本文へ移動
cccskills
無料GitHub で公開

dump-vtables

Batch-dump vtables from IDA Pro MCP by searching mangled symbol patterns, then write a merged YAML file beside the binary. Use this skill when you need to find and export all vtables matching a name pattern (e.g., all GameSystem vtables) in one shot. Triggers: dump vtables, batch vtable dump, export vtables, dump all vtables matching pattern

インストール方法を見る

含まれるファイル(2)

  • SKILL.md5.6 KB
  • agents/openai.yaml43 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dump VTables by Symbol Pattern

Search for vtable symbols matching a mangled name glob pattern via IDA Pro MCP, read all their entries, and write a merged YAML file beside the binary.

Prerequisites

  • An IDA Pro MCP instance with the target binary loaded

Required Parameters

ParameterDescriptionExample
symbol_patternMangled symbol glob pattern for vtables??_7C*System@@6B@
output_nameBase name for the output YAML file (without extension)IGameSystem_vtables

Method

Step 1: Search for matching vtable symbols

Use mcp__ida-pro-mcp__entity_query with kind names and a glob filter to find all matching mangled vtable symbols:

mcp__ida-pro-mcp__entity_query queries={"kind": "names", "filter": "<symbol_pattern>", "count": 0}

This returns all matching symbol names, addresses, and segments.

Step 2: Read vtable entries and write merged YAML

Run a single mcp__ida-pro-mcp__py_eval script that:

  1. Iterates each discovered vtable address
  2. Reads consecutive qword pointers until hitting a non-code address or 0
  3. Gets func.size() for each entry
  4. Writes a merged YAML list to disk
mcp__ida-pro-mcp__py_eval code="""
import idaapi
import ida_bytes
import ida_name
import os
import yaml

# === REQUIRED: Replace these values ===
output_name = "<output_name>"  # e.g., "IGameSystem_vtables"

# Populate from Step 1 results: list of (address, class_name, mangled_symbol)
vtables = [
    # (0x181538bb8, "CCSGCServerSystem", "??_7CCSGCServerSystem@@6B@"),
    # ...add all matches from entity_query results...
]
# ======================================

image_base = idaapi.get_imagebase()
ptr_size = 8 if idaapi.inf_is_64bit() else 4

input_file = idaapi.get_input_file_path()
dir_path = os.environ.get('CS2VIBE_ARTIFACT_DIR') or os.path.dirname(input_file)
platform = 'windows' if input_file.endswith('.dll') else 'linux'

all_vtables = []
for vt_addr, vt_name, vt_symbol in vtables:
    entries = []
    for i in range(1000):
        if ptr_size == 8:
            ptr_value = ida_bytes.get_qword(vt_addr + i * ptr_size)
        else:
            ptr_value = ida_bytes.get_dword(vt_addr + i * ptr_size)

        if ptr_value == 0 or ptr_value == 0xFFFFFFFFFFFFFFFF:
            break

        func = idaapi.get_func(ptr_value)
        if func is None:
            flags = ida_bytes.get_full_flags(ptr_value)
            if not ida_bytes.is_code(flags):
                break

        entries.append((ptr_value, func))

    count = len(entries)
    vtable_size = count * ptr_size
    vt_rva = vt_addr - image_base

    entries_dict = {}
    for i, (ptr_value, func) in enumerate(entries):
        func_size = func.size() if func else 0
        entries_dict[i] = f"{hex(ptr_value)} size={hex(func_size)}"

    yaml_data = {
        'vtable_class': vt_name,
        'vtable_symbol': vt_symbol,
        'vtable_va': hex(vt_addr),
        'vtable_rva': hex(vt_rva),
        'vtable_size': hex(vtable_size),
        'vtable_numvfunc': count,
        'vtable_entries': entries_dict
    }
    all_vtables.append(yaml_data)

yaml_path = os.path.join(dir_path, f"{output_name}.{platform}.yaml")
with open(yaml_path, 'w', encoding='utf-8') as f:
    yaml.dump(all_vtables, f, default_flow_style=False, sort_keys=False, allow_unicode=True)

print(f"Written {len(all_vtables)} vtables to {yaml_path}")
"""

Deriving vtable_class from the Mangled Symbol

For MSVC mangled vtable symbols (??_7<ClassName>@@6B@), extract the class name by stripping the ??_7 prefix and @@6B@ suffix.

