Agent skill

Vibe Fuzz Parser Inputs

by ash1794 in ash1794/vibe-engineering

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

MITAuto-check passedBackend & APIs

Install Vibe Fuzz Parser Inputs

skills CLI
$ npx skills add ash1794/vibe-engineering --skill vibe-fuzz-parser-inputs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ash1794/vibe-engineering vibe-fuzz-parser-inputs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ash1794/vibe-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vibe-engineering/skills/vibe-fuzz-parser-inputs .claude/skills/vibe-fuzz-parser-inputs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vibe-fuzz-parser-inputs
GitHub stars
163
Token cost
~722 tokens
SKILL.md length
206 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
MIT

At a glance

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

  • Works in 5 steps: Create fuzz test file… → Seed the corpus from → Run initial fuzz → …
  • Changing a parser
  • SKILL.md covers When to Use This Skill, When NOT to Use This Skill, Steps and Output Format
  • Calls go

What it does

Vibe Fuzz Parser Inputs is an agent skill from ash1794/vibe-engineering. Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). Seeds corpus from existing fixtures and runs initial pass. Use when implementing or changing a parser, or any code that ingests user input, webhook payloads, API responses, or file formats.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Fuzzing, Test generation and Webhooks. The repository describes itself as: 33 engineering discipline skills for Claude Code, OpenAI Codex & Gemini CLI + a CLI for CI/CD enforcement. Extracted from real-world multi-agent system development. Born from… The licence is MIT.

When your agent uses it

  • Changing a parser
  • Any code that ingests user input
  • Webhook payloads

Example prompts

  • “Use the vibe-fuzz-parser-inputs skill to generate fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input)”
  • “/vibe-fuzz-parser-inputs”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Create fuzz test file (parser_fuzz_test.go)
  2. Seed the corpus from
  3. Run initial fuzz
  4. Record results
  5. Fix crashes -- Every panic or unexpected behavior becomes a permanent test case

What it can do on your machine

Read from SKILL.md and the folder at commit 8f1d71b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vibe Fuzz Parser Inputs loads about 722 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 206 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~722

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ash1794/vibe-engineering at commit 8f1d71b, republished under its MIT licence (© ash1794). 206 words, ~722 tokens.

Download SKILL.mdSave it as .claude/skills/vibe-fuzz-parser-inputs/SKILL.md (or your agent's skills folder).
name
vibe-fuzz-parser-inputs
description
Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). Seeds corpus from existing fixtures and runs initial pass. Use when implementing or changing a parser, or any code that ingests user input, webhook payloads, API responses, or file formats.
user-invocable
true

vibe-fuzz-parser-inputs

Every parser will eventually see input you didn't expect. Fuzz testing finds the crashes before production does.

When to Use This Skill

  • Implementing any parser (YAML, JSON, XML, config, DSL)
  • Processing user-supplied input
  • Handling webhook payloads or API responses
  • Parsing file formats

When NOT to Use This Skill

  • The parser is a well-tested standard library (e.g., encoding/json)
  • You're only reading known, controlled input
  • The parser is trivial (e.g., splitting a string by comma)

Steps

Go Fuzz Tests
  1. Create fuzz test file (parser_fuzz_test.go):

    go
    func FuzzParseConfig(f *testing.F) {
        // Seed corpus from existing test fixtures
        files, _ := filepath.Glob("testdata/*.yaml")
        for _, file := range files {
            data, _ := os.ReadFile(file)
            f.Add(data)
        }
    
        // Add targeted seeds
        f.Add([]byte(""))           // empty
        f.Add([]byte("{}"))         // minimal valid
        f.Add([]byte("\x00\x00"))   // binary
    
        f.Fuzz(func(t *testing.T, data []byte) {
            // Should never panic
            result, err := ParseConfig(data)
            if err != nil {
                return // errors are fine
            }
            // If no error, result should be valid
            if result.Name == "" {
                t.Error("parsed successfully but Name is empty")
            }
        })
    }
  2. Seed the corpus from:

    • Existing test fixtures
    • Real production examples
    • Known edge cases
    • Minimally valid inputs
    • Binary/garbage data
  3. Run initial fuzz:

    bash
    go test -fuzz=FuzzParseConfig -fuzztime=30s
  4. Record results:

    • Crashes found
    • New corpus entries generated
    • Edge cases discovered
  5. Fix crashes -- Every panic or unexpected behavior becomes a permanent test case

Other Languages
  • JavaScript/TypeScript: Use jest-fuzz or fast-check property-based testing
  • Python: Use hypothesis for property-based testing
  • Rust: Use cargo-fuzz with libfuzzer

Output Format

Fuzz Test: [Parser Name]

Seeds: X (Y from fixtures, Z manual) Duration: [fuzz time] Corpus growth: X -> Y entries (Z% expansion) Crashes found: N

#Input (hex)Crash TypeFix
1\x00\xff...nil panic in tokenizerAdded nil check at line 42
New Edge Cases Discovered
  1. [Description] -- added as permanent test case

© ash1794, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vibe-engineering/skills/vibe-fuzz-parser-inputs of ash1794/vibe-engineering.

