Search

Security · Fuzzing

67 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

pashov/skills1.2k2 repos~11kAutomated safety check: PassMIT5 days ago
2

Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

digoal/blog8.6k—~4kAutomated safety check: PassGPL-2.0yesterday
3

Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

pashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT5 days ago
4

Reconcile an existing Fizz harness with a changed source tree.

pashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT5 days ago
5

Treat an open-ended investigation the way a fuzzer treats a program.

ARA-Labs/Agent-Native-Research-Artifact691—~2.4kAutomated safety check: PassMIT3 days ago
6

Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims.

inkline/inkline1.5k—~1.2kAutomated safety check: PassNo licence29 days ago
7

安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

tanweai/xianzhi-research185—~847Automated safety check: PassNo licence8 mo ago
8

Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

tihanyin/REx-skill108—~5.1kAutomated safety check: PassMIT16 days ago
9

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

jabrena/plinth447—~874Automated safety check: PassApache-2.02 days ago
10

Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

provos/ironcurtain612—~5.7kAutomated safety check: PassApache-2.03 days ago
11

Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

opensage-agent/opensage-adk127—~542Automated safety check: PassApache-2.02 mo ago
12

Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup.

tradecatlabs/vibe-coding-cn17k2 repos~9.9kAutomated safety check: PassMITtoday
13

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

ash1794/vibe-engineering163—~722Automated safety check: PassMIT2 days ago
14

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

InternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clausetoday
15

Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s.

s3s-project/s3s311—~838Automated safety check: PassApache-2.0yesterday
16

Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

cyberful/cyberful135—~1.5kAutomated safety check: PassAGPL-3.01 mo ago
17

Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

aviggiano/security144—~2.8kAutomated safety check: PassMIT24 days ago
18

Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

aftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.06 days ago
19

Extract crash inputs from fuzzing output into a target directory.

opensage-agent/opensage-adk127—~215Automated safety check: PassApache-2.02 mo ago
20

Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

trailofbits/skills7.5k1 repo~5.3kAutomated safety check: PassCC-BY-SA-4.0today
21

Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

Gabson0x/bountyforge442—~1.6kAutomated safety check: PassNo licence23 days ago
22

Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

AgentSecOps/SecOpsAgentKit2201 repo~3.3kAutomated safety check: PassUnknown5 mo ago
23

Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets.

trailofbits/skills7.5k—~3.2kAutomated safety check: PassCC-BY-SA-4.0today
24

Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

Encod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT1 mo ago
25

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMITtoday
26

Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

trailofbits/skills7.5k—~2.9kAutomated safety check: PassCC-BY-SA-4.0today
27

Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation.

trailofbits/skills7.5k—~2.5kAutomated safety check: PassCC-BY-SA-4.0today
28

Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.

trailofbits/skills7.5k—~4kAutomated safety check: PassCC-BY-SA-4.0today
29
29.LibaflOfficial

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library.

trailofbits/skills7.5k—~4.3kAutomated safety check: NotesCC-BY-SA-4.0today
30
30.OssfuzzOfficial

Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.

trailofbits/skills7.5k—~4.2kAutomated safety check: PassCC-BY-SA-4.0today
31
31.RuzzyOfficial

Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language.

trailofbits/skills7.5k—~3kAutomated safety check: PassCC-BY-SA-4.0today
32

Guides through Trail of Bits' 5-step secure development workflow.

trailofbits/skills7.5k—~1.7kAutomated safety check: PassCC-BY-SA-4.0today
33

Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts.

alt-research2/SolidityGuard104—~763Automated safety check: NotesUnknown3 mo ago
34

Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.

trailofbits/skills7.5k—~1.1kAutomated safety check: PassCC-BY-SA-4.0today
35

Discover hidden directories, files, and endpoints on a web server

NeoTheCapt/RedteamAgent143—~737Automated safety check: NotesNo licence2 mo ago
36
36.AflppOfficial

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

trailofbits/skills7.5k—~5.6kAutomated safety check: PassCC-BY-SA-4.0today
37

Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output.

trailofbits/skills7.5k—~5.3kAutomated safety check: PassCC-BY-SA-4.0today
38
38.LibfuzzerOfficial

Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.

trailofbits/skills7.5k—~6.1kAutomated safety check: PassCC-BY-SA-4.0today
39

Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

SnailSploit/Claude-Red7.4k—~3kAutomated safety check: WarnMIT20 days ago
40

Patrones de pruebas Go incluyendo pruebas basadas en tablas, subpruebas, benchmarks, fuzzing y cobertura de código.

affaan-m/ECC276k—~4.3kAutomated safety check: PassMITtoday
41

Current Go development guidance for modules, toolchains, workspaces, testing, fuzzing, concurrency, profiling, security, and Go tooling.

shepherdjerred/monorepo112—~1.7kAutomated safety check: PassGPL-3.0today
42

Use as the lead skill when Python tests must expose scheduler/interleaving bugs in asyncio, threading, queues, workers, databases, caches, or mixed-concurrency code

dzhalaevd/Donatello135—~3.3kAutomated safety check: PassApache-2.06 days ago
43

Discover hidden parameters, test values, and identify input handling anomalies

NeoTheCapt/RedteamAgent143—~944Automated safety check: PassNo licence2 mo ago
44

Discover hidden virtual hosts via Host header fuzzing and SSL certificate parsing.

uphiago/recon-skills1.3k—~1.4kAutomated safety check: NotesMIT1 mo ago
45

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
46

Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMITtoday
47

Essential fuzzing payloads: SQL injection, command injection, special characters.

Ch1nfo/RiftX1141 repo~329Automated safety check: PassMIT18 days ago
48

Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.

nwjs/chromium.src160—~1.1kAutomated safety check: PassBSD-3-Clausetoday