For nested classes like ??_7CServerSideClient_GameEventLegacyProxy@CSource1LegacyGameEventGameSystem@@6B@, use the outermost class or a descriptive name (e.g., CSource1LegacyGameEventGameSystem_Proxy).

Output File Naming Convention

  • <output_name>.<platform>.yaml
  • Written to the same directory as the input binary

Examples:

  • IGameSystem_vtables.windows.yaml
  • IGameSystem_vtables.linux.yaml

Output YAML Format

The file is a YAML list. Each entry follows the write-vtable-as-yaml convention with an added size= annotation per vfunc:

- vtable_class: CCSGCServerSystem
  vtable_symbol: ??_7CCSGCServerSystem@@6B@
  vtable_va: '0x181538bb8'
  vtable_rva: '0x1538bb8'
  vtable_size: '0x238'
  vtable_numvfunc: 71
  vtable_entries:
    0: 0x180ea9370 size=0x21
    1: 0x1801b7cd0 size=0x5
    2: 0x1801b88d0 size=0xb0

- vtable_class: CBotGameSystem
  vtable_symbol: ??_7CBotGameSystem@@6B@
  vtable_va: '0x18156c280'
  vtable_rva: '0x156c280'
  vtable_size: '0x1f8'
  vtable_numvfunc: 63
  vtable_entries:
    0: 0x180166080 size=0x14
    1: 0x18016b6f0 size=0x3
    ...

Entry format

Each vtable_entries value is a string: <hex_address> size=<hex_func_size>

  • size=0x0 means IDA has no function defined at that address (code but no func_t)
  • Small sizes like size=0x3 typically indicate stubs/thunks (ret or similar)

Notes

  • All addresses are version-specific and must be regenerated for each binary update
  • The script stops reading a vtable when it encounters a NULL pointer, BADADDR, or a non-code address
  • Maximum 1000 entries per vtable (safety limit)
  • Uses yaml.dump for consistent formatting with other skill outputs

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Clean up the local workspace after a dev branch has been merged into main. Verifies the current dev branch is fully merged into origin/main, then switches to main, pulls the latest, deletes the local dev branch, and deletes the remote dev branch if it still exists. STOPS and warns the user if the current branch is not yet merged. Triggers: cleanup workspace, cleanup branch, delete merged branch, finish dev branch, post-merge cleanup

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Convert an existing find-XXXX SKILL.md into a preprocessor Python script, updating configs/<GAMEVER>.yaml and removing the old SKILL.md. Covers xref-string-based and LLM_DECOMPILE-based discovery patterns.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create an Agent SKILL.md fallback for an existing find-XXXX finder that relies on a fragile discovery foundation — above all LLM_DECOMPILE (patterns C/D/E), which matches the decompiled shape of a predecessor function against a stored reference and breaks when a symbol is inlined or de-inlined in a way the reference does not cover. The generated fallback coexists with the preprocessor and runs only when it returns failure, recovering every target robustly by decompiling the predecessor and following the inline/de-inline boundary with semantic anchors. Use when a finder broke on a game update, or you want to durably backstop one before it does. The recipe generalizes to any finder foundation. Triggers: create agent skill fallback, add SKILL.md fallback, robust fallback for finder, backstop LLM_DECOMPILE finder, final guarantee skill

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create a new cpp_tests entry for validating a C++ interface vtable layout against binary reference YAMLs. Creates the .cpp test file in cpp_tests/ and appends a configs/<GAMEVER>.yaml entry under cpp_tests:. Use when a user asks to add vtable layout validation for a new hl2sdk_cs2 interface class.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

create-pr

無料

Create a GitHub pull request from staged task changes or an already-committed current branch. Deliver source/config/ reference changes together with their computed source-owned `bin_artifacts` closure. PR validation routing is owned by the default-branch trusted workflow; snapshots, gamedata, and manifests are Release-derived only.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create a new find-XXXX preprocessor Python script from scratch (no existing SKILL.md), add configs/<GAMEVER>.yaml skill and symbol entries. Covers xref-string-based and LLM_DECOMPILE-based discovery patterns. Use when a GitHub issue or user instruction specifies a new function to find.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

mrc4tt のスキルをすべて見る

このスキルの問題を報告する