Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

BSD-3-ClauseAuto-check passedSecurity

Install Clusterfuzzlite

skills CLI
$ npx skills add InternationalColorConsortium/iccDEV --skill clusterfuzzlite -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install InternationalColorConsortium/iccDEV clusterfuzzlite --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/InternationalColorConsortium/iccDEV.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/clusterfuzzlite .claude/skills/clusterfuzzlite && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clusterfuzzlite
GitHub stars
183
Token cost
~1.5k tokens
SKILL.md length
601 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

  • Tasks that involve Fuzzing
  • SKILL.md covers Contract, Expansion Order and Local Validation
  • Calls python3, git and bash

What it does

Clusterfuzzlite is an agent skill from InternationalColorConsortium/iccDEV. Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. It works with C++ and GitHub. The repository describes itself as: iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. The licence is BSD-3-Clause.

When your agent uses it

  • Tasks that involve Fuzzing

Example prompts

  • “/clusterfuzzlite”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit baabe0e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git
    • bash
    • actionlint

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clusterfuzzlite loads about 1.5k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 601 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from InternationalColorConsortium/iccDEV at commit baabe0e, republished under its BSD-3-Clause licence (© InternationalColorConsortium). 601 words, ~1,501 tokens.

Download SKILL.mdSave it as .claude/skills/clusterfuzzlite/SKILL.md (or your agent's skills folder).
name
clusterfuzzlite
description
Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

ClusterFuzzLite Integration

Use this skill for .clusterfuzzlite/**, .github/workflows/ci-clusterfuzzlite.yml, or the ClusterFuzzLite mode in .github/ci/cfl/build.sh.

Contract

  • Treat libFuzzer as the single fuzzing engine and address, undefined, and memory as three separate sanitizer builds.
  • Build all three in-process groups in ClusterFuzzLite: core (profileparse, cmmapply, profilevisualize, writerserialize), formats (xmlparse, jsonparse, connectconfig), and assessment (pawgreport).
  • Forward the GitHub matrix group and patch mode through CFL_EXTRA_*; the official action builds a fresh GITHUB_SHA clone, so pre-step checkout file mutations do not reach the builder container.
  • Forward and independently recompute the deterministic source-content digest. Reject a builder snapshot that differs from the Actions checkout; the official action may otherwise fall back to its current clone when a queued commit becomes unreachable after a history rewrite.
  • Keep the CLI-fidelity wrappers in the local CFL smoke lane; they launch child tools and do not provide useful parent-process coverage feedback.
  • Consume CC, CXX, CFLAGS, CXXFLAGS, and LIB_FUZZING_ENGINE from the OSS-Fuzz build environment. Do not combine hard-coded ASan flags with MSan.
  • Require matching Clang 21 or Clang 22 compilers. The pinned OSS-Fuzz builder supplies Clang 22; do not allow an older fallback.
  • Keep tools and zlib disabled. Enable XML/JSON only for targets that consume those libraries. The XML memory build must use the pinned instrumented libxml2 produced by the repository bootstrap.
  • For memory, build the pinned MSan libc++ and libc++abi before compiling the fuzzers. Reject libstdc++ or a libc++ outside that runtime in ldd; for xmlparse, also reject libxml2 outside the bundled runtime. Replay the pinned #2687 artifact through every emitted target. Do not classify a dependency report from an uninstrumented runtime as iccDEV.
  • Package tracked ICC, XML, and JSON fixtures only for the matching target family. Keep the shared profile/text options and profile/XML/JSON dictionaries aligned with explicit local CFL limits.
  • Keep cmmapply control bytes outside the ICC header so direction, intent, and interpolation can mutate without corrupting the profile-size field.
  • Keep a schema-shaped IccConnect seed and dedicated config dictionary. Drive fromJson()/toJson() round trips for top-level and nested CIccCfg* objects before adding another configuration target.
  • Keep the workflow limited to manual dispatch and the nightly schedule. Manual dispatch defaults to one address/core smoke job; run_mode=full and the schedule use all nine group/sanitizer combinations.
  • Keep the manual fuzz duration selectable as whole minutes from 2 through 45, validate it before the sanitizer matrix, pass it as the budget for each target group, and retain a 2-minute per-group budget for scheduled runs.
  • Keep corpus pruning runnable after a fuzz finding. Keep coverage an explicit manual option that emits a ClusterFuzzLite artifact without broadening repository permissions.
  • Keep one temporary CFL patch per open MSan issue. Attempt patches in order, report drift or already-integrated fixes, and continue the default workflow; reserve --strict for local patch-stack maintenance. Remove only the patch for an issue whose normal source fix has landed.
  • Pin every action to a full commit SHA and the builder image to a digest.
Show full SKILL.md (121 more words)Show less

