Bare-metal firmware reversing
The agent loaded an 11.4 KB AVR8 flash image into Ghidra via GhidraMCP and ran a full static reverse-engineering session β mapping the boot flow from the RESET vector, decompiling the authentication loop, and pinpointing a timing-vulnerable compare at 0x0006e8. It extracted the hardcoded password (TImInG@ttAkw0rk) and AES-128 key straight from flash, and flagged three CWEs (timing side-channel, hardcoded key, weak nonce).
Timestamps
- 0:00 Recording start
- 0:01 CSI Agents start
- 0:10 Claude Code boots on alias2-mini
- 0:23 GhidraMCP loaded and ready
- 0:40 Function listing & exploration
- 2:20 Decompile password-compare function
- 5:35 Claude Code boots on Opus 4.7
- 10:18 Password revealed by alias2-mini
- 10:38 Matching reveal by Opus 4.7
- 11:06 Report generation
- 12:35 Final summary β alias2-mini



