本文へ移動
cccskills
無料GitHub で公開

reverse-engineering

Read how a game actually works so a mod can hook it. Decompile .NET/Mono (ILSpy), IL2CPP (Cpp2IL, Il2CppDumper), Java (Vineflower) and native code (Ghidra, IDA, via MCP servers); dump data and asset formats; reverse-engineer a binary file format and prove it with a round trip; read live memory (Cheat Engine, Frida, x64dbg); find render passes (RenderDoc). Use when a mod needs game internals, e.g. "how does the boss AI work", "find the damage function", "what format is this .sld/.pak/.dat", "where is the player position in memory".

インストール方法を見る

含まれるファイル(1)

  • SKILL.md6.1 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Reverse engineering for mods

Rule zero: read the real thing, don't guess. Decompiled code, the actual data, a live memory view or a GPU capture is the spec. Write what you learn into MODLOG.md (names, IDs, offsets, formats) as you go.

Keep all decompiled output and extracted assets outside the mod repo (e.g. ~/<game>-decomp/) and never publish them. Single-player, offline or servers the user runs. Never attach debuggers or scanners to games with anti-cheat (see skills/mod-any-game/references/safety.md).

Pick the tool by what the code is (um scan tells you)

Managed .NET (XNA/FNA, Unity Mono, most indie C#)

  • dotnet tool install -g ilspycmd, then ilspycmd -p -o ~/<game>-decomp <Game>.exe (or Assembly-CSharp.dll). This gives a full C# project you can grep.
  • dnSpyEx: step through with a debugger, set breakpoints, edit methods.
  • MCP: ILSpy-MCP / dnspy-mcp let an agent query types and methods directly.

Unity IL2CPP

  • Cpp2IL (or Il2CppDumper) on GameAssembly.dll + global-metadata.dat gives types, fields, method signatures and addresses, plus dummy DLLs for ILSpy.
  • Method bodies are native: load GameAssembly.dll in Ghidra/IDA and apply the generated script to name functions.
  • Live: UnityExplorer, or il2cpp-frida-mcp.

Java (Minecraft, Slay the Spire...) Vineflower / CFR / Recaf. For Minecraft, use Loom genSources with Mojang mappings.

Native C/C++ (custom engines, Unreal game code, console recomps)

  • Ghidra (free) or IDA, driven through MCP so the agent can decompile, rename, retype and follow cross-references:
    • Ghidra: GhidraMCP (LaurieWired), pyghidra-mcp (headless, with a run-script tool; code-capable tools beat hundreds of tiny ones), ReVa.
    • IDA: the official Hex-Rays IDA MCP (IDA 9.4+ Pro/Home; "code mode" runs IDAPython), or ida-pro-mcp.
    • Binary Ninja and radare2 have MCP servers too.
  • Workflow:
    1. Strings, then cross-references, then the function.
    2. Name and type everything you understand. Renames accumulate into a readable program.
    3. Confirm dynamically (below) before building on a guess. Agents can confidently misidentify things.
  • Unreal: dump the reflection data first (UE4SS dumper or Dumper-7); it names most gameplay classes and properties for free.

Dynamic / live

  • Cheat Engine: value scans → "find out what writes to this address" → struct → owner. CheatEngine MCP servers exist.
  • x64dbg: breakpoints and tracing (x64dbg-mcp; bind it to 127.0.0.1, since some default to 0.0.0.0).
  • Frida (frida-mcp, frida-game-hacking-mcp): hook functions from JavaScript, log arguments.
  • ReClass.NET rebuilds structs from live memory.

Graphics

  • RenderDoc (renderdoc-mcp) captures a frame and shows every draw, the render targets, the constant buffers (view/projection matrices) and the depth buffer.
  • That's how you find where to inject geometry or effects (mashup-mods), and which texture holds a sprite atlas.

Data files and asset formats

Use the community tool first:

  • Unity: UABEA, AssetRipper
  • Unreal: FModel, UAssetGUI
  • Bethesda: xEdit, BSArch
  • GameMaker: UndertaleModTool
  • Genie: genieutils
  • Source: VRF, Crowbar
  • FromSoft: WitchyBND, Smithbox
  • Godot: GDRE Tools

Before reversing a format yourself, search the community archives. Most game formats from the 2000s and 2010s were worked out there:

Use them for format knowledge and tools, whatever its origin (betas, leaked SDKs). Don't download game files, leaked code, SDKs or license keys from them.

