Agent skill

API Fuzzer

by FerroxLabs in FerroxLabs/wayland

API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and…

Apache-2.0Auto-check passedSecurity

Install API Fuzzer

skills CLI
$ npx skills add FerroxLabs/wayland --skill api-fuzzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland api-fuzzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/testing-quality/api-fuzzer .claude/skills/api-fuzzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-fuzzer
GitHub stars
608
Token cost
~4.8k tokens
SKILL.md length
293 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and…

  • The user asks about api fuzzer
  • SKILL.md covers Property-Based Testing, API Fuzz Testing, Mutation Testing and Edge Case Generation Strategies, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Api fuzzer best practices

What it does

API Fuzzer is an agent skill from FerroxLabs/wayland. API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and mutmut, boundary value analysis, schema-driven fuzzing, and automated discovery of bugs through randomized inputs. Use when the user asks about api fuzzer, api fuzzer best practices, or needs guidance on api fuzzer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about api fuzzer
  • Api fuzzer best practices
  • Needs guidance on api fuzzer implementation
  • The user needs a different specialized skill

Example prompts

  • “/api-fuzzer”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, bash, typescript and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Fuzzer loads about 4.8k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 293 words, ~4,773 tokens.

Download SKILL.mdSave it as .claude/skills/api-fuzzer/SKILL.md (or your agent's skills folder).
name
api-fuzzer
description
API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and mutmut, boundary value analysis, schema-driven fuzzing, and automated discovery of bugs through randomized inputs. Use when the user asks about api fuzzer, api fuzzer best practices, or needs guidance on api fuzzer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
testing best-practices security
metadata.category
testing-quality
metadata.subcategory
test-methodology
metadata.disclaimer
none
metadata.difficulty
beginner

API Fuzzer

You are an expert API Fuzzer who finds bugs that traditional example-based tests miss. You use property-based testing to verify invariants across thousands of random inputs, fuzz APIs with schema-driven input generation, apply mutation testing to measure test suite effectiveness, and systematically explore boundary conditions and edge cases that developers overlook.

Property-Based Testing

Core Concept
Traditional testing:
  "Given input X, expect output Y" (one example at a time)

Property-based testing:
  "For ALL valid inputs, this property ALWAYS holds"
  (framework generates hundreds/thousands of random inputs)

Properties to test:
  1. Invariants: "The result always satisfies condition C"
  2. Idempotency: "Doing it twice gives the same result as once"
  3. Round-trip: "encode(decode(x)) == x"
  4. Commutativity: "f(a, b) == f(b, a)"
  5. Equivalence: "fast_function(x) == reference_function(x)"
  6. No-crash: "The function never throws for valid input"
Python: Hypothesis
python
from hypothesis import given, strategies as st, assume, settings, example
from hypothesis.stateful import RuleBasedStateMachine, rule, precondition
import pytest

# Strategy basics: generate random data of specific types
@given(st.integers(), st.integers())
def test_addition_commutative(a, b):
    assert a + b == b + a

@given(st.lists(st.integers()))
def test_sort_idempotent(xs):
    assert sorted(sorted(xs)) == sorted(xs)

@given(st.lists(st.integers(), min_size=1))
def test_sort_preserves_length(xs):
    assert len(sorted(xs)) == len(xs)

# Custom strategies for domain objects
user_strategy = st.fixed_dictionaries({
    'username': st.text(
        alphabet=st.characters(whitelist_categories=('L', 'N')),
        min_size=3, max_size=30
    ),
    'email': st.emails(),
    'age': st.integers(min_value=0, max_value=150),
    'role': st.sampled_from(['admin', 'user', 'viewer']),
})

@given(user=user_strategy)
def test_user_creation_roundtrip(user):
    """Creating and then fetching a user returns equivalent data."""
    created = create_user(user)
    fetched = get_user(created['id'])
    assert fetched['username'] == user['username']
    assert fetched['email'] == user['email']

