Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities.

MITAuto-check passedSecurity

Install Fuzzing APIs

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill fuzzing-apis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace fuzzing-apis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/fuzzing-apis .claude/skills/fuzzing-apis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fuzzing-apis
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
541 words
Files
6 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities.

  • Works in 7 steps: Parse the API specification to identify… → Configure the fuzzing strategy → Define fuzz input categories for each… → …
  • Performing specialized testing
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; needs TEST_TOKEN

What it does

Fuzzing APIs is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing. Trigger with phrases like "fuzz the API", "run fuzzing tests", or "discover edge cases".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/report_template.md` and `references/README.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Fuzzing. It works with OpenAPI. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Performing specialized testing
  • With phrases like fuzz the API
  • Run fuzzing tests
  • Discover edge cases

Example prompts

  • “fuzz the API”
  • “run fuzzing tests”
  • “discover edge cases”
  • “/fuzzing-apis”

Requirements

  • Python 3
  • A credential in TEST_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(test:fuzz-*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Parse the API specification to identify all endpoints, methods, and input schemas
  2. Configure the fuzzing strategy
  3. Define fuzz input categories for each parameter type
  4. Execute the fuzzing campaign
  5. Analyze findings
  6. For each finding, create a minimal reproducer (smallest input that triggers the issue).
  7. Write regression tests for confirmed bugs to prevent reintroduction.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(test:fuzz-*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • schemathesis.readthedocs.io
    • github.com
    • fast-check.dev
    • hypothesis.readthedocs.io
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TEST_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Fuzzing APIs loads about 1.6k tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 541 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 541 words, ~1,611 tokens.

Download SKILL.mdSave it as .claude/skills/fuzzing-apis/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
fuzzing-apis
description
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing. Trigger with phrases like "fuzz the API", "run fuzzing tests", or "discover edge cases".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(test:fuzz-*)
compatibility
Designed for Claude Code
version
1.25.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
testing, api, security

API Fuzzer

Overview

Perform API fuzzing to discover crashes, unhandled exceptions, security vulnerabilities, and edge case failures by sending malformed, unexpected, and boundary-value inputs to API endpoints. Supports RESTler (stateful REST API fuzzing), Schemathesis (OpenAPI-driven property-based testing), custom fuzz harnesses with fast-check, and OWASP ZAP active scanning.

Prerequisites

  • API specification available (OpenAPI/Swagger, GraphQL SDL, or Protobuf definitions)
  • Target API running in a test environment (never fuzz production)
  • Fuzzing tool installed (Schemathesis, RESTler, or custom harness with fast-check/Hypothesis)
  • API authentication credentials for protected endpoints
  • Error logging enabled on the target server to capture crashes and stack traces

Instructions

  1. Parse the API specification to identify all endpoints, methods, and input schemas:
    • Read OpenAPI spec files using Glob (**/openapi.yaml, **/swagger.json).
    • Catalog each endpoint's parameters (path, query, header, body) and their types.
    • Note validation constraints (min/max, pattern, enum, required fields).
  2. Configure the fuzzing strategy:
    • Schema-based: Generate inputs that violate schema constraints (wrong types, missing fields, extra fields).
    • Mutation-based: Start with valid requests and mutate individual fields (bit flips, boundary values, special characters).
    • Dictionary-based: Use known problematic inputs (SQL injection, XSS payloads, format strings, null bytes).
  3. Define fuzz input categories for each parameter type:
    • Strings: Empty, very long (10K+ chars), unicode, null bytes, format strings (%s%n), path traversal (../../etc/passwd).
    • Numbers: 0, -1, MAX_INT, MIN_INT, NaN, Infinity, floats where ints expected.
    • Arrays: Empty, single element, thousands of elements, nested arrays, mixed types.
    • Objects: Empty, missing required fields, extra unknown fields, deeply nested (100+ levels).
    • Dates: Invalid formats, epoch zero, far future, negative timestamps.
  4. Execute the fuzzing campaign:
    • Run Schemathesis: schemathesis run http://localhost:3000/openapi.json --stateful=links.
    • Or run RESTler: restler-fuzzer fuzz --grammar_file grammar.py.
    • Or write custom fuzz tests with fast-check/Hypothesis for targeted endpoints.
    • Set a time budget (30-60 minutes for initial run).
  5. Analyze findings:
    • 5xx responses: Unhandled server errors -- file as bugs.
    • Crashes/hangs: Application process terminated or stopped responding.
    • Resource exhaustion: Memory/CPU spike from malicious payloads.
    • Information disclosure: Stack traces, internal paths, or credentials in error responses.
  6. For each finding, create a minimal reproducer (smallest input that triggers the issue).
  7. Write regression tests for confirmed bugs to prevent reintroduction.
Show full SKILL.md (194 more words)Show less

Output

  • Fuzz campaign report with discovered issues sorted by severity
  • Minimal reproducer for each finding (curl command or test case)
  • Categorized findings: crashes, unhandled errors, security issues, validation gaps
  • Regression test file with one test per confirmed bug
  • Coverage metrics showing which endpoints and parameters were fuzzed

