Agent skill

Run Fuzzing Campaign

by opensage-agent in opensage-agent/opensage-adk

Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

Apache-2.0Auto-check passedSecurity

Install Run Fuzzing Campaign

skills CLI
$ npx skills add opensage-agent/opensage-adk --skill run-fuzzing-campaign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install opensage-agent/opensage-adk run-fuzzing-campaign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/opensage/bash_tools/fuzz/run-fuzzing-campaign .claude/skills/run-fuzzing-campaign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
run-fuzzing-campaign
GitHub stars
127
Token cost
~542 tokens
SKILL.md length
153 words
Files
2 (incl. scripts)
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

  • Tasks that involve Fuzzing
  • SKILL.md covers Usage, Parameters, Custom Mutator and Return Value, plus 2 more sections
  • Runs Shell scripts from its folder

What it does

Run Fuzzing Campaign is an agent skill from opensage-agent/opensage-adk. Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/run_fuzzing_campaign.sh`).

It sits in Security, covering Fuzzing. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Fuzzing

Example prompts

  • “/run-fuzzing-campaign”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 54d6470. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Run Fuzzing Campaign loads about 542 tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 153 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~542

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from opensage-agent/opensage-adk at commit 54d6470, republished under its Apache-2.0 licence (© opensage-agent). 153 words, ~542 tokens.

Download SKILL.mdSave it as .claude/skills/run-fuzzing-campaign/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
run-fuzzing-campaign
description
Run a fuzzing campaign using AFL++ with optional seeds; supports `--custom_mutator_path` (you can write your own custom mutator and use this to execute).
should_run_in_sandbox
fuzz
returns_json
false

Run Fuzzing Campaign

Run an AFL++ fuzzing campaign.

This tool supports custom mutators via --custom_mutator_path. You can also write your own custom mutator (Python) and pass it in.

Usage

bash
/bash_tools/fuzz/run-fuzzing-campaign/scripts/run_fuzzing_campaign.sh target_binary 180
bash
/bash_tools/fuzz/run-fuzzing-campaign/scripts/run_fuzzing_campaign.sh target_binary 180 /path/to/seed1.txt /path/to/seed2.txt
bash
/bash_tools/fuzz/run-fuzzing-campaign/scripts/run_fuzzing_campaign.sh target_binary 180 /path/to/seed.txt --custom_mutator_path /fuzz/mutator/custom_mutator.py
bash
/bash_tools/fuzz/run-fuzzing-campaign/scripts/run_fuzzing_campaign.sh target_binary 180 /path/to/seed.txt --reset_output

Parameters

fuzz_target (required, positional position 0)

Type: str

Fuzz target binary name (expected at /out/<fuzz_target>).

duration_seconds (required, positional position 1)

Type: int

Fuzzing duration in seconds (e.g., 180).

seed_paths (optional, positional position 2+)

Type: list of strings

Optional seed file/dir paths.

--custom_mutator_path (optional, named parameter)

Type: str

Optional path to a custom mutator script.

--reset_output (optional, flag)

Type: bool (default: false)

Reset output and start fresh.

Custom Mutator

If you provide --custom_mutator_path, AFL++ will load the mutator from that path. A common convention is to place it in the fuzz sandbox, e.g.:

bash
/bash_tools/fuzz/run-fuzzing-campaign/scripts/run_fuzzing_campaign.sh target_binary 180 /path/to/seed.txt \
  --custom_mutator_path /fuzz/mutator/custom_mutator.py

You can implement your own custom_mutator.py as part of your workflow and iterate on it during fuzzing.

Return Value

Returns text output (summary of fuzzing results).

Requires Sandbox

fuzz

Timeout

200 seconds

© opensage-agent, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in src/opensage/bash_tools/fuzz/run-fuzzing-campaign of opensage-agent/opensage-adk.

