Agent skill

Security Fuzzing

by Ch1nfo in Ch1nfo/RiftX

Essential fuzzing payloads: SQL injection, command injection, special characters.

MITAuto-check passedSecurity

Install Security Fuzzing

skills CLI
$ npx skills add Ch1nfo/RiftX --skill security-fuzzing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Ch1nfo/RiftX security-fuzzing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Ch1nfo/RiftX.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recommended-skills/security-fuzzing .claude/skills/security-fuzzing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-fuzzing
GitHub stars
113
Used in
1 other repo
Token cost
~329 tokens
SKILL.md length
81 words
Files
9 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Essential fuzzing payloads: SQL injection, command injection, special characters.

  • Tasks that involve Fuzzing
  • SKILL.md covers Description, When to Use This Skill and Key Files in This Skill
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Web application vulnerabilities

What it does

Security Fuzzing is an agent skill from Ch1nfo/RiftX. Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.

Its SKILL.md is about 330 tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including reference files.

It sits in Security, covering Fuzzing and Web application vulnerabilities. The repository describes itself as: Pentest anything you want. The licence is MIT.

When your agent uses it

  • Tasks that involve Fuzzing
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/security-fuzzing”

What it can do on your machine

Read from SKILL.md and the folder at commit 1e3369f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Fuzzing loads about 329 tokens when it runs, and up to ~238k if it reads all its reference files. Until then it costs about 36 tokens; SKILL.md has 81 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~329
With references · SKILL.md plus every file in references/, read only if the agent opens them
~238k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Ch1nfo/RiftX at commit 1e3369f, republished under its MIT licence (© Ch1nfo). 81 words, ~329 tokens.

Download SKILL.mdSave it as .claude/skills/security-fuzzing/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
security-fuzzing
description
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.

SecLists Fuzzing (Curated)

Description

Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.

Source: SecLists/Fuzzing Repository: https://github.com/danielmiessler/SecLists License: MIT

When to Use This Skill

Use this skill when you need:

  • SQL injection testing
  • Command injection testing
  • Input validation testing
  • LDAP injection
  • NoSQL injection

Key Files in This Skill

  • references/Fuzzing/Databases/SQLi/quick-SQLi.txt - Quick SQL injection tests
  • references/Fuzzing/Databases/SQLi/Generic-SQLi.txt - Generic SQL injection
  • references/Fuzzing/Databases/SQLi/sqli.auth.bypass.txt - Authentication bypass
  • references/Fuzzing/Databases/SQLi/MySQL.fuzzdb.txt - MySQL-specific payloads
  • references/Fuzzing/Databases/SQLi/NoSQL.txt - NoSQL injection payloads
  • references/Fuzzing/command-injection-commix.txt - Command injection
  • references/Fuzzing/LDAP.Fuzzing.txt - LDAP injection
  • references/Fuzzing/special-chars.txt - Special characters

© Ch1nfo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in recommended-skills/security-fuzzing of Ch1nfo/RiftX.

  • SKILL.md
  • references/Fuzzing/Databases/SQLi/Generic-SQLi.txt
  • references/Fuzzing/Databases/SQLi/MySQL.fuzzdb.txt
  • references/Fuzzing/Databases/SQLi/NoSQL.txt
  • references/Fuzzing/Databases/SQLi/quick-SQLi.txt
  • references/Fuzzing/Databases/SQLi/sqli.auth.bypass.txt
  • references/Fuzzing/LDAP.Fuzzing.txt
  • references/Fuzzing/command-injection-commix.txt
  • references/Fuzzing/special-chars.txt

Open the folder on GitHubat commit 1e3369f

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Ch1nfo/RiftX, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Fuzzing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Fuzzing this skillCh1nfo/RiftX1131 repos~329Automated safety check: PassMIT
ffuf Web FuzzerAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: PassCustom licence
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT

Similar skills

  • ffuf Web Fuzzer

    AgentSecOps/SecOpsAgentKit

    Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed

More from Ch1nfo/RiftX

  • Recon Crawl

    Ch1nfo/RiftX

    Attack-surface crawling with the crawl tool — BFS link/form/hidden-field collection, JS-bundle API route extraction, and auth boundary mapping through the scoped browser.

    113 GitHub stars~718 tokensUpdated 17 days ago
    Auto-check passed
  • LLM Testing

    Ch1nfo/RiftX

    Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.

    113 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check: warnings
  • Security Patterns

    Ch1nfo/RiftX

    Security pattern matching for code audit and content inspection: grep strings for source auditing, malicious-string signatures, PHP magic hashes, error-message patterns.

    113 GitHub stars~425 tokensUpdated 17 days ago
    Auto-check passed
  • Security Webshells

    Ch1nfo/RiftX

    Webshell samples for detection and analysis webshell 样本: PHP, ASP, ASPX, JSP, Python, Perl shells.

    113 GitHub stars~306 tokensUpdated 17 days ago
    Auto-check passed
  • Security Usernames

    Ch1nfo/RiftX

    Top username lists for enumeration: common usernames, default credentials, names.

    113 GitHub stars~226 tokensUpdated 17 days ago
    Auto-check passed

Categories

Questions about Security Fuzzing

What does Security Fuzzing do?

Essential fuzzing payloads: SQL injection, command injection, special characters. Security Fuzzing is an agent skill from Ch1nfo/RiftX. Essential fuzzing payloads: SQL injection, command injection, special characters.

When should I use Security Fuzzing?

Security Fuzzing fits situations like: tasks that involve Fuzzing; tasks that involve Web application vulnerabilities.

How do I install Security Fuzzing in Claude Code?

Run `npx skills add Ch1nfo/RiftX --skill security-fuzzing -a claude-code`. Or copy the skill folder (recommended-skills/security-fuzzing in Ch1nfo/RiftX) into .claude/skills/security-fuzzing in your project. Claude Code loads it when a task matches its description.

How do I install Security Fuzzing in Codex?

Run `npx skills add Ch1nfo/RiftX --skill security-fuzzing -a codex`. Or copy the skill folder (recommended-skills/security-fuzzing in Ch1nfo/RiftX) into .agents/skills/security-fuzzing in your project. Codex loads it when a task matches its description.

Can I use Security Fuzzing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Ch1nfo/RiftX --skill security-fuzzing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-fuzzing, .gemini/skills/security-fuzzing, .github/skills/security-fuzzing and .opencode/skills/security-fuzzing in your project.

What does Security Fuzzing need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Fuzzing is instructions for the agent only.

Does Security Fuzzing access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Security Fuzzing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Fuzzing use?

Security Fuzzing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Fuzzing use?

About 329 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 237k tokens, read only when the agent opens those files.

What are the alternatives to Security Fuzzing?

Skills that share tags, products or a category with Security Fuzzing: ffuf Web Fuzzer (AgentSecOps/SecOpsAgentKit, 220 stars), Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Fuzzing?

Ch1nfo (a GitHub user) maintains it in Ch1nfo/RiftX, which has 113 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 21, 2026.

Source: Ch1nfo/RiftX on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.