Agent skill

703 Technologies Fuzzing Testing

by jabrena in jabrena/plinth

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

Apache-2.0Auto-check passedTesting & QA

Install 703 Technologies Fuzzing Testing

skills CLI
$ npx skills add jabrena/plinth --skill 703-technologies-fuzzing-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jabrena/plinth 703-technologies-fuzzing-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/703-technologies-fuzzing-testing .claude/skills/703-technologies-fuzzing-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
703-technologies-fuzzing-testing
GitHub stars
447
Token cost
~874 tokens
SKILL.md length
373 words
Files
4 (incl. scripts, references, assets)
Skills in repo
124
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

  • You need to add
  • SKILL.md covers Constraints, When to use this skill, Workflow and Reference
  • Runs Shell scripts from its folder; calls mvn
  • Review fuzz testing for Java APIs with CATS — including contract-driven negative testing

What it does

703 Technologies Fuzzing Testing is an agent skill from jabrena/plinth. Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests such as Add fuzz testing to a Java project; Use CATS for API negative testing; Review CI quality gates for API contract robustness; Improve boundary and malformed input test coverage; Run CATS fuzz tests against an OpenAPI contract. Part of…

Its SKILL.md is about 870 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets (for example `references/703-technologies-fuzzing-testing.md` and `scripts/run-cats-fuzz.sh`).

It sits in Testing & QA, covering Fuzzing, OpenAPI specifications and API design. It works with Java and OpenAPI. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.

When your agent uses it

  • You need to add
  • Review fuzz testing for Java APIs with CATS — including contract-driven negative testing
  • Malformed payload validation
  • Boundary input exploration

Example prompts

  • “/703-technologies-fuzzing-testing”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

703 Technologies Fuzzing Testing loads about 874 tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~874
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 373 words, ~874 tokens.

Download SKILL.mdSave it as .claude/skills/703-technologies-fuzzing-testing/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
703-technologies-fuzzing-testing
description
Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance. This should trigger for requests such as Add fuzz testing to a Java project; Use CATS for API negative testing; Review CI quality gates for API contract robustness; Improve boundary and malformed input test coverage; Run CATS fuzz tests against an OpenAPI contract. Part of Plinth Toolkit
license
Apache-2.0
metadata.author
Juan Antonio Breña Moral
metadata.version
0.19.0

Java fuzz testing with CATS

Design and implement contract-driven fuzz testing for Java APIs using CATS to uncover edge cases and input-validation defects early.

What is covered in this Skill?

  • CATS setup using a trusted local jar or prebuilt image and baseline command usage for OpenAPI-driven fuzzing
  • Negative testing strategy for invalid payloads, missing fields, wrong types, and malformed values
  • Boundary testing for size, range, format, and enum constraints
  • CI integration patterns with actionable logs and reproducible failures
  • Local execution workflow for contributors before opening pull requests
  • Reporting and triage practices for fuzzing findings

Scope: Focus on HTTP API fuzzing and contract validation with CATS. Use this skill to define practical, repeatable checks in both local and CI workflows.

Constraints

Before applying any fuzz testing changes, ensure the project compiles. If compilation fails, stop immediately. After implementation, regenerate skills and run verification.

  • MANDATORY: Run ./mvnw compile or mvn compile before applying any change
  • SAFETY: If compilation fails, stop immediately and do not proceed
  • VERIFY: Run ./mvnw clean verify or mvn clean verify after applying improvements
  • SUPPLY CHAIN: Use only a verified local cats/cats.jar or an approved prebuilt image; generated artifacts must depend only on trusted local or approved image inputs
  • BEFORE APPLYING: Read the reference for detailed examples, good/bad patterns, and constraints
  • EDGE CASE: If request scope is ambiguous, stop and ask a clarifying question before applying changes
  • EDGE CASE: If required inputs, files, or tooling are missing, report what is missing and ask whether to proceed with setup guidance
Show full SKILL.md (123 more words)Show less

When to use this skill

  • Add fuzz testing to a Java project
  • Use CATS for API negative testing
  • Review CI quality gates for API contract robustness
  • Improve boundary and malformed input test coverage
  • Run CATS fuzz tests against an OpenAPI contract

Workflow

  1. Read reference and assess project context

Read references/703-technologies-fuzzing-testing.md and inspect current API/context artifacts before proposing changes.

  1. Gather scope and decide target improvements

Identify requested outcomes, constraints, and the minimum safe set of changes to apply.

  1. Apply technology-aligned changes

Implement or refactor artifacts following the reference patterns and project conventions.

  1. Run verification and report results

Execute appropriate checks and summarize what changed, what was verified, and any follow-up actions.

Reference

For detailed guidance, examples, and constraints, see references/703-technologies-fuzzing-testing.md.

© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in skills/703-technologies-fuzzing-testing of jabrena/plinth.