Error Handling

ErrorCauseSolution
Fuzzer cannot parse API specInvalid or incomplete OpenAPI specificationValidate the spec with swagger-cli validate; fix schema errors before fuzzing
All requests return 401Authentication not configured in fuzzerProvide auth headers via --set-header "Authorization: Bearer TOKEN" or config file
Server crashes during fuzzingUnhandled exception or resource exhaustionRestart the server with a process manager; enable crash dump collection; add OOM killer threshold
Too many false positives (500 errors)Application returns 500 for expected validation errorsFilter known error patterns; configure the fuzzer to ignore specific response bodies
Fuzzer generates unrealistic inputsSchema-based generation produces impossible combinationsAdd x-examples to the OpenAPI spec; use stateful fuzzing to maintain valid sequences

Examples

Schemathesis OpenAPI fuzzing:

bash
# Basic schema-based fuzzing
schemathesis run http://localhost:3000/api/openapi.json \  # 3000: 3 seconds in ms
  --stateful=links \
  --hypothesis-max-examples=500 \  # HTTP 500 Internal Server Error
  --base-url=http://localhost:3000 \  # 3 seconds in ms
  --header "Authorization: Bearer $TEST_TOKEN"

# With specific checks
schemathesis run http://localhost:3000/api/openapi.json \  # 3 seconds in ms
  --checks all \
  --validate-schema=true

fast-check property-based API test:

typescript
import fc from 'fast-check';
import request from 'supertest';
import { app } from '../src/app';

test('POST /api/users handles arbitrary input without crashing', async () => {
  await fc.assert(
    fc.asyncProperty(
      fc.record({
        name: fc.string(),
        email: fc.string(),
        age: fc.oneof(fc.integer(), fc.string(), fc.constant(null)),
      }),
      async (body) => {
        const res = await request(app).post('/api/users').send(body);
        expect(res.status).toBeLessThan(500); // No server errors  # HTTP 500 Internal Server Error
      }
    ),
    { numRuns: 200 }  # HTTP 200 OK
  );
});

Custom fuzz dictionary for injection testing:

json
[
  "' OR '1'='1",
  "<script>alert(1)</script>",
  "${7*7}",
  "{{7*7}}",
  "../../../etc/passwd",
  "\u0000",
  "A".repeat(100000)  # 100000 = configured value
]

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/.curated/fuzzing-apis of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/report_template.md
  • references/README.md
  • scripts/README.md
  • scripts/generate_payloads.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Fuzzing APIs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fuzzing APIs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fuzzing APIs this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
703 Technologies Fuzzing Testingjabrena/plinth447—~874Automated safety check: PassApache-2.0
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Mavenskjolber/3d-bin-container-packing569—~886Automated safety check: PassApache-2.0
Harness Design Fuzzingprovos/ironcurtain612—~5.7kAutomated safety check: PassApache-2.0
ClusterfuzzliteInternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clause

Similar skills

  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    447 GitHub stars~874 tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Maven

    skjolber/3d-bin-container-packing

    Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

    569 GitHub stars~886 tokensUpdated today
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    612 GitHub stars~5.7k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Stateful Invariant Testing

    aviggiano/security

    Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects.

    144 GitHub stars~2.8k tokensUpdated 25 days ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Fuzzing APIs

What does Fuzzing APIs do?

Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Fuzzing APIs is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities.

When should I use Fuzzing APIs?

Fuzzing APIs fits situations like: performing specialized testing; with phrases like fuzz the API; run fuzzing tests; discover edge cases.

How do I install Fuzzing APIs in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fuzzing-apis -a claude-code`. Or copy the skill folder (skills/.curated/fuzzing-apis in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/fuzzing-apis in your project. Claude Code loads it when a task matches its description.

How do I install Fuzzing APIs in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fuzzing-apis -a codex`. Or copy the skill folder (skills/.curated/fuzzing-apis in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/fuzzing-apis in your project. Codex loads it when a task matches its description.

Can I use Fuzzing APIs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill fuzzing-apis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzzing-apis, .gemini/skills/fuzzing-apis, .github/skills/fuzzing-apis and .opencode/skills/fuzzing-apis in your project.

What does Fuzzing APIs need to run?

Going by SKILL.md and its folder, Fuzzing APIs needs Python for the scripts in its folder and credentials named TEST_TOKEN. Our summary lists: Python 3; A credential in TEST_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(test:fuzz-*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Fuzzing APIs access the network?

SKILL.md names 5 domains. As links in the text: schemathesis.readthedocs.io, github.com, fast-check.dev, hypothesis.readthedocs.io and owasp.org. This is read from the text; nothing was executed.

Is Fuzzing APIs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Fuzzing APIs use?

Fuzzing APIs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fuzzing APIs use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14 tokens, read only when the agent opens those files.

What are the alternatives to Fuzzing APIs?

Skills that share tags, products or a category with Fuzzing APIs: 703 Technologies Fuzzing Testing (jabrena/plinth, 447 stars), Fizz (pashov/skills, 1.2k stars), Maven (skjolber/3d-bin-container-packing, 569 stars) and Harness Design Fuzzing (provos/ironcurtain, 612 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fuzzing APIs?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.