Expansion Order

After strengthening an existing target, prefer a multi-profile CMM chain, separate XML/JSON serializers, and V5 display-observer conversion, in that order. Add image or carrier targets only with instrumented MSan dependencies. Do not copy the local research inventory wholesale; require a public in-process seam, structured seed, and distinct attribution boundary.

Local Validation

From an OSS-Fuzz checkout, run for each sanitizer in address, undefined, and memory:

bash
iccdev_source=/path/to/iccDEV
source_sha="$(git -C "$iccdev_source" rev-parse HEAD)"
source_digest="$("$iccdev_source/.github/scripts/iccdev-cfl-source-digest.sh" "$iccdev_source")"
python3 infra/helper.py build_image --external --pull "$iccdev_source"
python3 infra/helper.py build_fuzzers --external --clean \
  -e "ICCDEV_CFL_SOURCE_SHA=$source_sha" \
  -e "ICCDEV_CFL_SOURCE_DIGEST=$source_digest" \
  --engine libfuzzer --sanitizer SANITIZER "$iccdev_source"
python3 infra/helper.py check_build --external \
  --engine libfuzzer --sanitizer SANITIZER "$iccdev_source"
for target in profileparse cmmapply profilevisualize writerserialize \
  xmlparse jsonparse connectconfig pawgreport; do
  python3 infra/helper.py run_fuzzer --external \
    --engine libfuzzer --sanitizer SANITIZER \
    "$iccdev_source" "icc_${target}_fuzzer" -- -max_total_time=30
done

Also run:

bash
bash -n .clusterfuzzlite/build.sh .github/ci/cfl/build.sh \
  .github/scripts/iccdev-clusterfuzzlite-config-tests.sh \
  .github/scripts/iccdev-clusterfuzzlite-target-tests.sh
.github/scripts/iccdev-clusterfuzzlite-config-tests.sh
.github/scripts/iccdev-fuzz-patch-check-tests.sh
.github/scripts/check-fuzz-patches.sh
ctest --test-dir Build -R '^iccdev\.clusterfuzzlite-(configuration|targets)$' \
  --output-on-failure --no-tests=error
actionlint -no-color .github/workflows/ci-clusterfuzzlite.yml
.github/scripts/preflight-safety-checks.sh --require-tools

Report each build, instrumentation check, and bounded run separately. An MSan failure is not equivalent to an ASan or UBSan failure and must not be hidden by fallback flags or an allowed-broken-target percentage. Record the resolved C++ runtime for every MSan fuzzer, the XML target's resolved libxml2, and the #2687 one-shot replay result.

© InternationalColorConsortium, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/clusterfuzzlite of InternationalColorConsortium/iccDEV.

Open the folder on GitHubat commit baabe0e

Compare with similar skills

Clusterfuzzlite next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clusterfuzzlite compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clusterfuzzlite this skillInternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clause
Harness Design Fuzzingprovos/ironcurtain612—~5.7kAutomated safety check: PassApache-2.0
Fuzzing Harness Designtrailofbits/skills7.4k1 repos~5.3kAutomated safety check: PassCC-BY-SA-4.0
Web2 Reconawarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT
Fuzzing Obstacle Patchertrailofbits/skills7.4k—~4kAutomated safety check: PassCC-BY-SA-4.0
Aflpptrailofbits/skills7.4k—~5.6kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    612 GitHub stars~5.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Fuzzing Harness Design

    trailofbits/skills

    Official

    Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

    7.4k GitHub starsUsed in 1 repo~5.3k tokens
    SecurityAuto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    SecurityAuto-check: warnings
  • Fuzzing Obstacle Patcher

    trailofbits/skills

    Official

    Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.