Open the folder on GitHubat commit 8f1d71b

Compare with similar skills

Vibe Fuzz Parser Inputs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vibe Fuzz Parser Inputs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vibe Fuzz Parser Inputs this skillash1794/vibe-engineering163—~722Automated safety check: PassMIT
Directed Test Input GeneratorArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0
Kernel Testingmohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Run Testsnetboxlabs/netbox-branching155—~1.2kAutomated safety check: PassCustom licence
703 Technologies Fuzzing Testingjabrena/plinth447—~874Automated safety check: PassApache-2.0

Similar skills

  • Directed Test Input Generator

    ArabelaTso/Skills-4-SE

    Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

    253 GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Kernel Testing

    mohitmishra786/low-level-dev-skills

    Linux kernel testing skill for KUnit, kselftest, syzkaller, and LTP.

    253 GitHub stars~1.4k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Run Tests

    netboxlabs/netbox-branching

    Run the netboxbranching plugin's Django test suite against a local NetBox checkout.

    155 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    447 GitHub stars~874 tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Tg Bot Ops

    serejaris/personal-corp-os

    A skill your agent uses when operating, debugging, deploying, or monitoring a Telegram bot or Telegram-to-agent gateway.

    229 GitHub stars~1.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes

More from ash1794/vibe-engineering

All 33 skills in this repo
  • Vibe Concurrent Test Safety

    ash1794/vibe-engineering

    Audits tests for concurrency safety — race conditions, shared mock state, cleanup ordering.

    163 GitHub stars~665 tokensUpdated 2 days ago
    Auto-check passed
  • Vibe Golden File Testing

    ash1794/vibe-engineering

    Implements snapshot/golden file tests with temporal normalization so tests don't break daily.

    163 GitHub stars~669 tokensUpdated 2 days ago
    Auto-check passed
  • Vibe Parallel Task Decomposition

    ash1794/vibe-engineering

    Analyzes large tasks for independent subtasks that can be safely parallelized.

    163 GitHub stars~717 tokensUpdated 2 days ago
    Auto-check passed
  • Vibe Slop Filter

    ash1794/vibe-engineering

    Strips AI-generation "smell" from prose before it ships (READMEs, docs, release notes, PR descriptions, posts, emails).

    163 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Vibe Spec Sync

    ash1794/vibe-engineering

    Keeps specification documents and code in agreement. An agent skill from ash1794/vibe-engineering.

    163 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Vibe Adversarial Test Generation

    ash1794/vibe-engineering

    Generates edge case, failure mode, and spec-driven test cases.

    163 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed

Questions about Vibe Fuzz Parser Inputs

What does Vibe Fuzz Parser Inputs do?

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). Vibe Fuzz Parser Inputs is an agent skill from ash1794/vibe-engineering. Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

When should I use Vibe Fuzz Parser Inputs?

Vibe Fuzz Parser Inputs fits situations like: changing a parser; any code that ingests user input; webhook payloads.

How do I install Vibe Fuzz Parser Inputs in Claude Code?

Run `npx skills add ash1794/vibe-engineering --skill vibe-fuzz-parser-inputs -a claude-code`. Or copy the skill folder (plugins/vibe-engineering/skills/vibe-fuzz-parser-inputs in ash1794/vibe-engineering) into .claude/skills/vibe-fuzz-parser-inputs in your project. Claude Code loads it when a task matches its description.

How do I install Vibe Fuzz Parser Inputs in Codex?

Run `npx skills add ash1794/vibe-engineering --skill vibe-fuzz-parser-inputs -a codex`. Or copy the skill folder (plugins/vibe-engineering/skills/vibe-fuzz-parser-inputs in ash1794/vibe-engineering) into .agents/skills/vibe-fuzz-parser-inputs in your project. Codex loads it when a task matches its description.

Can I use Vibe Fuzz Parser Inputs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ash1794/vibe-engineering --skill vibe-fuzz-parser-inputs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-fuzz-parser-inputs, .gemini/skills/vibe-fuzz-parser-inputs, .github/skills/vibe-fuzz-parser-inputs and .opencode/skills/vibe-fuzz-parser-inputs in your project.

What does Vibe Fuzz Parser Inputs need to run?

Going by SKILL.md and its folder, Vibe Fuzz Parser Inputs needs the command-line tools its instructions call (go).

Does Vibe Fuzz Parser Inputs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vibe Fuzz Parser Inputs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vibe Fuzz Parser Inputs use?

Vibe Fuzz Parser Inputs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vibe Fuzz Parser Inputs use?

About 722 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vibe Fuzz Parser Inputs?

Skills that share tags, products or a category with Vibe Fuzz Parser Inputs: Directed Test Input Generator (ArabelaTso/Skills-4-SE, 253 stars), Kernel Testing (mohitmishra786/low-level-dev-skills, 253 stars), Fizz Convert (pashov/skills, 1.2k stars) and Run Tests (netboxlabs/netbox-branching, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vibe Fuzz Parser Inputs?

ash1794 (a GitHub user) maintains it in ash1794/vibe-engineering, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 7, 2026.

Source: ash1794/vibe-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.