You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Inspect JSON Web Tokens (JWT) for signature bypasses (alg: "none", token tampering, and claim inspection).
Measure Shannon entropy to distinguish plaintext, compressed assets, and encrypted or packed payloads.
Defang suspicious indicators before reporting.
Changes
strix/skills/tooling/cyberchef.md: Official playbook detailing canonical tool invocations, agent-safe baselines, common deobfuscation patterns, and failure recovery.
docs/integrations/mcp.mdx: Added cyberchef to the recommended MCP servers configuration template.
Testing & Validation
Verified skill registration via strix.skills._iter_user_skill_files(): returns ('tooling', 'cyberchef').
All tests/test_skill_dir_extension.py tests pass (20/20).
### Issue 1
strix/skills/tooling/cyberchef.md:106
The playbook recommends decoding Hex or Base64 before measuring entropy, but `call_mcp` passes JSON values and does not provide a way to pass arbitrary decoded bytes to the next tool. For encrypted or compressed payloads containing such bytes, an agent cannot reliably apply the stated bits-per-byte thresholds and may misclassify the payload.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary
The PR adds a CyberChef MCP tooling playbook and a sample server configuration. Since the prior review, it updates the package reference, routes examples through Strix’s generic MCP tools, and qualifies entropy guidance by encoding.
The dispatch and configuration-description issues from the prior review are addressed.
The decoded-byte entropy recommendation still needs a workable representation for binary payloads.
Thank you for the thorough and high-signal review! All 3 findings have been addressed in commit b851572:
P1 — MCP Dispatch Interface: Updated the playbook to detail Strix's generic MCP dispatch architecture (list_mcps, search_mcp_tools, get_mcp_tool_schema, and call_mcp). Replaced all direct tool invocations with call_mcp(connection="cyberchef", tool="...", arguments={...}).
P2 — Representation-Calibrated Shannon Entropy: Added explicit qualifications explaining that Shannon entropy is bounded by alphabet size ($\log_2(N)$). Documented calibrated thresholds for Hex ($\le 4.0$ bits/char) and Base64 ($\le 6.0$ bits/char), and advised decoding to raw byte streams before assessing binary entropy.
P2 — Documentation Mismatch: Updated the introductory sentence in docs/integrations/mcp.mdx to accurately describe the local stdio servers (CyberChef and local filesystem) alongside the remote HTTP GitHub server.
Updated all examples and playbooks to use Strix's generic call_mcp dispatch workflow with the cyberchef connection.
Calibrated the Shannon entropy guidance by input representation (Hex max 4.0 bits/char, Base64 max 6.0 bits/char, raw bytes max 8.0 bits/byte) to prevent misclassifying hex ciphertext.
Adjusted the transport wording in docs/integrations/mcp.mdx to reflect local stdio servers.
Updated the description to accurately reflect CyberChef MCP's 28 core zero-dependency deterministic operations.
Ready for your re-review!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a native tooling skill and integration guide for the CyberChef MCP Server (
cyberchef).CyberChef provides over 500 data transformation and cryptographic operations. Connecting CyberChef via MCP enables autonomous Strix agents to:
cyberchef_magic).alg: "none", token tampering, and claim inspection).Changes
strix/skills/tooling/cyberchef.md: Official playbook detailing canonical tool invocations, agent-safe baselines, common deobfuscation patterns, and failure recovery.docs/integrations/mcp.mdx: Addedcyberchefto the recommended MCP servers configuration template.Testing & Validation
strix.skills._iter_user_skill_files(): returns('tooling', 'cyberchef').tests/test_skill_dir_extension.pytests pass (20/20).cyberchef-mcpserver (https://github.com/noor202401938-netizen/cyber-chef-mcp).