  • SKILL.md
  • assets/cats.dockerfile
  • references/703-technologies-fuzzing-testing.md
  • scripts/run-cats-fuzz.sh

Open the folder on GitHubat commit dca88dc

Compare with similar skills

703 Technologies Fuzzing Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

703 Technologies Fuzzing Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
703 Technologies Fuzzing Testing this skilljabrena/plinth447—~874Automated safety check: PassApache-2.0
Mavenskjolber/3d-bin-container-packing569—~886Automated safety check: PassApache-2.0
API Contract Openapimakifbaysal/tasktrooper112—~1.2kAutomated safety check: PassApache-2.0
Analyze API Contract Coveragecyberful/cyberful135—~585Automated safety check: PassAGPL-3.0
API Contract Testingsecondsky/claude-skills227—~977Automated safety check: PassMIT
Jacred Tracker Parserjacred-fdb/jacred126—~1.4kAutomated safety check: PassAGPL-3.0

Similar skills

  • Maven

    skjolber/3d-bin-container-packing

    Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

    569 GitHub stars~886 tokensUpdated today
    SecurityAuto-check passed
  • API Contract Openapi

    makifbaysal/tasktrooper

    A skill your agent uses when you add or change any HTTP endpoint's request or response shape (Go or Java) — implement the task's contract exactly, evolve additively, keep the OpenAPI document in…

    112 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Deterministically compare OpenAPI JSON operations with implementation and observation inventories to expose undocumented, unimplemented, unexercised, and security-declaration coverage gaps.

    135 GitHub stars~585 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • API Contract Testing

    secondsky/claude-skills

    Verifies API contracts between services using consumer-driven contracts, schema validation, and tools like Pact.

    227 GitHub stars~977 tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Jacred Tracker Parser

    jacred-fdb/jacred

    Adds and debugs JacRed torrent/anime tracker parsers (site probe, auth, magnet policy, SyncService, cron, fixtures, dry-run, OpenAPI wiring).

    126 GitHub stars~1.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Automating API Testing

    jeremylongshore/tons-of-skills-marketplace

    Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs.

    2.8k GitHub stars~1.7k tokensUpdated today
    Testing & QAAuto-check passed

More from jabrena/plinth

All 124 skills in this repo
  • A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…

    447 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

    447 GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…

    447 GitHub stars~842 tokensUpdated 2 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…

    447 GitHub stars~903 tokensUpdated 2 days ago
    Auto-check passed
  • A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…

    447 GitHub stars~697 tokensUpdated 2 days ago
    Auto-check passed
  • 002 Agents Inventory

    jabrena/plinth

    A skill your agent uses when you need to generate a checklist document with embedded agents inventory, following the embedded template exactly and producing INVENTORY-AGENTS-JAVA.md in the project…

    447 GitHub stars~675 tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about 703 Technologies Fuzzing Testing

What does 703 Technologies Fuzzing Testing do?

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…. 703 Technologies Fuzzing Testing is an agent skill from jabrena/plinth. Use when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI integration, reproducible failures, and local execution guidance.

When should I use 703 Technologies Fuzzing Testing?

703 Technologies Fuzzing Testing fits situations like: you need to add; review fuzz testing for Java APIs with CATS — including contract-driven negative testing; malformed payload validation; boundary input exploration.

How do I install 703 Technologies Fuzzing Testing in Claude Code?

Run `npx skills add jabrena/plinth --skill 703-technologies-fuzzing-testing -a claude-code`. Or copy the skill folder (skills/703-technologies-fuzzing-testing in jabrena/plinth) into .claude/skills/703-technologies-fuzzing-testing in your project. Claude Code loads it when a task matches its description.

How do I install 703 Technologies Fuzzing Testing in Codex?

Run `npx skills add jabrena/plinth --skill 703-technologies-fuzzing-testing -a codex`. Or copy the skill folder (skills/703-technologies-fuzzing-testing in jabrena/plinth) into .agents/skills/703-technologies-fuzzing-testing in your project. Codex loads it when a task matches its description.

Can I use 703 Technologies Fuzzing Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 703-technologies-fuzzing-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/703-technologies-fuzzing-testing, .gemini/skills/703-technologies-fuzzing-testing, .github/skills/703-technologies-fuzzing-testing and .opencode/skills/703-technologies-fuzzing-testing in your project.

What does 703 Technologies Fuzzing Testing need to run?

Going by SKILL.md and its folder, 703 Technologies Fuzzing Testing needs a shell for the scripts in its folder and the command-line tools its instructions call (mvn). Our summary lists: A Bash shell.

Does 703 Technologies Fuzzing Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 703 Technologies Fuzzing Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does 703 Technologies Fuzzing Testing use?

703 Technologies Fuzzing Testing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 703 Technologies Fuzzing Testing use?

About 874 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to 703 Technologies Fuzzing Testing?

Skills that share tags, products or a category with 703 Technologies Fuzzing Testing: Maven (skjolber/3d-bin-container-packing, 569 stars), API Contract Openapi (makifbaysal/tasktrooper, 112 stars), Analyze API Contract Coverage (cyberful/cyberful, 135 stars) and API Contract Testing (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 703 Technologies Fuzzing Testing?

jabrena (a GitHub user) maintains it in jabrena/plinth, which has 447 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.

Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.