From file to useful result
How to ask with this skill installed
Installing the skill gives your AI a method. Your request still has to provide the case-specific facts, constraints and expected output.
Describe the decision or deliverable, not just the topic.
Add source material, audience, limits and known facts.
Set format, quality criteria and checks.
When to use it
- Writing new YARA-X rules for malware detection
- Reviewing existing rules for quality or performance issues
- Optimizing slow-running rulesets
- Converting IOCs or threat intel into detection signatures
- Debugging false positive issues
- Preparing rules for production deployment
- Migrating legacy YARA rules to YARA-X
- Analyzing Chrome extensions (crx module)
- Analyzing Android apps (dex module)
When not to use it
- Static analysis requiring disassembly → use Ghidra/IDA skills
- Dynamic malware analysis → use sandbox analysis skills
- Network-based detection → use Suricata/Snort skills
- Memory forensics with Volatility → use memory forensics skills
- Simple hash-based detection → just use hash lists
Mistakes to avoid
| Mistake | Bad | Good | |---------|-----|------| | API names as indicators | "VirtualAlloc" | Hex pattern of call site + unique mutex | | Unbounded regex | /https?:\\/\\/.*/ | /https?:\\/\\/[a-z0-9]{8,12}\\.onion/ | | Missing file type filter | pe.imports(...) first | uint16(0) == 0x5A4D and filesize < 10MB first | | Short strings | "abc" (3 bytes) | "abcdef" (4+ bytes) | | Unescaped braces (YARA-X) | /config{key}/ | /config\\{key\\}/ |