Agent skill

Fuzzing

by nwjs in nwjs/chromium.src

Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.

BSD-3-ClauseAuto-check passedSecurity

Install Fuzzing

skills CLI
$ npx skills add nwjs/chromium.src --skill fuzzing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nwjs/chromium.src fuzzing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/fuzzing .claude/skills/fuzzing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fuzzing
GitHub stars
160
Token cost
~1.1k tokens
SKILL.md length
264 words
Files
2
Skills in repo
64
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.

  • The user asks to add
  • SKILL.md covers 1. Setup, Resources and Common Issues & Fixes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Write fuzzers in C++

What it does

Fuzzing is an agent skill from nwjs/chromium.src. Implements, registers, and verifies fuzz tests in Chromium. Use when the user asks to add or write fuzzers in C++, or mentions fuzz testing or FUZZTEST.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Security, covering Fuzzing. It works with C++. The repository describes itself as: Chromium codebase with NW.js modifications. Based on https://chromium.googlesource.com/chromium/src.git. The licence is BSD-3-Clause.

When your agent uses it

  • The user asks to add
  • Write fuzzers in C++
  • Mentions fuzz testing

Example prompts

  • “/fuzzing”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit a9e8946. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, cpp, gn and python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fuzzing loads about 1.1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 264 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nwjs/chromium.src at commit a9e8946, republished under its BSD-3-Clause licence (© nwjs). 264 words, ~1,101 tokens.

Download SKILL.mdSave it as .claude/skills/fuzzing/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
fuzzing
description
Implements, registers, and verifies fuzz tests in Chromium. Use when the user asks to add or write fuzzers in C++, or mentions fuzz testing or FUZZ_TEST.

Fuzzing (Chromium)

1. Setup

Ensure the output directory is configured:

bash
gn gen out/fuzz --args='enable_fuzztest_fuzz=true is_debug=false is_asan=true \
is_component_build=false use_remoteexec=true'
2. Implement the FUZZ_TEST

Add to *_unittest.cc alongside existing tests:

cpp
#include "third_party/fuzztest/src/fuzztest/fuzztest.h"
#include "third_party/googletest/src/googletest/include/gtest/gtest.h"

// 1. Define the property function. Use a descriptive name that reflects
// the property being tested (e.g., "ParseFooDoesNotCrash" or "RoundTripIsLossless").
void MyPropertyFunctionDoesNotCrash(int i, const std::string& s) {
  // Call code under test. Focus on functions parsing untrusted input, complex
  // state machines, or data processing.
  bool result = MyComponent::DoSomething(i, s);
  // Add test assertions about invariants (e.g. "roundtrip equality", "valid
  // output structure"). Sanitizers like ASAN catch crashes.
  EXPECT_TRUE(result);
}

// 2. Register with FUZZ_TEST macro
FUZZ_TEST(MyComponentFuzzTest, MyPropertyFunctionDoesNotCrash)
  .WithDomains(
      fuzztest::InRange(0, 100),
      fuzztest::Arbitrary<std::string>()
  );

For complex types:

  • Construct from primitives: If the object has a parsing constructor (e.g. GURL(string)), accept the primitive and construct it inside your test function.
  • Define a local domain: Use fuzztest::Constructor or fuzztest::Map to build valid objects.
    cpp
    auto ArbitraryFoo() {
      return fuzztest::Constructor<Foo>(fuzztest::InRange(0, 10));
    }
3. Register in BUILD.gn

You MUST register the test in the fuzztests list (in alphabetical order) of the executable test target.

Case A: File is in a test() target

gn
test("my_component_unittests") {
  sources = [ "my_component_unittest.cc" ]

  # Format: SuiteName.TestName
  fuzztests = [
    "MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash",
  ]

  # No dependency changes are needed here. The build system
  # automatically adds FuzzTest dependencies for targets
  # with a `fuzztests` list.

}

Case B: File is in a source_set(): Add //third_party/fuzztest:fuzztest to deps.

gn
source_set("tests") {
  sources = [ "my_component_unittest.cc" ]
  deps = [
    "//third_party/fuzztest:fuzztest",
    # ...
  ]
}

Find the executable test() target that depends on this source_set(): gn refs out/fuzz //path/to:source_set --testonly=true --type=executable --all

Then, ensure it lists the fuzz test in its fuzztests variable (in alphabetical order).

4. Mandatory verification workflow

The task is incomplete until you successfully execute this sequence:

  1. Find the target and Build

Find the executable test() target that contains your test file:

bash
gn refs out/fuzz //path/to/my_component_unittest.cc --type=executable --all

Build the identified target (e.g. unit_tests or browser_tests):

bash
autoninja --quiet -C out/fuzz <target_name>

Note: If the build fails with an include not allowed by DEPS error, see the Common Issues & Fixes section below.

