Harness Design Fuzzing
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.
$ npx skills add nwjs/chromium.src --skill fuzzing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nwjs/chromium.src fuzzing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/fuzzing .claude/skills/fuzzing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .claude/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nwjs/chromium.src --skill fuzzing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nwjs/chromium.src fuzzing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/fuzzing .agents/skills/fuzzing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .agents/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill fuzzing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nwjs/chromium.src fuzzing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/fuzzing .cursor/skills/fuzzing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .cursor/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nwjs/chromium.src.git --path agents/skills/fuzzing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nwjs/chromium.src --skill fuzzing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nwjs/chromium.src fuzzing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/fuzzing .gemini/skills/fuzzing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .gemini/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nwjs/chromium.src fuzzingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nwjs/chromium.src --skill fuzzing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/fuzzing .github/skills/fuzzing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .github/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill fuzzing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nwjs/chromium.src fuzzing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/fuzzing .opencode/skills/fuzzing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fuzzing" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/fuzzing into .opencode/skills/fuzzing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzzing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fuzzingImplements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.
Fuzzing is an agent skill from nwjs/chromium.src. Implements, registers, and verifies fuzz tests in Chromium. Use when the user asks to add or write fuzzers in C++, or mentions fuzz testing or FUZZTEST.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Security, covering Fuzzing. It works with C++. The repository describes itself as: Chromium codebase with NW.js modifications. Based on https://chromium.googlesource.com/chromium/src.git. The licence is BSD-3-Clause.
Read from SKILL.md and the folder at commit a9e8946. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, cpp, gn and python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fuzzing loads about 1.1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 264 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nwjs/chromium.src at commit a9e8946, republished under its BSD-3-Clause licence (© nwjs). 264 words, ~1,101 tokens.
.claude/skills/fuzzing/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Ensure the output directory is configured:
gn gen out/fuzz --args='enable_fuzztest_fuzz=true is_debug=false is_asan=true \
is_component_build=false use_remoteexec=true'Add to *_unittest.cc alongside existing tests:
#include "third_party/fuzztest/src/fuzztest/fuzztest.h"
#include "third_party/googletest/src/googletest/include/gtest/gtest.h"
// 1. Define the property function. Use a descriptive name that reflects
// the property being tested (e.g., "ParseFooDoesNotCrash" or "RoundTripIsLossless").
void MyPropertyFunctionDoesNotCrash(int i, const std::string& s) {
// Call code under test. Focus on functions parsing untrusted input, complex
// state machines, or data processing.
bool result = MyComponent::DoSomething(i, s);
// Add test assertions about invariants (e.g. "roundtrip equality", "valid
// output structure"). Sanitizers like ASAN catch crashes.
EXPECT_TRUE(result);
}
// 2. Register with FUZZ_TEST macro
FUZZ_TEST(MyComponentFuzzTest, MyPropertyFunctionDoesNotCrash)
.WithDomains(
fuzztest::InRange(0, 100),
fuzztest::Arbitrary<std::string>()
);For complex types:
GURL(string)), accept the primitive and construct it inside your test
function.fuzztest::Constructor or fuzztest::Map to
build valid objects.auto ArbitraryFoo() {
return fuzztest::Constructor<Foo>(fuzztest::InRange(0, 10));
}You MUST register the test in the fuzztests list (in alphabetical order)
of the executable test target.
Case A: File is in a test() target
test("my_component_unittests") {
sources = [ "my_component_unittest.cc" ]
# Format: SuiteName.TestName
fuzztests = [
"MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash",
]
# No dependency changes are needed here. The build system
# automatically adds FuzzTest dependencies for targets
# with a `fuzztests` list.
}Case B: File is in a source_set(): Add //third_party/fuzztest:fuzztest
to deps.
source_set("tests") {
sources = [ "my_component_unittest.cc" ]
deps = [
"//third_party/fuzztest:fuzztest",
# ...
]
}Find the executable test() target that depends on this source_set():
gn refs out/fuzz //path/to:source_set --testonly=true --type=executable --all
Then, ensure it lists the fuzz test in its fuzztests variable (in alphabetical
order).