    7.4k GitHub stars~4k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Aflpp

    trailofbits/skills

    Official

    Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

    7.4k GitHub stars~5.6k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Libfuzzer

    trailofbits/skills

    Official

    Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.

    7.4k GitHub stars~6.1k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from InternationalColorConsortium/iccDEV

All 23 skills in this repo
  • Afl Smoke

    InternationalColorConsortium/iccDEV

    Run or update the iccDEV AFL++ manual smoke workflow, seeds, and maintainer documentation.

    183 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Avx2 Clut Diagnostics

    InternationalColorConsortium/iccDEV

    Diagnose runtime-dispatched AVX2 3D CLUT interpolation, collect trace evidence, validate vector and masked-tail output, and prepare optimization handoff data.

    183 GitHub stars~850 tokensUpdated today
    Auto-check passed
  • iOS Clut Editor

    InternationalColorConsortium/iccDEV

    Build, review, and maintain the ios-clut-editor profile and 3D CLUT editing proof-of-concept app without repeating prior iOS review-loop failures.

    183 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • iOS Manual Examples

    InternationalColorConsortium/iccDEV

    Maintain the manual iOS example app CMake projects, local Xcode build helpers, device signing guard rails, and documentation.

    183 GitHub stars~796 tokensUpdated today
    Auto-check passed
  • JSON Config Regression

    InternationalColorConsortium/iccDEV

    Validate iccDEV JSON/profile config parser changes with fail-closed regression gates and CLI exercises.

    183 GitHub stars~469 tokensUpdated today
    Auto-check passed
  • Maintainer CI Ctest

    InternationalColorConsortium/iccDEV

    Maintainer workflow for scoping and updating iccDEV CI, CTest, CPack, sanitizer, workflow, and release-gate infrastructure.

    183 GitHub stars~2.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Clusterfuzzlite

What does Clusterfuzzlite do?

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan. Clusterfuzzlite is an agent skill from InternationalColorConsortium/iccDEV. Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

When should I use Clusterfuzzlite?

Clusterfuzzlite fits situations like: tasks that involve Fuzzing.

How do I install Clusterfuzzlite in Claude Code?

Run `npx skills add InternationalColorConsortium/iccDEV --skill clusterfuzzlite -a claude-code`. Or copy the skill folder (.github/skills/clusterfuzzlite in InternationalColorConsortium/iccDEV) into .claude/skills/clusterfuzzlite in your project. Claude Code loads it when a task matches its description.

How do I install Clusterfuzzlite in Codex?

Run `npx skills add InternationalColorConsortium/iccDEV --skill clusterfuzzlite -a codex`. Or copy the skill folder (.github/skills/clusterfuzzlite in InternationalColorConsortium/iccDEV) into .agents/skills/clusterfuzzlite in your project. Codex loads it when a task matches its description.

Can I use Clusterfuzzlite in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add InternationalColorConsortium/iccDEV --skill clusterfuzzlite -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clusterfuzzlite, .gemini/skills/clusterfuzzlite, .github/skills/clusterfuzzlite and .opencode/skills/clusterfuzzlite in your project.

What does Clusterfuzzlite need to run?

Going by SKILL.md and its folder, Clusterfuzzlite needs the command-line tools its instructions call (python3, git, bash and actionlint). Our summary lists: Python 3.

Does Clusterfuzzlite access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Clusterfuzzlite safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clusterfuzzlite use?

Clusterfuzzlite is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clusterfuzzlite use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clusterfuzzlite?

Skills that share tags, products or a category with Clusterfuzzlite: Harness Design Fuzzing (provos/ironcurtain, 612 stars), Fuzzing Harness Design (trailofbits/skills, 7.4k stars), Web2 Recon (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Fuzzing Obstacle Patcher (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clusterfuzzlite?

InternationalColorConsortium (a GitHub organization) maintains it in InternationalColorConsortium/iccDEV, which has 183 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: InternationalColorConsortium/iccDEV on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.