docs(radare2): document radare2-skills ecosystem

This commit is contained in:
deku
2026-08-14 13:44:27 +08:00
parent acf96b3e3a
commit 47d293df44
2 changed files with 53 additions and 2 deletions
+21 -2
View File
@@ -381,6 +381,27 @@ rax2 -s hello
- 命令速查:`references/cheatsheet.md`
- 标准侦察脚本:`scripts/recon.ps1`
## radare2-skills 生态
radare2-skills 项目(radareorg/radare2-skills)提供了更完整的生态工具和工作流:
- **r2xsql**:SQL 查询二进制导入表 / 字符串 / 函数
- **r2mcp / r2http**:MCP 工具与 HTTP 状态化命令通道
- **radius2**:符号执行、符号动态分析
- **r2pm**:插件管理、扩展
- **decompiler plugins**:radare2 插件机制
**使用策略**:
- 当用户提到 `r2xsql`、`r2mcp`、`r2http`、`radius2`、`r2pm`、`rabin2`、`rasm2`、`radiff2`、`rahash2`、`rax2` 时,优先路由到本 skill(radare2/SKILL.md)
- 这些工具只是生态加速器,**不能绕过**:授权门禁、`tool-index` 校验、Evidence 导入、写模式确认
- 给出最小可复现命令示例:
- `r2xsql -s <file> -q "SELECT ..."`
- `curl.exe -sS --data-binary 'aaa' http://127.0.0.1:9393/cmd`
- `radius2 -p <binary> ...`
- `r2pm -ci <plugin>`
本 skill 保持原有硬门禁和证据链完整性,不允许跳过任何授权或 Evidence 步骤。
---
## 路由上下文
@@ -394,8 +415,6 @@ rax2 -s hello
**同级关联模块**: `ida-reverse/`(互补:r2 侦察快,IDA 反编译深)
---
## 按需自举(On-Demand Bootstrap)
本 skill 的入口脚本已接入统一自举系统。缺少 radare2 时不会直接报错,而是自动尝试安装。
+32
View File
@@ -95,3 +95,35 @@ rax2 0x401000
rax2 4198400
rax2 -s hello
```
## radare2-skills 生态命令
### r2xsql 查询示例
```powershell
r2xsql -s sample.exe -q "SELECT name, module FROM imports WHERE name LIKE '%Crypt%'"
r2xsql -s sample.exe -q "SELECT addr, content FROM strings WHERE content LIKE '%http%'"
```
### r2http / r2mcp 会话
```powershell
r2 -N -e http.bind=localhost -e http.port=9393 -e http.sandbox=false -q -c=h sample.exe
curl.exe -sS --data-binary 'aaa' http://127.0.0.1:9393/cmd
curl.exe -sS --data-binary 'aflj' http://127.0.0.1:9393/cmd
```
### radius2 符号执行
```powershell
radius2 -p sample.exe -s stdin 96 -X Incorrect
radius2 -p sample.exe -s flag 256 -A . flag -B Correct -X Wrong -j
```
### r2pm 插件安装
```powershell
r2pm -ci r2ghidra
r2pm -ci r2dec
r2pm -l
```