The task is incomplete until you successfully execute this sequence:
Find the executable test() target that contains your test file:
gn refs out/fuzz //path/to/my_component_unittest.cc --type=executable --allBuild the identified target (e.g. unit_tests or browser_tests):
autoninja --quiet -C out/fuzz <target_name>Note: If the build fails with an include not allowed by DEPS error, see the
Common Issues & Fixes section below.
./out/fuzz/<target_name> \
--gtest_filter="MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash"./out/fuzz/<target_name> \
--fuzz="MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash" --fuzz_for=10stesting/libfuzzer/getting_started.mdthird_party/fuzztest/src/doc/fuzz-test-macro.mdthird_party/fuzztest/src/doc/domains-reference.mdthird_party/fuzztest/src/doc/fixtures.mdSymptom: Build fails with an error like:
ERROR: include not allowed by DEPS: third_party/fuzztest/...
Fix: You must allow the fuzztest include in the nearest DEPS file
(usually in the same directory as your test or a parent directory). Add
+third_party/fuzztest to specific_include_rules for your test files:
specific_include_rules = {
".*_unittest\\.cc": [
"+third_party/fuzztest",
],
}© nwjs, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in agents/skills/fuzzing of nwjs/chromium.src.
Open the folder on GitHubat commit a9e8946
Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fuzzing this skillnwjs/chromium.src | 160 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause | |
| Harness Design Fuzzingprovos/ironcurtain | 613 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | |
| ClusterfuzzliteInternationalColorConsortium/iccDEV | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | |
| Fuzzing Harness Designtrailofbits/skills | 7.4k | 1 repos | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Fuzzing Obstacle Patchertrailofbits/skills | 7.4k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Aflpptrailofbits/skills | 7.4k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 |
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
InternationalColorConsortium/iccDEV
Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.
trailofbits/skills
Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.
trailofbits/skills
Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.
trailofbits/skills
Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.
trailofbits/skills
Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.
nwjs/chromium.src
Extracts raw trace data from Perfetto traces, runs arbitrary SQL queries for custom follow-up analysis, and applies expert cognitive principles (Tiered Flow Analysis, Semantic Mismatch, Redundancy)…
nwjs/chromium.src
Autonomous multi-agent performance optimization loop for Chromium and V8.
nwjs/chromium.src
Automated Tracing & Performance Telemetry in Chromium using Perfetto and Telemetry benchmarks.
nwjs/chromium.src
Queries Chrome commit, version, release, and milestone metadata.
nwjs/chromium.src
Search and reference Chromium documentation from the local docs index, including design docs, APIs, and development guides.
nwjs/chromium.src
Diagnose Chromium GN dependency and include-visibility failures, including BUILD.gn deps/publicdeps, DEPS include rules, private headers, and circular dependencies.
Works with
Categories
Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src. src. Implements, registers, and verifies fuzz tests in Chromium.
Fuzzing fits situations like: the user asks to add; write fuzzers in C++; mentions fuzz testing.
Run `npx skills add nwjs/chromium.src --skill fuzzing -a claude-code`. Or copy the skill folder (agents/skills/fuzzing in nwjs/chromium.src) into .claude/skills/fuzzing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nwjs/chromium.src --skill fuzzing -a codex`. Or copy the skill folder (agents/skills/fuzzing in nwjs/chromium.src) into .agents/skills/fuzzing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nwjs/chromium.src --skill fuzzing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzzing, .gemini/skills/fuzzing, .github/skills/fuzzing and .opencode/skills/fuzzing in your project.
SKILL.md names no scripts, command-line tools or credentials: Fuzzing is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fuzzing is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fuzzing: Harness Design Fuzzing (provos/ironcurtain, 613 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars), Fuzzing Harness Design (trailofbits/skills, 7.4k stars) and Fuzzing Obstacle Patcher (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nwjs (a GitHub organization) maintains it in nwjs/chromium.src, which has 160 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 3, 2026.
Source: nwjs/chromium.src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.