# API endpoint property testing
@given(
    title=st.text(min_size=1, max_size=200),
    content=st.text(min_size=1, max_size=10000),
)
@settings(max_examples=200, deadline=5000)  # 200 test cases, 5s timeout each
def test_create_post_always_returns_valid_id(client, title, content):
    """POST /api/posts always returns a valid UUID for valid input."""
    response = client.post('/api/posts', json={
        'title': title,
        'content': content,
    })
    assert response.status_code == 201
    data = response.json()
    assert 'id' in data
    assert len(data['id']) == 36  # UUID format

# Explicit edge cases alongside random generation
@given(st.text())
@example('')           # Always test empty string
@example(' ')          # Whitespace only
@example('a' * 10000)  # Very long string
@example('\x00')       # Null byte
@example('<script>alert(1)</script>')  # XSS attempt
def test_search_never_crashes(client, query):
    """Search endpoint handles any string input without 500 errors."""
    response = client.get(f'/api/search', params={'q': query})
    assert response.status_code in [200, 400]  # OK or validation error, never 500
JavaScript: fast-check
typescript
import fc from 'fast-check';

// Basic property test
test('JSON roundtrip', () => {
  fc.assert(
    fc.property(fc.anything(), (value) => {
      // Some values are not JSON-serializable (undefined, functions)
      // So we test the roundtrip property for serializable values
      const serializable = JSON.parse(JSON.stringify(value));
      expect(JSON.parse(JSON.stringify(serializable))).toEqual(serializable);
    })
  );
});

// API property test
test('POST /users always returns created user with valid input', () => {
  fc.assert(
    fc.asyncProperty(
      fc.record({
        username: fc.string({ minLength: 3, maxLength: 30 })
          .filter(s => ./^[a-zA-Z0-9_]+$/.test(s)),
        email: fc.emailAddress(),
        age: fc.integer({ min: 18, max: 120 }),
      }),
      async (userData) => {
        const response = await get('/api/users', {
          method: 'POST',
          headers: { 'Content-Type': 'application/json' },
          body: JSON.stringify(userData),
        });

        // Property: valid input always produces 201 or 409 (duplicate)
        expect([201, 409]).toContain(response.status);

        if (response.status === 201) {
          const created = await response.json();
          // Property: created user has the submitted username
          expect(created.username).toBe(userData.username);
          // Property: id is always a valid UUID
          expect(created.id).toMatch(
            /^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/
          );
        }
      }
    ),
    { numRuns: 100 }
  );
});

// Custom arbitraries for domain-specific data
const orderArbitrary = fc.record({
  items: fc.array(
    fc.record({
      productId: fc.uuid(),
      quantity: fc.integer({ min: 1, max: 99 }),
      unitPrice: fc.float({ min: 0.01, max: 9999.99, noNaN: true }),
    }),
    { minLength: 1, maxLength: 20 }
  ),
  couponCode: fc.option(fc.stringOf(fc.constantFrom(...'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789'), { minLength: 5, maxLength: 10 })),
});

test('order total is always sum of (quantity * unitPrice)', () => {
  fc.assert(
    fc.property(orderArbitrary, (order) => {
      const result = calculateOrderTotal(order);
      const expectedTotal = order.items.reduce(
        (sum, item) => sum + item.quantity * item.unitPrice, 0
      );
      // Property: total matches calculated sum (within floating point tolerance)
      expect(Math.abs(result.total - expectedTotal)).toBeLessThan(0.01);
      // Property: total is never negative
      expect(result.total).toBeGreaterThanOrEqual(0);
    })
  );
});
Stateful Property Testing
python
# Stateful testing: model-based testing that generates sequences of operations
from hypothesis.stateful import RuleBasedStateMachine, rule, initialize, precondition
from hypothesis import strategies as st

class ShoppingCartStateMachine(RuleBasedStateMachine):
    """Tests that our shopping cart implementation matches a simple model."""

    def __init__(self):
        super().__init__()
        self.model_cart = {}     # Our simple reference model: {product_id: quantity}
        self.real_cart = None     # The real cart API

    @initialize()
    def create_cart(self):
        response = self.client.post('/api/cart')
        self.real_cart = response.json()['id']
        self.model_cart = {}

    @rule(product_id=st.sampled_from(['prod-1', 'prod-2', 'prod-3']),
          quantity=st.integers(min_value=1, max_value=10))
    def add_item(self, product_id, quantity):
        # Apply to model
        self.model_cart[product_id] = self.model_cart.get(product_id, 0) + quantity

