# Add to your Claude Code skills
git clone https://github.com/Ablation-Tool/ablationSee how ablation compares with popular alternatives.
ablation is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Ablation-Tool. Ablation is a reverse engineering framework. It has 51 GitHub stars.
ablation's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/Ablation-Tool/ablation" and add it to your Claude Code skills directory (see the Installation section above).
ablation is primarily written in Python. It is open-source under Ablation-Tool on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh ablation against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
Español · Português · Français · Deutsch · 中文 · 日本語 · Русский · العربية · 한국어 · हिन्दी · Italiano · Türkçe · Tiếng Việt · Indonesia · Polski · Nederlands
Ablation is a reverse engineering framework that provides the exact same core disassembly, decompilation, and binary analysis capabilities as industry-standard tools like Ghidra, IDA Pro, and Binary Ninja.
Combined with Claude Code or OpenAI Codex, it transforms into a fully autonomous reverse engineering tool.

Semantic Search via BERT: Semantic search finds results based on meaning rather than exact keywords. BERT reads text and figures out what it means. Similar meanings get similar scores, so you can search by concept instead of exact words. By combining the two, it speeds up the main bottleneck of reverse engineering while finding the vulnerable functions.
Extreme Performance: A 50 MB binary loads in 35 seconds. Ghidra and IDA Pro can take hours because they parse the entire file into a database before you can do anything. Ablation only analyzes the functions you are actively working on, so you start immediately.
Version Diffing: Utilizing the Jaccard method to measure how much a function's behavior overlaps between releases and Dynamic Time Warping that tracks the "shape" of how a function executes across those versions of firmware or software that a vendor updated, Ablation confirms whether a patch actually changed the logic or just the packaging, because a cosmetic recompile can't hide an unpatched vulnerability.
Cross-Binary Analysis: Analyze every shared library in a firmware image simultaneously, tracking data flows across binary boundaries.
Source Code Audit: Audit any large codebase faster than reading it linearly, with higher accuracy than pattern matching alone. Every source file gets a 5-bit security profile that determines exactly how much attention it needs, so nothing gets missed and nothing gets read twice.
Windows Kernel Driver & BYOVD Analysis: Scans kernel drivers for entry points that expose system memory or admin privileges from user mode. One signed driver with those capabilities is enough to disable endpoint security software.
Android / APK Analysis: Reads Android APKs at the binary level with no dependencies. It maps native code entry points and IPC surface from compiled bytecode, so the full surface is visible without decompiling. LibraryInventory scans every native library in a directory at once, scores each one by credential exposure and JNI attack surface, and sorts the results so the high-risk library surfaces first. The engagement starts on the library most likely to have a finding, not the one that happens to be listed first in the filesystem.
Erlang / BEAM Analysis: Maps exports, imports, and atoms from .beam bytecode files, so dangerous calls like os:cmd and code:load_binary are visible without running the release.
Cryptographic Analysis
Ablation strips away every layer that makes cryptography invisible in a compiled binary. Entropy Mapper locates the encrypted region. Crypto Audit and HashAlgoDiscriminator identify the algorithm. XorSolver, BmpKeyExtractor, and CustomCBCDetector break the encryption or recover the key. ELFVtableReconstructor and VtableDispatchScanner reconstruct what the runtime does with the result.
A binary can hide its crypto from import-table analysis, from symbol tables, and from string search. These eight tools collectively close that gap, so by the end you know the algorithm, the key, and the ciphertext.
Ablation has been used to analyze production firmware and kernel drivers from Cisco, Fortinet, Juniper, Apple MacOS, Microsoft Windows, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio, Axis Communications, Dahua Security System, and Tuya.
Following coordinated disclosure on Cisco FMC and ISE, the Cisco Product Security Incident Response Team (PSIRT) has adopted Ablation for internal vulnerability triage. Cisco PSIRT is actively using it to triage ongoing disclosure reports across Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex, and Catalyst. Cisco Adaptive Security Appliance (ASA) LINA has also been reverse engineered using Ablation, with findings currently under coordinated triage via CERT/CC VINCE.
| CVE | Product | Title | CVSS | Advisory |
|---|---|---|---|---|
| CVE-2026-76420 | Secure Firewall Management Center (FMC) | Peer Impersonation | 9.0 Critical | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76412 | Secure Firewall Management Center (FMC) | Privilege Escalation to root | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76413 | Secure Firewall Management Center (FMC) | Single Sign-On Token Forgery | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76447 | Identity Services Engine (ISE) | OCSP Responder Authentication Bypass | 5.3 Medium | cisco-sa-ise-multiauth-bypass-sgD2HbL4 |
| Architecture | Variants |
|---|---|
| x86 | x86-32 · x86-64 |
| ARM | ARM-32 · ARM-64 |
| MIPS | MIPS-32 · nanoMIPS · MIPS-64 |
| PowerPC | PPC-32 · PPC-64 |
| RISC-V | RISC-V 32 · RISC-V 64 |
| Embedded | ARC EM/HS · V850-32 |
| Provider | Models |
|---|---|
| Claude Code | /model claude-sonnet-4-6 |
| OpenAI Codex | All known models |
pip install git+https://github.com/Ablation-Tool/ablation
capstone, numpy, lief, sentence-transformers, pyelftoolsAblation is built for authorized security research. Use it only against systems you own or have explicit written permission to test. Running it against systems without authorization violates computer fraud laws in most jurisdictions. The authors are not responsible for misuse.
This project was greatly informed and inspired by several key literary works.
Research Papers