For an undocumented format:

  1. Collect several stock files. Compare sizes, and hex-dump the headers (xxd | head). Look for magic numbers, counts, offsets and tables of fixed-size records.
  2. Form a hypothesis for the header, then the frame/record layout, then the compression. Check it by parsing every stock file without errors.
  3. Write a reader that decodes to something viewable (PNGs, JSON) and look at it.
  4. Write the writer, and prove it with a round trip: decode → encode → decode, compared against the original. The AoE2 SLD sprite writer was accepted only when it round-tripped the stock knight at 0.9/255 mean error (examples/aoe2-de-civ/sld.py).
  5. Only then write new files. Test them in game with one asset before batch-converting.

Make it an oracle

  • Engine logic you port (for a simulator, a trainer, a reimplementation): record real traces from the game (positions, velocities per tick) and replay them against your port. In the Terraria Eye of Cthulhu work, the Eye's velocity matched 99.9% once the port used the action applied on frame t+1. Float32 constants mattered too (0.2f ≠ 0.2). A leftover mismatch was traced to a hidden buff (Happy!, x1.21 move speed). Replays find what reading the code misses.
  • For long RE runs:
    • a journal file;
    • small verified steps;
    • cap attempts per problem (about 3 identical failures, then change approach);
    • commit every confirmed fact.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Turn generated or hand-made art into exactly what a game engine loads. Covers sprite cutout, trim and nearest-neighbour fitting to frame sizes, pixelation to a palette, sprite sheets and strips, player/team-colour masks, seamless textures, and rendering a 3D model into sprite frames from the game's own camera (isometric/RTS 8 or 16 headings, side view, top-down) with Blender. Use after generating assets, or when the user asks to make sprites, sprite sheets, animation frames, isometric unit sprites or icons for a game.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

Generate game assets with fal (fal.ai) through the fal MCP server, the `um fal` CLI (REST) or `fal api`. Covers sprites and icons with transparent backgrounds, consistent variants and animation frames, pixel art, seamless textures, PBR material maps, image-to-3D models, remeshing, auto-rigging, sound effects, music, voice lines, and trailer or cutscene video. Use whenever a mod needs new art, audio or 3D models, or the user mentions fal, generating sprites, textures, models, SFX or music for a game.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

Launch, see and drive a real game so an agent can test its own mods. Covers launching via Steam or the exe, windowed mode at a fixed size, screenshots of the game window (GPU-safe capture), clicking and typing into menus, holding keys, relative mouse, crash-reporter cleanup, killing by PID, reading logs, scripted test scenes, and an in-game JSON bridge that lets an agent observe and act. Windows-first (also from WSL), with notes for Linux and macOS. Use when a mod must be verified in game, when navigating menus automatically, or when building a repeatable test or demo scene.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

Figure out how a specific installed game can be modded, before writing any mod code. Covers where it's installed, the engine and version, managed vs native code, anti-cheat, loaders already present, save and config folders, and the community's modding route. Use when the user asks "can I mod <game>?", "what engine is <game>", "how do people mod <game>", or at the start of any modding task. Produces MODDING_PLAN.md.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

Research a game, engine or modding technique on the open web with archive-aware, rate-limit-safe searches — Wayback Machine/archive.today for dead forums (XeNTaX, Zenhax, old threads), GitHub code/repo search, Nexus/Steam Workshop/Thunderstore APIs, Reddit JSON, YouTube transcripts, plus archive snapshots as evidence. Use when starting work on a game ("how did people mod X before?"), when a documented tool/link is dead, when forum threads are login-gated (semi-auto handoff to the human), and before writing a field note so claims carry source URLs.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

Build cross-game mashups and total conversions, the "Minecraft inside Elden Ring" or "skateboarding in MW2" kind. Covers passthrough mods (two games running at once and exchanging state, rendering and collision), porting one game's content or mechanics into another, embedding a decompiled game as a library, and clean reimplementations that read the user's own game files. Use when the user wants to combine two games, bring an enemy, mechanic or world from one game into another, or rebuild a game's runtime, or reimplement the guest's rules headless inside a real host.

日本語の概要は準備中です。原文の説明を表示しています。

rehan-remade/universal-modder6,4262026年10月10日 更新

rehan-remade のスキルをすべて見る

このスキルの問題を報告する