        # Apply to real system
        response = self.client.post(
            f'/api/cart/{self.real_cart}/items',
            json={'product_id': product_id, 'quantity': quantity}
        )
        assert response.status_code == 200

    @precondition(lambda self: len(self.model_cart) > 0)
    @rule(data=st.data())
    def remove_item(self, data):
        product_id = data.draw(st.sampled_from(list(self.model_cart.keys())))

        # Apply to model
        del self.model_cart[product_id]

        # Apply to real system
        response = self.client.delete(
            f'/api/cart/{self.real_cart}/items/{product_id}'
        )
        assert response.status_code == 200

    @rule()
    def check_cart_state(self):
        """Invariant: real cart always matches model cart."""
        response = self.client.get(f'/api/cart/{self.real_cart}')
        real_items = {item['product_id']: item['quantity']
                     for item in response.json()['items']}
        assert real_items == self.model_cart


# Run the state machine test
TestShoppingCart = ShoppingCartStateMachine.TestCase

API Fuzz Testing

Schema-Driven Fuzzing
python
# Generate fuzz inputs from OpenAPI/JSON Schema
import schemathesis
import hypothesis

# Load API schema and generate test cases
schema = schemathesis.from_url('[reference URL]')

@schema.parametrize()
def test_api_endpoint(case):
    """Every endpoint handles random valid input without 500 errors."""
    response = case.call()

    # Property: server should never return 500 for valid schema input
    assert response.status_code < 500, (
        f"Server error on {case.method} {case.path}\n"
        f"Input: {case.body}\n"
        f"Response: {response.text[:500]}"
    )

# Target specific endpoints
@schema.parametrize(endpoint='/api/users', method='POST')
def test_create_user_fuzz(case):
    response = case.call()
    if response.status_code == 201:
        data = response.json()
        assert 'id' in data
        assert 'email' in data

# Run with: pytest --hypothesis-seed=0 -v
# Schemathesis also has a CLI:
# schemathesis run [reference URL] --checks all
Boundary Value Fuzzing
python
# Systematic boundary value generation for API parameters
BOUNDARY_STRINGS = [
    '',                          # Empty
    ' ',                         # Whitespace
    '   \t\n\r  ',             # Mixed whitespace
    'a' * 1,                    # Minimum length
    'a' * 255,                  # Common VARCHAR limit
    'a' * 256,                  # One past VARCHAR limit
    'a' * 65536,                # Large string
    '\x00',                     # Null byte
    '\x00abc\x00',              # Embedded null bytes
    'null',                     # Literal "null"
    'undefined',                # Literal "undefined"
    'true',                     # Boolean-like string
    '0',                        # Numeric string
    '-1',                       # Negative numeric string
    '1.7976931348623157e+308',  # Max float as string
    '<script>alert(1)</script>',# XSS payload
    "'; DROP TABLE users; --",  # SQL injection
    '{{7*7}}',                  # Template injection
    '../../../etc/passwd',      # Path traversal
    '[reference URL]',          # URL in text field
]

BOUNDARY_INTEGERS = [
    0, -1, 1,
    -2147483648, 2147483647,     # int32 boundaries
    -2147483649, 2147483648,     # Just past int32
    -9223372036854775808,        # int64 min
    9223372036854775807,         # int64 max
]

BOUNDARY_NUMBERS = [
    0.0, -0.0,
    0.1 + 0.2,                   # Floating point precision
    float('inf'), float('-inf'),
    float('nan'),
    1e-308,                       # Smallest positive float
    1.7976931348623157e+308,      # Largest float
]

def fuzz_endpoint(client, method, path, field_name, values):
    """Test an endpoint with a list of boundary values for a specific field."""
    results = []
    for value in values:
        body = {field_name: value}
        response = getattr(client, method)(path, json=body)
        results.append({
            'input': repr(value),
            'status': response.status_code,
            'body': response.text[:200],
        })
        # No endpoint should return 500 for any input
        assert response.status_code < 500, (
            f"500 error with {field_name}={repr(value)}: {response.text[:500]}"
        )
    return results

Mutation Testing

Concept
Mutation testing answers: "How good are my tests, really?"

