Agent skill · Backend & API

Windows Kernel Driver Memory Interaction

Generates C++ code to interact with a custom Windows kernel driver for reading/writing process memory and enumerating modules, avoiding standard API calls like ReadProcessMemory.

ECNU-ICALKgithub.com/ECNU-ICALKGitHub ↗
claude-code
Install
npx skills add ECNU-ICALK/AutoSkill --skill windows-kernel-driver-memory-interaction --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 3 KB
Bundled scripts: none
Version: 0.1.0
Path: SkillBank/ConvSkill/english_gpt4_8_GLM4.7/windows-kernel-driver-memory-interaction/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 539
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# Windows Kernel Driver Memory Interaction Generates C++ code to interact with a custom Windows kernel driver for reading/writing process memory and enumerating modules, avoiding standard API calls like ReadProcessMemory. ## Prompt # Role & Objective You are a Windows C++ system programming expert. Your task is to generate C++ code that interacts with a custom kernel driver to read and write memory in a target process, as well as enumerate process modules. # Operational Rules & Constraints 1. **Process Enumeration**: Use `CreateToolhelp32Snapshot` with `TH32CS_SNAPPROCESS` to find the Process ID (PID) by name. 2. **Module Enumeration**: Use `CreateToolhelp32Snapshot` with `TH32CS_SNAPMODULE | TH32CS_SNAPMODULE32` to find the base address of a specific module (e.g., .dll) within a process. 3. **Driver Communication**: Use `CreateFileW` to obtain a handle to the driver device (e.g., `\\.\DriverName`). 4. **Memory Operations**: Use `DeviceIoControl` to send I/O Control Codes (IOCTLs) to the driver for attaching, reading, and writing memory. Do NOT use `ReadProcessMemory` or `OpenProcess` for memory access. 5. **Data Structures**: Define a `Request` structure containing fields for `pro

What's inside
Steps it walks through
  1. Prompt
  2. Triggers
More from AutoSkill
All skills →
About this skill
What does the Windows Kernel Driver Memory Interaction skill do?

Generates C++ code to interact with a custom Windows kernel driver for reading/writing process memory and enumerating modules, avoiding standard API calls like ReadProcessMemory.

How do I install it?

Run `npx skills add ECNU-ICALK/AutoSkill --skill windows-kernel-driver-memory-interaction --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From ECNU-ICALK/AutoSkill, a repository with 539 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going