot · by dariushoule

Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis

No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add skill-dariushoule-x64dbg-skills-state-snapshot

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of State Snapshot? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

state-snapshot

Capture a full debuggee state snapshot — all committed memory regions as raw binary files plus the complete processor state as JSON.

Instructions

Follow these steps exactly:

1. Verify debugger connection

Call mcp__x64dbg__get_debugger_status to confirm the debugger is connected and a debuggee is loaded. Note the session PID and x64dbg path from the current MCP connection — you will need these to reconnect later.

If no debuggee is loaded, tell the user and stop.

2. Pause the debuggee if running

If the debugger status shows the debuggee is running (not paused), call mcp__x64dbg__pause to pause it. Remember that you auto-paused so you can resume later.

3. Disconnect the MCP client

Call mcp__x64dbg__disconnect to release the ZMQ connection. This is required because only one client can be connected to an x64dbg session at a time, and the Python script needs its own connection.

4. Run the snapshot script

Execute the snapshot script:

python "${CLAUDE_PLUGIN_ROOT}\skills\state-snapshot\state_snapshot.py" --x64dbg-path "" --pid 

Where:

  • `` is the path to the x64dbg executable noted in step 1
  • `` is the debugger process PID noted in step 1

The script defaults output to ./snapshots//. If the user specified a custom output directory, pass --output-dir .

5. Reconnect the MCP client

Call mcp__x64dbg__connect_to_session with the x64dbg path and session PID saved from step 1 to restore the MCP connection.

6. Report results

Summarize what was captured:

  • Output directory path
  • Number of memory region files saved and total size
  • Whether registers were captured successfully
  • Any regions that failed to read

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.