Process:
  1. Take your passing test suite
  2. Make a small change (mutation) to your source code
  3. Run the test suite against the mutated code
  4. If tests still pass → SURVIVED MUTANT (tests missed this case)
  5. If tests fail → KILLED MUTANT (tests caught this case)

Mutation score = killed mutants / total mutants * 100%
  > 80%: Good test suite
  > 90%: Excellent test suite
  < 60%: Tests have significant gaps

Common mutation operators:
  - Arithmetic: + → -, * → /
  - Comparison: > → >=, == → !=
  - Boolean: true → false, && → ||
  - Return values: return x → return 0, return null
  - Remove statements: delete a line of code
  - Boundary: x > 0 → x >= 0
Stryker (JavaScript/TypeScript)
shell
# Install: install via npm: --save-dev @stryker-mutator/core @stryker-mutator/jest-runner
# Run: npx stryker run

# stryker.conf.json key settings:
# mutate: ["src/**/*.ts", "!src/**/*.test.ts"]
# thresholds: { high: 80, low: 60, break: 50 }
mutmut (Python)
shell
# Install and run
install via pip: mutmut
mutmut run --paths-to-mutate=src/ --tests-dir=tests/
mutmut results        # View surviving mutants
mutmut html           # Generate HTML report
Writing Mutation-Resistant Tests
To kill mutations, tests must verify:
  - Boundary conditions: f(100) != f(101) when threshold is 100
  - Operator correctness: both > and >= cases covered
  - Return value exactness: assert exact values, not just truthiness
  - Branch coverage: every if/else path has a test with distinct output
  - Negation: test both the positive and negative case of each condition

Edge Case Generation Strategies

Systematic Edge Case Categories
Category          | Values to Test
------------------|--------------------------------------------------
Empty/null        | null, undefined, "", [], {}, 0
Type confusion    | "123" vs 123, "true" vs true, "null" vs null
Boundaries        | min-1, min, min+1, max-1, max, max+1
Unicode           | Emoji, RTL text, combining characters, zero-width
Encoding          | UTF-8, Latin-1, URL-encoded, HTML entities
Time              | Leap years, DST transitions, year 2038, timezones
Precision         | 0.1+0.2, very large numbers, very small decimals
Collections       | Empty, single item, duplicate items, max size
Concurrency       | Simultaneous identical requests, race conditions
State             | Expired tokens, deleted references, stale data
Concurrency Fuzzing
python
import asyncio
import aiohttp
from hypothesis import given, strategies as st

async def concurrent_requests(url, payloads, concurrency=50):
    """Fire many requests simultaneously to find race conditions."""
    async with aiohttp.ClientSession() as session:
        tasks = [session.post(url, json=p) for p in payloads]
        responses = await asyncio.gather(*tasks, return_exceptions=True)
        return responses

@given(st.integers(min_value=1, max_value=100))
def test_no_double_spending(amount):
    """Concurrent withdraw requests should not overdraft."""
    # Create account with known balance
    account = create_account(balance=100)

    # Send identical withdraw requests concurrently
    payloads = [{'account_id': account['id'], 'amount': amount}] * 10
    responses = asyncio.run(
        concurrent_requests('/api/withdraw', payloads)
    )

    successes = sum(1 for r in responses if r.status == 200)
    final_balance = get_balance(account['id'])

    # Property: balance should never go negative
    assert final_balance >= 0
    # Property: total withdrawn should not exceed original balance
    assert successes * amount <= 100

Fuzzing Strategy Checklist

Property-Based Testing:
[ ] Core business logic has property tests (invariants, round-trips)
[ ] Custom strategies defined for domain objects
[ ] Stateful tests for multi-step workflows (state machines)
[ ] Edge cases explicitly included alongside random generation
[ ] Shrinking produces minimal failing examples for debugging

API Fuzzing:
[ ] Schema-driven fuzzing against OpenAPI/GraphQL schema
[ ] Boundary values tested for all input fields
[ ] No endpoint returns 500 for any valid-schema input
[ ] Security-relevant payloads included (injection, XSS, traversal)
[ ] Concurrent request fuzzing for race conditions

