Skip to content

feat(skills): add CyberChef MCP tooling skill and documentation - #1368

Open
noor202401938-netizen wants to merge 5 commits into
usestrix:mainfrom
noor202401938-netizen:feat/cyberchef-mcp-skill
Open

noor202401938-netizen wants to merge 5 commits into
usestrix:mainfrom
noor202401938-netizen:feat/cyberchef-mcp-skill

Conversation

@noor202401938-netizen

Copy link
Copy Markdown

Summary

Adds a native tooling skill and integration guide for the CyberChef MCP Server (cyberchef).

CyberChef provides over 500 data transformation and cryptographic operations. Connecting CyberChef via MCP enables autonomous Strix agents to:

  • Automatically deobfuscate multi-layer encoded injection payloads (e.g. Hex inside Base64 inside URL-encoded query params) using heuristic magic detection (cyberchef_magic).
  • Inspect JSON Web Tokens (JWT) for signature bypasses (alg: "none", token tampering, and claim inspection).
  • Measure Shannon entropy to distinguish plaintext, compressed assets, and encrypted or packed payloads.
  • Defang suspicious indicators before reporting.

Changes

  • strix/skills/tooling/cyberchef.md: Official playbook detailing canonical tool invocations, agent-safe baselines, common deobfuscation patterns, and failure recovery.
  • docs/integrations/mcp.mdx: Added cyberchef to the recommended MCP servers configuration template.

Testing & Validation

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Low risk] Adds CyberChef tooling documentation and configuration example.

The PR appears safe to merge, with a non-blocking correction needed to the binary entropy guidance.

Findings

  1. P2 Raw-byte entropy workflow is missing ▶
Fix with agent prompt
### Issue 1
strix/skills/tooling/cyberchef.md:106
The playbook recommends decoding Hex or Base64 before measuring entropy, but `call_mcp` passes JSON values and does not provide a way to pass arbitrary decoded bytes to the next tool. For encrypted or compressed payloads containing such bytes, an agent cannot reliably apply the stated bits-per-byte thresholds and may misclassify the payload.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR adds a CyberChef MCP tooling playbook and a sample server configuration. Since the prior review, it updates the package reference, routes examples through Strix’s generic MCP tools, and qualifies entropy guidance by encoding.

  • The dispatch and configuration-description issues from the prior review are addressed.
  • The decoded-byte entropy recommendation still needs a workable representation for binary payloads.

Reviews (2) · Last reviewed commit: "docs(cyberchef): correct operation count..."

Comment thread strix/skills/tooling/cyberchef.md Outdated
Comment thread strix/skills/tooling/cyberchef.md Outdated
Comment thread docs/integrations/mcp.mdx
@noor202401938-netizen

Copy link
Copy Markdown
Author

Thank you for the thorough and high-signal review! All 3 findings have been addressed in commit b851572:

  1. P1 — MCP Dispatch Interface: Updated the playbook to detail Strix's generic MCP dispatch architecture (list_mcps, search_mcp_tools, get_mcp_tool_schema, and call_mcp). Replaced all direct tool invocations with call_mcp(connection="cyberchef", tool="...", arguments={...}).
  2. P2 — Representation-Calibrated Shannon Entropy: Added explicit qualifications explaining that Shannon entropy is bounded by alphabet size ($\log_2(N)$). Documented calibrated thresholds for Hex ($\le 4.0$ bits/char) and Base64 ($\le 6.0$ bits/char), and advised decoding to raw byte streams before assessing binary entropy.
  3. P2 — Documentation Mismatch: Updated the introductory sentence in docs/integrations/mcp.mdx to accurately describe the local stdio servers (CyberChef and local filesystem) alongside the remote HTTP GitHub server.

Ready for re-review!

@noor202401938-netizen

Copy link
Copy Markdown
Author

Hi team! I have addressed all review feedback:

Updated all examples and playbooks to use Strix's generic call_mcp dispatch workflow with the cyberchef connection.
Calibrated the Shannon entropy guidance by input representation (Hex max 4.0 bits/char, Base64 max 6.0 bits/char, raw bytes max 8.0 bits/byte) to prevent misclassifying hex ciphertext.
Adjusted the transport wording in docs/integrations/mcp.mdx to reflect local stdio servers.
Updated the description to accurately reflect CyberChef MCP's 28 core zero-dependency deterministic operations.
Ready for your re-review!

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

Comment thread strix/skills/tooling/cyberchef.md Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant