Search
Fuzzing
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Fizz Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects. | pashov/ | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | Diagnoses a failed GreptimeDB fuzz CI job by pulling its GitHub Actions logs and fuzz artifacts, then matching the evidence to the local source code. | GreptimeTeam/ | 6.7k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 3 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | 9 days ago |
| 4 | Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage. | antoniopaya22/ | 172 | 9 repos | ~4.2k | Automated safety check: Pass | No licence | 6 mo ago |
| 5 | Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. | pashov/ | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | Reconcile an existing Fizz harness with a changed source tree. | pashov/ | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | Treat an open-ended investigation the way a fuzzer treats a program. | ARA-Labs/ | 690 | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 8 | Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims. | inkline/ | 1.5k | — | ~1.2k | Automated safety check: Pass | No licence | 26 days ago |
| 9 | 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. | tanweai/ | 185 | — | ~847 | Automated safety check: Pass | No licence | 8 mo ago |
| 10 | Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware. | tihanyin/ | 105 | — | ~5.1k | Automated safety check: Pass | MIT | 14 days ago |
| 11 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI… | jabrena/ | 445 | — | ~874 | Automated safety check: Pass | Apache-2.0 | today |
| 13 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 613 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute). | opensage-agent/ | 127 | — | ~542 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 15 | Create Foundry fuzz tests from deterministic unit tests. An agent skill from aviggiano/security. | aviggiano/ | 144 | — | ~584 | Automated safety check: Pass | MIT | 22 days ago |
| 16 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | 6 days ago |
| 17 | Adds a new Go fuzz target to remindb following its seed-corpus discipline: one target per logical surface, discovered automatically by its FuzzXxx function name. | radimsem/ | 129 | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 18 | Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan. | InternationalColorConsortium/ | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | today |
| 19 | 19.Fuzz Testing Add, run or schedule a fuzz target in this repository. An agent skill from s3s-project/s3s. | s3s-project/ | 311 | — | ~838 | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 134 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 21 | Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects. | aviggiano/ | 144 | — | ~2.8k | Automated safety check: Pass | MIT | 22 days ago |
| 22 | Production-ready Golang tests — table-driven tests, testify suites and mocks, parallel tests, fuzzing, fixtures, goroutine leak detection with goleak, snapshot testing, code coverage, integration… | unxed/ | 240 | 1 repo | ~4.5k | Automated safety check: Pass | MIT | today |
| 23 | Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 4 days ago |
| 24 | Extract crash inputs from fuzzing output into a target directory. | opensage-agent/ | 127 | — | ~215 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 25 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.4k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 26 | 26.Web2 Recon Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. | Gabson0x/ | 443 | — | ~1.6k | Automated safety check: Pass | No licence | 20 days ago |
| 27 | Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans. | AgentSecOps/ | 219 | 1 repo | ~3.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 28 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 29 | Walks through adding a new file format to remindb's Go parser package: the parser file, the ParseBytes case, table tests and fuzz seeds. | radimsem/ | 129 | — | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | 30.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 31 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.4k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 32 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 33 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 34 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 35 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.4k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 36 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.4k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 37 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 38 | Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts. | alt-research2/ | 104 | — | ~763 | Automated safety check: Notes | Unknown | 3 mo ago |
| 39 | Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 40 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 140 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 41 | Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. | trailofbits/ | 7.4k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 42 | Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output. | trailofbits/ | 7.4k | — | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 43 | Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang. | trailofbits/ | 7.4k | — | ~6.1k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | Table-driven testler, subtestler, benchmark'lar, fuzzing ve test coverage içeren Go test desenleri. | affaan-m/ | 274k | 1 repo | ~4.3k | Automated safety check: Pass | MIT | 2 days ago |
| 45 | Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies… | SnailSploit/ | 7.3k | — | ~3k | Automated safety check: Warn | MIT | 17 days ago |
| 46 | Production-ready Golang tests — table-driven, testify suites/mocks, parallel tests, fuzzing, fixtures, goleak leak detection, snapshots, coverage, integration tests. | context-labs/ | 1.1k | — | ~4.4k | Automated safety check: Pass | MIT | 2 days ago |
| 47 | Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). | ash1794/ | 162 | — | ~689 | Automated safety check: Pass | MIT | yesterday |
| 48 | Patrones de pruebas Go incluyendo pruebas basadas en tablas, subpruebas, benchmarks, fuzzing y cobertura de código. | affaan-m/ | 274k | — | ~4.3k | Automated safety check: Pass | MIT | 2 days ago |