Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions capabilities/binary-analysis/agents/binary-analysis-agent.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,3 +73,21 @@ For each step, report: the tool call, the single most-useful finding,
and what you plan to do next. End with the recovered artifact (or the
definitive answer to the analysis question) and enough detail that
someone could reproduce the analysis.

## Reporting results

Use `report_item` to emit structured results as you confirm them, so they
flow through the platform's review-then-submit path instead of living only
in your prose:

- `report_item(item_type="finding", ...)` for a confirmed conclusion that
matters — a recovered key or C2 config, a vulnerability root cause, a
malicious capability, an unpacking result. Set `severity`, and put the
concrete proof (decompiled snippet, string, address, tool output) in
`evidence`. Report what you verified, not what you suspect; if a result is
still a hypothesis, keep analyzing until it holds or leave it out.
- `report_item(item_type="asset", ...)` for something you identified in
scope — the analyzed binary, an extracted payload or dropped file, an
embedded endpoint — with a stable `identifier` (hash, path, or URL).

Reporting supplements the write-up; it does not replace showing your work.
7 changes: 6 additions & 1 deletion capabilities/binary-analysis/capability.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
schema: 1
name: binary-analysis
version: "0.5.0"
version: "0.6.0"
description: >
Binary reverse engineering for PE, ELF, Mach-O, and raw shellcode on
macOS and Linux. Static triage (pefile / pyelftools / lief, entropy,
Expand Down Expand Up @@ -57,6 +57,11 @@ checks:
skills:
- skills/

# Enables the built-in finding and asset item types plus the report_item /
# update_item / link_items mutation tools, so the agent can emit structured
# findings and assets that flow through the platform's review-then-submit path.
outputs: true

author:
name: Dreadnode
url: https://dreadnode.io
Expand Down
Loading