Install
$ agentstack add skill-hlnd2t-cs2-vibesignatures-write-structoffset-as-yaml ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Write Struct Offset as YAML
Persist a single struct member offset analysis result to a YAML file beside the binary using IDA Pro MCP.
Prerequisites
Before using this skill, you should have:
- Identified the struct name and member name
- Determined the member offset (and optionally size)
- Generated a unique signature using
/generate-signature-for-structoffset
Required Parameters
| Parameter | Description | Example | |-----------|-------------|---------| | struct_name | Name of the struct/class | CBaseEntity | | member_name | Name of the struct member | m_skeletonInstance | | offset | Hex offset of the member from struct start | 0x278 |
Optional Parameters
| Parameter | Description | Example | |-----------|-------------|---------| | size | Size of the member in bytes (use None to omit) | 8 | | offset_sig | Unique byte signature locating an instruction that contains the offset (use None to omit) | 8B 93 E0 04 00 00 | | offset_sig_disp | Byte displacement from signature start to the target instruction. 0 or None means signature starts at the target instruction. Non-zero means backward expansion was used by /generate-signature-for-structoffset. (use None to omit) | 8 |
Method
mcp__ida-pro-mcp__py_eval code="""
import idaapi
import os
import yaml
# === REQUIRED: Replace these values ===
struct_name = "" # e.g., "CBaseEntity"
member_name = "" # e.g., "m_skeletonInstance"
offset = # e.g., 0x278
# ======================================
# === OPTIONAL: Set to None to omit from output ===
size = # e.g., 8 or None
offset_sig = # e.g., "8B 93 E0 04 00 00" or None
offset_sig_disp = # e.g., 8 or None (0 also omitted)
# =================================================
# Get binary path and determine platform
input_file = idaapi.get_input_file_path()
dir_path = os.path.dirname(input_file)
if input_file.endswith('.dll'):
platform = 'windows'
else:
platform = 'linux'
# Build data dictionary conditionally
data = {}
data['struct_name'] = struct_name
data['member_name'] = member_name
data['offset'] = hex(offset)
if size is not None and size > 0:
data['size'] = size
if offset_sig is not None:
data['offset_sig'] = offset_sig
if offset_sig_disp is not None and offset_sig_disp > 0:
data['offset_sig_disp'] = offset_sig_disp
yaml_path = os.path.join(dir_path, f"{struct_name}_{member_name}.{platform}.yaml")
with open(yaml_path, 'w', encoding='utf-8') as f:
yaml.dump(data, f, default_flow_style=False, sort_keys=False, allow_unicode=True)
print(f"Written to: {yaml_path}")
"""
Output File Naming Convention
The output YAML filename follows this pattern:
_..yaml
Examples:
server.dll→CBaseEntity_m_skeletonInstance.windows.yamllibserver.so/libserver.so→CBaseEntity_m_skeletonInstance.linux.yaml
Output YAML Format
Full output (with size, offset_sig, and offset_sig_disp provided):
struct_name: CBaseEntity
member_name: m_skeletonInstance
offset: 0x278
size: 8
offset_sig: FF 50 ?? 48 85 C0 74 ?? 48 8B 80 A0 03 00 00 48 83 C4 28 C3
offset_sig_disp: 8
Output without backward expansion (offset_sig_disp is 0 or omitted):
struct_name: CBaseEntity
member_name: m_skeletonInstance
offset: 0x278
size: 8
offset_sig: 8B 93 78 02 00 00
Minimal output (with size=None, offset_sig=None):
struct_name: CBaseEntity
member_name: m_skeletonInstance
offset: 0x278
Each field:
struct_name- Name of the struct/classmember_name- Name of the struct memberoffset- Hex offset from struct startsize(optional) - Size in bytesoffset_sig(optional) - Unique byte signature of an instruction containing the offset (e.g.,8B 93 E0 04 00 00formov edx, [rbx+4E0h])offset_sig_disp(optional) - Byte displacement from signature start to the target instruction. Only present when non-zero (backward expansion was used). Runtime: scan foroffset_sig, then addoffset_sig_dispto get the target instruction address.
Platform Detection
The skill automatically detects the platform based on file extension:
.dll→ Windows.so→ Linux
Example Usage
With all parameters
struct_name = "CBaseEntity"
member_name = "m_skeletonInstance"
offset = 0x278
size = 8
offset_sig = "8B 93 78 02 00 00"
offset_sig_disp = None
With backward-expanded signature
struct_name = "CSkeletonInstance"
member_name = "m_animationController"
offset = 0x3A0
size = 8
offset_sig = "FF 50 40 48 85 C0 74 0C 48 8B 80 A0 03 00 00 48 83 C4 28 C3"
offset_sig_disp = 8
Without optional parameters
struct_name = "CBaseEntity"
member_name = "m_skeletonInstance"
offset = 0x278
size = None
offset_sig = None
offset_sig_disp = None
With only size
struct_name = "CBaseEntity"
member_name = "m_iHealth"
offset = 0x408
size = 4
offset_sig = None
With only signature
struct_name = "CBaseEntity"
member_name = "m_nActualMoveType"
offset = 0x4E0
size = None
offset_sig = "8B 93 E0 04 00 00"
Notes
- All offsets are written in hexadecimal format with lowercase
0xprefix - The YAML file is written to the same directory as the input binary
- When
sizeisNoneor0, thesizefield is omitted from the output entirely - When
offset_sigisNone, theoffset_sigfield is omitted from the output entirely - When
offset_sig_dispisNoneor0, theoffset_sig_dispfield is omitted from the output entirely (signature starts at the target instruction) offset_sigshould be a signature generated by/generate-signature-for-structoffsetoffset_sig_dispis the byte displacement from signature start to the target instruction, only needed when backward expansion was used
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: HLND2T
- Source: HLND2T/CS2_VibeSignatures
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.