  • SKILL.md
  • scripts/run_fuzzing_campaign.sh

Open the folder on GitHubat commit 54d6470

Compare with similar skills

Run Fuzzing Campaign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Run Fuzzing Campaign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Run Fuzzing Campaign this skillopensage-agent/opensage-adk127—~542Automated safety check: PassApache-2.0
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Fizz Syncpashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT
Research FuzzerARA-Labs/Agent-Native-Research-Artifact691—~2.4kAutomated safety check: PassMIT
Vuln Researchtanweai/xianzhi-research185—~847Automated safety check: PassNone
Binary Reverse Engineering Audittihanyin/REx-skill108—~5.1kAutomated safety check: PassMIT

Similar skills

  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Research Fuzzer

    ARA-Labs/Agent-Native-Research-Artifact

    Treat an open-ended investigation the way a fuzzer treats a program.

    691 GitHub stars~2.4k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Vuln Research

    tanweai/xianzhi-research

    安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

    185 GitHub stars~847 tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

    108 GitHub stars~5.1k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    612 GitHub stars~5.7k tokensUpdated 3 days ago
    SecurityAuto-check passed

More from opensage-agent/opensage-adk

All 21 skills in this repo
  • Pool

    opensage-agent/opensage-adk

    Run N tasks under a concurrency cap K via a sliding-window worker pool.

    127 GitHub stars~462 tokensUpdated 2 mo ago
    Auto-check passed
  • Create New Tool

    opensage-agent/opensage-adk

    Scaffold a new bashtools Skill under bashtools/newtools/. An agent skill from opensage-agent/opensage-adk.

    127 GitHub stars~302 tokensUpdated 2 mo ago
    Auto-check passed
  • Extract Crashes

    opensage-agent/opensage-adk

    Extract crash inputs from fuzzing output into a target directory.

    127 GitHub stars~215 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Call Paths

    opensage-agent/opensage-adk

    Get a path in the call graph from a source function to a specified destination function in the codebase.

    127 GitHub stars~272 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Callee

    opensage-agent/opensage-adk

    Tool to get the callee of a function in the codebase by function name and file path.

    127 GitHub stars~223 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Caller

    opensage-agent/opensage-adk

    Tool to get the caller of a function in the codebase. An agent skill from opensage-agent/opensage-adk.

    127 GitHub stars~208 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Run Fuzzing Campaign

What does Run Fuzzing Campaign do?

Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute). Run Fuzzing Campaign is an agent skill from opensage-agent/opensage-adk. Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

When should I use Run Fuzzing Campaign?

Run Fuzzing Campaign fits situations like: tasks that involve Fuzzing.

How do I install Run Fuzzing Campaign in Claude Code?

Run `npx skills add opensage-agent/opensage-adk --skill run-fuzzing-campaign -a claude-code`. Or copy the skill folder (src/opensage/bash_tools/fuzz/run-fuzzing-campaign in opensage-agent/opensage-adk) into .claude/skills/run-fuzzing-campaign in your project. Claude Code loads it when a task matches its description.

How do I install Run Fuzzing Campaign in Codex?

Run `npx skills add opensage-agent/opensage-adk --skill run-fuzzing-campaign -a codex`. Or copy the skill folder (src/opensage/bash_tools/fuzz/run-fuzzing-campaign in opensage-agent/opensage-adk) into .agents/skills/run-fuzzing-campaign in your project. Codex loads it when a task matches its description.

Can I use Run Fuzzing Campaign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add opensage-agent/opensage-adk --skill run-fuzzing-campaign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/run-fuzzing-campaign, .gemini/skills/run-fuzzing-campaign, .github/skills/run-fuzzing-campaign and .opencode/skills/run-fuzzing-campaign in your project.

What does Run Fuzzing Campaign need to run?

Going by SKILL.md and its folder, Run Fuzzing Campaign needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Run Fuzzing Campaign access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Run Fuzzing Campaign safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Run Fuzzing Campaign use?

Run Fuzzing Campaign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Run Fuzzing Campaign use?

About 542 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Run Fuzzing Campaign?

Skills that share tags, products or a category with Run Fuzzing Campaign: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 691 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Run Fuzzing Campaign?

opensage-agent (a GitHub organization) maintains it in opensage-agent/opensage-adk, which has 127 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 4, 2026.

Source: opensage-agent/opensage-adk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.