  1. Verify unit tests pass
bash
./out/fuzz/<target_name> \
--gtest_filter="MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash"
  1. Verify fuzzing mode doesn't crash
bash
./out/fuzz/<target_name> \
--fuzz="MyComponentFuzzTest.MyPropertyFunctionDoesNotCrash" --fuzz_for=10s

Resources

  • Chromium Guide: testing/libfuzzer/getting_started.md
  • Macro Usage: third_party/fuzztest/src/doc/fuzz-test-macro.md
  • Domains: third_party/fuzztest/src/doc/domains-reference.md
  • Fixtures: third_party/fuzztest/src/doc/fixtures.md

Common Issues & Fixes

Build failure: include not allowed by DEPS

Symptom: Build fails with an error like: ERROR: include not allowed by DEPS: third_party/fuzztest/...

Fix: You must allow the fuzztest include in the nearest DEPS file (usually in the same directory as your test or a parent directory). Add +third_party/fuzztest to specific_include_rules for your test files:

python
specific_include_rules = {
  ".*_unittest\\.cc": [
    "+third_party/fuzztest",
  ],
}

© nwjs, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in agents/skills/fuzzing of nwjs/chromium.src.

  • SKILL.md
  • OWNERS

Open the folder on GitHubat commit a9e8946

Compare with similar skills

Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fuzzing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fuzzing this skillnwjs/chromium.src160—~1.1kAutomated safety check: PassBSD-3-Clause
Harness Design Fuzzingprovos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0
ClusterfuzzliteInternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clause
Fuzzing Harness Designtrailofbits/skills7.4k1 repos~5.3kAutomated safety check: PassCC-BY-SA-4.0
Fuzzing Obstacle Patchertrailofbits/skills7.4k—~4kAutomated safety check: PassCC-BY-SA-4.0
Aflpptrailofbits/skills7.4k—~5.6kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Fuzzing Harness Design

    trailofbits/skills

    Official

    Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code.

    7.4k GitHub starsUsed in 1 repo~5.3k tokens
    SecurityAuto-check passed
  • Fuzzing Obstacle Patcher

    trailofbits/skills

    Official

    Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact.

    7.4k GitHub stars~4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Aflpp

    trailofbits/skills

    Official

    Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.

    7.4k GitHub stars~5.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Libfuzzer

    trailofbits/skills

    Official

    Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.

    7.4k GitHub stars~6.1k tokensUpdated yesterday
    SecurityAuto-check passed

More from nwjs/chromium.src

All 64 skills in this repo
  • Analyzing SQL Traces

    nwjs/chromium.src

    Extracts raw trace data from Perfetto traces, runs arbitrary SQL queries for custom follow-up analysis, and applies expert cognitive principles (Tiered Flow Analysis, Semantic Mismatch, Redundancy)…

    160 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Autonomous multi-agent performance optimization loop for Chromium and V8.

    160 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Automated Tracing

    nwjs/chromium.src

    Automated Tracing & Performance Telemetry in Chromium using Perfetto and Telemetry benchmarks.

    160 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed
  • Chrome Releases

    nwjs/chromium.src

    Queries Chrome commit, version, release, and milestone metadata.

    160 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Chromium Docs

    nwjs/chromium.src

    Search and reference Chromium documentation from the local docs index, including design docs, APIs, and development guides.

    160 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Gn Deps Debugging

    nwjs/chromium.src

    Diagnose Chromium GN dependency and include-visibility failures, including BUILD.gn deps/publicdeps, DEPS include rules, private headers, and circular dependencies.

    160 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Fuzzing

What does Fuzzing do?

Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src. src. Implements, registers, and verifies fuzz tests in Chromium.

When should I use Fuzzing?

Fuzzing fits situations like: the user asks to add; write fuzzers in C++; mentions fuzz testing.

How do I install Fuzzing in Claude Code?

Run `npx skills add nwjs/chromium.src --skill fuzzing -a claude-code`. Or copy the skill folder (agents/skills/fuzzing in nwjs/chromium.src) into .claude/skills/fuzzing in your project. Claude Code loads it when a task matches its description.

How do I install Fuzzing in Codex?

Run `npx skills add nwjs/chromium.src --skill fuzzing -a codex`. Or copy the skill folder (agents/skills/fuzzing in nwjs/chromium.src) into .agents/skills/fuzzing in your project. Codex loads it when a task matches its description.

Can I use Fuzzing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nwjs/chromium.src --skill fuzzing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzzing, .gemini/skills/fuzzing, .github/skills/fuzzing and .opencode/skills/fuzzing in your project.

What does Fuzzing need to run?

SKILL.md names no scripts, command-line tools or credentials: Fuzzing is instructions for the agent only. Our summary lists: Python 3.

Does Fuzzing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fuzzing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fuzzing use?

Fuzzing is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fuzzing use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fuzzing?

Skills that share tags, products or a category with Fuzzing: Harness Design Fuzzing (provos/ironcurtain, 613 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars), Fuzzing Harness Design (trailofbits/skills, 7.4k stars) and Fuzzing Obstacle Patcher (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fuzzing?

nwjs (a GitHub organization) maintains it in nwjs/chromium.src, which has 160 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 3, 2026.

Source: nwjs/chromium.src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.