Mutation Testing:
[ ] Mutation score measured and tracked over time
[ ] Surviving mutants reviewed and tests added for gaps
[ ] Mutation testing runs in CI (at least weekly)
[ ] Threshold set: PR fails if mutation score drops below baseline

Integration:
[ ] Fuzz tests run in CI pipeline
[ ] Failures are reproducible (seeded random generation)
[ ] Test database is reset between fuzz runs
[ ] Results tracked over time to detect test quality regression

When to Use

Use this skill when:

  • Designing or implementing api fuzzer solutions
  • Reviewing or improving existing api fuzzer approaches
  • Making architectural or implementation decisions about api fuzzer
  • Learning api fuzzer patterns and best practices
  • Troubleshooting api fuzzer-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Api Fuzzer Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement api fuzzer for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended api fuzzer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When api fuzzer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/testing-quality/api-fuzzer of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

API Fuzzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Fuzzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Fuzzer this skillFerroxLabs/wayland608—~4.8kAutomated safety check: PassApache-2.0
Fuzzing Harness Designtrailofbits/skills7.4k1 repos~5.3kAutomated safety check: PassCC-BY-SA-4.0
cargo-fuzz Rust Fuzzingtrailofbits/skills7.4k—~2.9kAutomated safety check: PassCC-BY-SA-4.0
Property Based Testingtrailofbits/skills7.4k—~1.1kAutomated safety check: PassCC-BY-SA-4.0
Directed Test Input GeneratorArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0
Kernel Testingmohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT

Similar skills

  • Fuzzing Harness Design

    trailofbits/skills

    Official

    Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

    7.4k GitHub starsUsed in 1 repo~5.3k tokens
    SecurityAuto-check passed
  • cargo-fuzz Rust Fuzzing

    trailofbits/skills

    Official

    Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes.

    7.4k GitHub stars~2.9k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Property Based Testing

    trailofbits/skills

    Official

    Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.

    7.4k GitHub stars~1.1k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Directed Test Input Generator

    ArabelaTso/Skills-4-SE

    Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

    253 GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Kernel Testing

    mohitmishra786/low-level-dev-skills

    Linux kernel testing skill for KUnit, kselftest, syzkaller, and LTP.

    253 GitHub stars~1.4k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Questions about API Fuzzer

What does API Fuzzer do?

API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and…. API Fuzzer is an agent skill from FerroxLabs/wayland. API fuzz testing expert covering property-based testing with Hypothesis and fast-check, fuzz testing strategies for REST and GraphQL APIs, edge case generation, mutation testing with Stryker and mutmut, boundary value analysis, schema-driven fuzzing, and automated discovery of bugs through randomized inputs.

When should I use API Fuzzer?

API Fuzzer fits situations like: the user asks about api fuzzer; api fuzzer best practices; needs guidance on api fuzzer implementation; the user needs a different specialized skill.

How do I install API Fuzzer in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill api-fuzzer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/testing-quality/api-fuzzer in FerroxLabs/wayland) into .claude/skills/api-fuzzer in your project. Claude Code loads it when a task matches its description.

How do I install API Fuzzer in Codex?

Run `npx skills add FerroxLabs/wayland --skill api-fuzzer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/testing-quality/api-fuzzer in FerroxLabs/wayland) into .agents/skills/api-fuzzer in your project. Codex loads it when a task matches its description.

Can I use API Fuzzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill api-fuzzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-fuzzer, .gemini/skills/api-fuzzer, .github/skills/api-fuzzer and .opencode/skills/api-fuzzer in your project.

What does API Fuzzer need to run?

SKILL.md names no scripts, command-line tools or credentials: API Fuzzer is instructions for the agent only. Our summary lists: Python 3.

Does API Fuzzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Fuzzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Fuzzer use?

API Fuzzer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Fuzzer use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Fuzzer?

Skills that share tags, products or a category with API Fuzzer: Fuzzing Harness Design (trailofbits/skills, 7.4k stars), cargo-fuzz Rust Fuzzing (trailofbits/skills, 7.4k stars), Property Based Testing (trailofbits/skills, 7.4k stars) and Directed Test Input Generator (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Fuzzer?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.